Storage system, data processing method, data processing unit, and program product

By introducing a data processing unit into the storage system, uninstalling the data encryption and decryption service, and using preset keys and encryption parameters to encrypt and decrypt data transmission and storage, the computing resource consumption and management problems caused by device self-encryption are solved, and the full-link data security and unified management are realized.

CN120301707AActive Publication Date: 2025-07-11LANGCHAO ELECTRONIC INFORMATION IND CO LTD
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
CN202510772191.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-11
Publication Date
2025-07-11
Estimated Expiration
2045-06-11

AI Technical Summary

Technical Problem

In the prior art, the devices in the storage link implement data encryption by themselves, resulting in large consumption of computing resources and serious performance losses, which is not conducive to docking and unified control between devices.

Method used

The data encryption and decryption service is offloaded to the data processing units in the server, storage controller and separate storage. Through these units, data encryption and decryption and unified management are realized, and data transmission and storage are encrypted and decrypted using preset keys and encryption parameters.

Benefits of technology

It reduces the computing resource burden of servers, storage controllers and separate storage, realizes full-link data encryption, and improves the security and unified management and control capabilities of data transmission and storage.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120301707A_ABST
    Figure CN120301707A_ABST
Patent Text Reader

Abstract

The invention discloses a storage system, a data processing method, a data processing unit and a program product, and relates to the technical field of storage. The server, the storage controller and the separated storage in the storage system are provided with corresponding data processing units, data encryption and decryption services can be unloaded to the data processing units, computing resources of the server, the storage controller and the separated storage can be released, and data encryption can be managed and controlled in a unified mode through the data processing units; in addition, dynamic encryption in data transmission and static encryption in data storage can be realized based on the data processing unit, so that full-link data encryption in the storage system can be more effectively realized.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of storage technologies, and in particular, to a storage system, a data processing method, a data processing unit, and a program product. Background Art

[0002] In a data center, to effectively protect data security, full-link encryption protection for data transmission and storage is of great significance. In related technologies, data encryption is usually implemented by each device (such as a server, a storage controller, etc.) in the storage link. However, data encryption consumes a large amount of computing resources and is likely to cause serious performance losses to these devices. Moreover, implementing the data encryption function by each device is not conducive to the docking between devices and is also not conducive to the unified management and control of data encryption.

[0003] In view of this, how to avoid each device in the storage link implementing data encryption by itself is a technical problem that needs to be urgently solved by those skilled in the art. Summary of the Invention

[0004] The present invention provides a storage system, a data processing method, a data processing unit, and a program product, so as to offload the data encryption and decryption services to the data processing units in the server, the storage controller, and the disaggregated storage, which can release the computing resources of the server, the storage controller, and the disaggregated storage, and is conducive to the unified management and control of data encryption.

[0005] To solve the above technical problem, the present invention provides a storage system, including a server, a storage controller, and a disaggregated storage. The server has a first data processing unit, the storage controller has a second data processing unit and a third data processing unit, and the disaggregated storage has a fourth data processing unit; Either end of the first data processing unit and the second data processing unit is used to encrypt the interaction data between the server and the storage controller by using a first preset key and a first preset encryption parameter and transmit it to the other end of the first data processing unit and the second data processing unit, and decrypt the interaction data between the server and the storage controller sent by the other end; Either end of the third data processing unit and the fourth data processing unit is used to encrypt the interaction data between the storage controller and the disaggregated storage by using a second preset key and a second preset encryption parameter and transmit it to the other end of the third data processing unit and the fourth data processing unit, and decrypt the interaction data between the storage controller and the disaggregated storage sent by the other end; The fourth data processing unit is further used to encrypt the data written into the disaggregated storage by using a third preset key and decrypt the data read out from the disaggregated storage.

[0006] The present invention also provides a data processing method, which is applied to the first data processing unit in the above storage system. The method includes: Receiving the first plaintext data sent by the server, encrypting the first plaintext data into the first ciphertext data by using the first preset key and the first preset encryption parameter, and sending the first ciphertext data to the second data processing unit; Receiving the second ciphertext data sent by the second data processing unit, decrypting the second ciphertext data into the second plaintext data by using the first preset key and the first preset encryption parameter, and sending the second plaintext data to the server.

[0007] The present invention also provides a data processing method, which is applied to the second data processing unit in the above storage system. The method includes: Receiving the first ciphertext data sent by the first data processing unit, decrypting the first ciphertext data into the first plaintext data by using the first preset key and the first preset encryption parameter, and sending the first plaintext data to the storage controller; Receiving the second plaintext data sent by the storage controller, encrypting the second plaintext data into the second ciphertext data by using the first preset key and the first preset encryption parameter, and sending the second ciphertext data to the first data processing unit.

[0008] The present invention also provides a data processing method, which is applied to the third data processing unit in the above storage system. The method includes: Receiving the third plaintext data sent by the storage controller, encrypting the third plaintext data into the third ciphertext data by using the second preset key and the second preset encryption parameter, and sending the third ciphertext data to the fourth data processing unit; Receiving the fourth ciphertext data sent by the fourth data processing unit, decrypting the fourth ciphertext data into the fourth plaintext data by using the second preset key and the second preset encryption parameter, and sending the fourth plaintext data to the storage controller.

[0009] The present invention also provides a data processing method, which is applied to the fourth data processing unit in the above storage system. The method includes: Receiving the third ciphertext data sent by the third data processing unit, decrypting the third ciphertext data into the third plaintext data by using the second preset key and the second preset encryption parameter, encrypting the third plaintext data into the fifth ciphertext data by using the third preset key, and writing the fifth ciphertext data into the discrete storage; Receiving the sixth ciphertext data sent by the discrete storage, decrypting the sixth ciphertext data into the fourth plaintext data by using the third preset key, encrypting the fourth plaintext data into the fourth ciphertext data by using the second preset key and the second preset encryption parameter, and sending the fourth ciphertext data to the third data processing unit.

[0010] The present invention also provides a data processing unit, including: A processor module, the processor module having an encryptor; A programmable logic device module, the programmable logic device module having a network transmission module and being connected to a server, a storage controller or a discrete storage; The processor module and the programmable logic device module are used to execute the above-mentioned data processing method.

[0011] The present invention also provides a computer program product, including a computer program or instruction, and when the computer program or instruction is executed by a processor, the above-mentioned data processing method is implemented.

[0012] The present invention also provides a non-volatile computer-readable storage medium, in which computer-executable instructions are stored, and when the computer-executable instructions are loaded and executed by a processor, the above-mentioned data processing method is implemented.

[0013] The beneficial effects of the present invention are as follows: In this storage system, the server, the storage controller, and the discrete storage have corresponding data processing units, that is, the server has a first data processing unit, the storage controller has a second data processing unit and a third data processing unit, and the discrete storage has a fourth data processing unit. Among them, either end of the first data processing unit and the second data processing unit is used to encrypt the interaction data between the server and the storage controller by using a first preset key and a first preset encryption parameter and transmit it to the other end of the first data processing unit and the second data processing unit, and decrypt the interaction data between the server and the storage controller sent by the other end to ensure the data transmission security between the server and the storage controller. Either end of the third data processing unit and the fourth data processing unit is used to encrypt the interaction data between the storage controller and the discrete storage by using a second preset key and a second preset encryption parameter and transmit it to the other end of the third data processing unit and the fourth data processing unit, and decrypt the interaction data between the storage controller and the discrete storage sent by the other end to ensure the data transmission security between the storage controller and the discrete storage. The fourth data processing unit can also encrypt the data written into the discrete storage by using a third preset key and decrypt the data read out from the discrete storage. In this way, the present invention can offload the data encryption and decryption services to each data processing unit, release the computing resources of the server, the storage controller, and the discrete storage, and can uniformly control the data encryption through the data processing unit; in addition, dynamic encryption in data transmission and static encryption in data storage can be realized based on the above-mentioned data processing unit, so as to more effectively realize full-link data encryption in the storage system.

[0014] The present invention also provides a data processing method, a data processing unit, a computer program product, and a non-volatile computer-readable storage medium, which have the above-mentioned beneficial effects. BRIEF DESCRIPTION OF THE DRAWINGS

[0015] To more clearly illustrate the embodiments of the present invention, the drawings required for use in the embodiments will be briefly introduced below. Obviously, the drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained based on these drawings.

[0016] Figure 1 It is a structural block diagram of a storage system provided by an embodiment of the present invention; Figure 2 It is a structural block diagram of another storage system provided by an embodiment of the present invention; Figure 3 It is a flowchart of a data processing method applied to a first data processing unit provided by an embodiment of the present invention; Figure 4 It is a flowchart of a data processing method applied to a second data processing unit provided by an embodiment of the present invention; Figure 5 It is a flowchart of a data processing method applied to a third data processing unit provided by an embodiment of the present invention; Figure 6 It is a flowchart of a data processing method applied to a fourth data processing unit provided by an embodiment of the present invention; Figure 7 It is a structural block diagram of a data processing unit provided by an embodiment of the present invention; Figure 8 It is a structural block diagram of another data processing unit provided by an embodiment of the present invention; Figure 9 It is a processing flowchart of a data processing unit provided by an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0017] The technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the drawings in the embodiments of the present invention. Obviously, the described embodiments are only some, rather than all, embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts fall within the protection scope of the present invention.

[0018] It should be noted that in the description of the present invention, the terms "include", "comprise" or any other variant thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements not only includes those elements, but also includes other elements not expressly listed, or also includes elements inherent to such process, method, article or device. The terms "first", "second", etc. in the present invention are used to distinguish similar objects, rather than to describe a specific order or sequence.

[0019] In order to enable those skilled in the art of the present technology to better understand the solution of the present invention, the present invention will be further described in detail below with reference to the accompanying drawings and specific embodiments.

[0020] In a data center, in order to effectively protect data security, it is of great significance to perform full-link encryption protection on data during transmission and storage. Among them, encrypting data during the data transmission process can be called data dynamic encryption, and encrypting data during data storage can be called data static encryption. In related technologies, data encryption is usually implemented by each device (such as a server, a storage controller) on the storage link. However, data encryption and decryption consume a large amount of computing resources, which is likely to cause serious performance loss to these devices. In addition, implementing the data encryption function by each device itself is not conducive to the docking between devices, nor is it conducive to the unified management and control of data encryption.

[0021] In view of this, in response to the technical problem of how to avoid each device in the storage link implementing data encryption by itself, the present invention can provide a storage system, which can set data processing units for a server, a storage controller, and a discrete storage, can offload data encryption and decryption services to the data processing units, and can realize unified management and control of data encryption based on these data units.

[0022] First, the specific structure of the storage system provided in this embodiment will be introduced below. Please refer to Figure 1 , Figure 1 which is a structural block diagram of a storage system provided in an embodiment of the present invention. This storage system may include a server 1, a storage controller 2, and a discrete storage 3. The following is an introduction to the uses and internal structures of these three devices: The server 1 is a client in this storage system, and is used to write data or read data into the storage system. A processor 11 and a first data processing unit 11 can be set inside it. The processor 11 and the first data processing unit 11 can be connected by a bus structure, such as being connected by a PCIe bus (Peripheral Component Interconnect express, a high-speed serial computer expansion bus standard).

[0023] The storage controller 2 is used to execute storage service processing, such as data compression, deduplication, caching, RAID processing (Redundant Arrays of Independent Disks), etc. A processor 21, a second data processing unit 22, and a third data processing unit 23 can be set inside it. The processor 21 can be connected to the second data processing unit 22 and the third data processing unit 23 respectively through a bus structure, such as using a PCIe bus connection. There can be multiple storage controllers 2 in the storage system to meet the multi-controller requirements.

[0024] The discrete storage 3 is used for backend data storage. One or more memories 31 and a fourth data processing unit 32 can be set inside it. The memory 31 and the fourth data processing unit 32 can be connected through a bus structure, such as using a PCIe bus connection. The type of the memory 31 can be selected according to actual needs. For example, it can be a mechanical hard disk (HDD, Hard Disk), a solid-state drive (SSD, Solid State Disk), etc.

[0025] Furthermore, the first data processing unit 12, the second data processing unit 22, the third data processing unit 23, and the fourth data processing unit 32 in this storage system all belong to the same type of data processing unit, and there is a communication connection between the first data processing unit 12 and the second data processing unit 22, and between the third data processing unit 23 and the fourth data processing unit 32, for example, a network communication connection is established. The following are the uses of the first data processing unit 12, the second data processing unit 22, the third data processing unit 23, and the fourth data processing unit 32: Either end of the first data processing unit 12 and the second data processing unit 22 is used to encrypt the interaction data between the server 1 and the storage controller 2 using a first preset key and first preset encryption parameters and transmit it to the other end of the first data processing unit 12 and the second data processing unit 22, and decrypt the interaction data between the server 1 and the storage controller 2 sent by the other end; Either end of the third data processing unit 23 and the fourth data processing unit 32 is used to encrypt the interaction data between the storage controller 2 and the discrete storage 3 using a second preset key and second preset encryption parameters and transmit it to the other end of the third data processing unit 23 and the fourth data processing unit 32, and decrypt the interaction data between the storage controller 2 and the discrete storage 3 sent by the other end; The fourth data processing unit 32 is also used to encrypt the data written into the discrete storage 3 using a third preset key and decrypt the data read out from the discrete storage 3.

[0026] For both the first data processing unit 12 and the second data processing unit 22, they are responsible for the encryption, decryption and transmission of the data exchanged between the server 1 and the storage controller 2.

[0027] Specifically, the first data processing unit 12 can execute: receiving the first plaintext data sent by the server, encrypting the first plaintext data into the first ciphertext data by using the first preset key and the first preset encryption parameter, and sending the first ciphertext data to the second data processing unit 22; receiving the second ciphertext data sent by the second data processing unit 22, decrypting the second ciphertext data into the second plaintext data by using the first preset key and the first preset encryption parameter, and sending the second plaintext data to the server 1.

[0028] The second data processing unit 22 can execute: receiving the first ciphertext data sent by the first data processing unit 12, decrypting the first ciphertext data into the first plaintext data by using the first preset key and the first preset encryption parameter, and sending the first plaintext data to the storage controller 2; receiving the second plaintext data sent by the storage controller 2, encrypting the second plaintext data into the second ciphertext data by using the first preset key and the first preset encryption parameter, and sending the second ciphertext data to the first data processing unit 12.

[0029] For both the third data processing unit 23 and the fourth data processing unit 32, they are responsible for the encryption, decryption and transmission of the data exchanged between the storage controller 2 and the discrete storage 3. The fourth data processing unit 32 is also responsible for encrypting the data written into the discrete storage 3 and decrypting the data read out from the discrete storage 3.

[0030] Specifically, the third data processing unit 23 can execute: receiving the third plaintext data sent by the storage controller 2, encrypting the third plaintext data into the third ciphertext data by using the second preset key and the second preset encryption parameter, and sending the third ciphertext data to the fourth data processing unit 32; receiving the fourth ciphertext data sent by the fourth data processing unit 32, decrypting the fourth ciphertext data into the fourth plaintext data by using the second preset key and the second preset encryption parameter, and sending the fourth plaintext data to the storage controller 2.

[0031] The fourth data processing unit 32 can execute: receiving the third ciphertext data sent by the third data processing unit 23, decrypting the third ciphertext data into the third plaintext data by using the second preset key and the second preset encryption parameter, encrypting the third plaintext data into the fifth ciphertext data by using the third preset key, and writing the fifth ciphertext data into the discrete storage 3; receiving the sixth ciphertext data sent by the discrete storage 3, decrypting the sixth ciphertext data into the fourth plaintext data by using the third preset key, encrypting the fourth plaintext data into the fourth ciphertext data by using the second preset key and the second preset encryption parameter, and sending the fourth ciphertext data to the third data processing unit 23.

[0032] It should be noted that the first preset encryption parameter and the second preset encryption parameter are configuration parameters related to encryption and decryption, such as encryption algorithm type, encryption mode, data block size, etc. The first preset encryption parameter and the second preset encryption parameter can be preset inside the data processing unit or sent by the device to which the data processing unit belongs. This embodiment does not limit the specific content of the first preset encryption parameter and the second preset encryption parameter, and can be set according to the specific requirements of data transmission and data storage. The first preset encryption parameter and the second preset encryption parameter can be different.

[0033] It should also be noted that the first preset key and the second preset key are communication keys used during data communication, and the third preset key is a storage key used during data storage. The first preset key, the second preset key, and the third preset key can be different. In addition, the first preset key, the second preset key, and the third preset key can be preset keys inside each data processing unit or provided by other devices. For example, the first preset key can be a hardware built-in key of Server 1 and Storage Controller 2, the second preset key can be a hardware built-in key of Storage Controller 2 and Separate Storage 3, and the third preset key can be a hardware built-in key of Separate Storage 3. At this time, each data processing unit needs to obtain the preset key from the device to which it belongs. Another example is that a unified management server can be set to allocate and manage the first preset key, the second preset key, and the third preset key. Furthermore, each data processing unit needs to request the corresponding preset key from the management server.

[0034] As can be seen from the above embodiments, the dynamic encryption and static encryption of data on the storage link of the server 1, the storage controller 2, and the discrete storage 3 can be offloaded to the data processing unit (DPU, Data Process Unit) in each device for processing. Among them, the first data processing unit 12 and the second data processing unit 22 are responsible for the encryption and decryption processing and encrypted transmission processing of the interactive data between the server 1 and the storage controller 2. The third data processing unit 23 and the fourth data processing unit 32 are responsible for the encryption and decryption processing and encrypted transmission processing of the interactive data between the storage controller 2 and the discrete storage 3. In addition, the fourth data processing unit 32 can also encrypt the data written to the discrete storage 3 and decrypt the data read from the discrete storage 3 separately. In this way, first, it can ensure that the data is encrypted during both the transmission stage and the storage stage, realizing full-link encryption of data storage and ensuring the security of data transmission and storage. In addition, offloading the heavy data encryption and decryption tasks to dedicated hardware devices (i.e., data processing units) can reduce the burdens of the server 1, the storage controller 2, and the discrete storage 3. Most importantly, offloading the data encryption and decryption tasks to the data processing unit can achieve unified management and control of the data encryption and decryption services through the data processing unit and can improve scalability. For example, the operation and maintenance personnel can flexibly manage and adjust the first preset key, the first preset encryption parameter, the second preset key, the second preset encryption parameter, and the third preset key based on the above data processing units to meet different security requirements. In addition, the first data processing unit, the second data processing unit 22, the third data processing unit 23, and the fourth data processing unit 32 are all the same, which means that the unified functional upgrade of each data processing unit can be carried out, such as uniformly upgrading the types of encryption algorithms supported by the data processing unit. Therefore, this embodiment can not only effectively avoid using the server 1, the storage controller 2, and the discrete storage 3 themselves to execute data encryption and decryption, but also improve the unity and flexibility of the management and control of the data encryption and decryption services.

[0035] It should be noted that Figure 1 The structure shown is the simplest structure. In other cases, the storage system may also include other devices, and there may be other components inside the server 1, the storage controller 2, and the discrete storage 3, which can be set according to actual application requirements. For example, a memory (DRAM, Dynamic Random Access Memory) can also be set in the server 1 and the storage controller 2.

[0036] In another embodiment, for the convenience of managing and controlling the data encryption and decryption services, a management server can also be set in this storage system, which is at least used to manage and control the first preset key, the second preset key, and the third preset key. Please refer to Figure 2 , Figure 2Block diagram of another storage system provided by an embodiment of the present invention. In Figure 2 this system, a management server 4 may also be included, and a communication connection is established between the first data processing unit 12, the second data processing unit 22, the third data processing unit 23, and the fourth data processing unit 32 and the management server 4. At this time: The first data processing unit 12 is further configured to obtain a first preset key from the management server 4 according to the communication information of the second data processing unit 22; The second data processing unit 22 is further configured to obtain a first preset key from the management server 4 according to the communication information of the first data processing unit 12; The third data processing unit 23 is further configured to obtain a second preset key from the management server 4 according to the communication information of the fourth data processing unit 32; The fourth data processing unit 32 is further configured to obtain a second preset key from the management server 4 according to the communication information of the third data processing unit 23, and obtain a third preset key from the management server 4.

[0037] It can be seen that in this embodiment, the first preset key, the second preset key, and the third preset key are all allocated by the management server 4. At this time, each data processing unit does not need to request a key from the affiliated device; moreover, the server 1, the storage controller 2, and the discrete storage 3 do not need to consider providing keys for the data processing units, and only need to send the preset encryption parameters representing the encryption requirements to each data processing unit. In this way, the data encryption and decryption services can be further separated from the server 1, the storage controller 2, and the discrete storage 3.

[0038] It should be noted that, different from the traditional communication method, in this embodiment, the first preset key and the second preset key for data transmission are not negotiated by the data processing units, but can be requested from the management server 4. In this way, the data processing units can avoid negotiating communication keys, which can improve the communication efficiency between the data processing units, such as improving the efficiency of reconstructing communication after the device is disconnected.

[0039] At the same time, when the data processing unit requests a preset key, it can use the communication information of the communication peer to request the preset key from the management server 4, so that the management server 4 can perceive the communication relationship between the data processing units and allocate a preset key for this communication relationship. At this time, the management server 4 can effectively manage the communication relationship between the data processing units and the communication key of this communication relationship, which can improve the unity of management and control.

[0040] For example, in the initial situation, when the first data processing unit 12 is to communicate with the second data processing unit 22, it can obtain a first preset key from the management server 4 according to the communication information (such as the IP address) of the second data processing unit 22. At this time, the management server 4 can sense that the first data processing unit 12 is to communicate with the second data processing unit 22, and then can record the communication relationship between the first data processing unit 12 and the second data processing unit 22, and allocate a first preset key for this communication relationship, and send the first preset key to the first data processing unit 12. Furthermore, the first data processing unit 12 can use the obtained first preset key to send ciphertext data to the second data processing unit 22.

[0041] Subsequently, when the second data processing unit 22 obtains the ciphertext data, it can obtain the first preset key from the management server 4 according to the communication information of the first data processing unit. At this time, since the management server 4 has previously allocated a first preset key for the communication between the first data processing unit 12 and the second data processing unit 22, it can directly send the first preset key to the second data processing unit 22. Furthermore, the second data processing unit 22 can use the obtained first preset key to decrypt the ciphertext data.

[0042] Of course, in addition to allocating keys for data processing units, the management server 4 can also perform other processing operations. For example, the management server 4 can detect the validity period of the preset key, and when it determines that the preset key has expired, re-send the preset key to the corresponding data processing unit. In addition, the management server 4 can also control the preset encryption parameters used between data processing units to further separate the data encryption and decryption services from the server 1, the storage controller 2, and the discrete storage 3. In addition, when the management server 4 receives a key request sent by a data processing unit, it can also detect whether the communication relationship between data processing units is prohibited. If it is not prohibited, it can allocate a key; otherwise, it can refuse to allocate a key.

[0043] Based on the above embodiments, in this storage system, the server, the storage controller, and the discrete storage have corresponding data processing units, that is, the server has a first data processing unit, the storage controller has a second data processing unit and a third data processing unit, and the discrete storage has a fourth data processing unit. Among them, either end of the first data processing unit and the second data processing unit is used to encrypt the interaction data between the server and the storage controller by using a first preset key and a first preset encryption parameter and transmit it to the other end of the first data processing unit and the second data processing unit, and decrypt the interaction data between the server and the storage controller sent by the other end, so as to ensure the data transmission security between the server and the storage controller. Either end of the third data processing unit and the fourth data processing unit is used to encrypt the interaction data between the storage controller and the discrete storage by using a second preset key and a second preset encryption parameter and transmit it to the other end of the third data processing unit and the fourth data processing unit, and decrypt the interaction data between the storage controller and the discrete storage sent by the other end, so as to ensure the data transmission security between the storage controller and the discrete storage. The fourth data processing unit can also encrypt the data written into the discrete storage by using a third preset key and decrypt the data read out from the discrete storage. In this way, the present invention can offload the data encryption and decryption services to each data processing unit, release the computing resources of the server, the storage controller, and the discrete storage, and can uniformly control the data encryption through the data processing unit; in addition, dynamic encryption in data transmission and static encryption in data storage can be realized based on the above data processing unit, so as to more effectively realize full-link data encryption in the storage system.

[0044] Based on the above embodiments, the execution logic of the first data processing unit will be introduced in detail below. Please refer to Figure 3 , Figure 3 which is a flowchart of a data processing method applied to the first data processing unit provided by an embodiment of the present invention. This method may include: S31. Receive the first plaintext data sent by the server, encrypt the first plaintext data into the first ciphertext data by using a first preset key and a first preset encryption parameter, and send the first ciphertext data to the second data processing unit.

[0045] S32. Receive the second ciphertext data sent by the second data processing unit, decrypt the second ciphertext data into the second plaintext data by using a first preset key and a first preset encryption parameter, and send the second plaintext data to the server.

[0046] It should be noted that the second plaintext data is sent by the storage controller to the second data processing unit.

[0047] In this embodiment, the interaction data between the server and the storage controller is related to the data storage service. For example, the first plaintext data sent by the server can be a read request or a write request, and the second plaintext data returned by the storage controller can be a request response to the read request or the write request. The first preset encryption parameter is a parameter required for data encryption and decryption, such as the algorithm type, algorithm mode, data block size, etc. The first preset encryption parameter can be built into the first data processing unit, or provided by the server or the management server. The first preset key is a communication key used for encrypting the transmitted interaction data, which can be built into the first data processing unit, or provided by the server or the management server.

[0048] In this step, when receiving the plaintext data sent by the server, the first data processing unit can encrypt the plaintext data into ciphertext data by using the first preset key and the first preset encryption parameter, and send the ciphertext data to the second data processing unit. In addition, when receiving the ciphertext data sent by the second data processing unit, the first data processing unit decrypts the ciphertext data into plaintext data by using the first preset key and the first preset encryption parameter, and sends the plaintext data to the server. In this way, the data transmission security between the server and the storage controller can be ensured.

[0049] It should be noted that in the actual application scenario, steps S31 and S32 can be executed in disorder.

[0050] Furthermore, considering that there is a correlation between the data encryption service and the storage service performance. To facilitate the user to manually optimize the encryption and decryption methods, the first preset encryption parameter of the first data processing unit can be sent by the server.

[0051] Based on this, this method can further include: S331. Receive the first preset encryption parameter sent by the server and save it.

[0052] In this step, the first data processing unit can receive the first preset encryption parameter sent by the server to understand how the server expects to communicate with the storage controller in an encrypted manner.

[0053] It should be noted that the above first preset encryption parameter can be dynamically adjusted by the server. Further, in order to separate the data encryption and decryption services from the server, the storage system may also include a management server, which can provide a first preset key for the first data processing unit. Specifically, the first data processing unit can request the first preset key from the management server by using its own first authentication information and the communication information of the second data processing unit. Among them, the first authentication information is used to indicate the identity of the first data processing unit, and the communication information of the second data processing unit is used to indicate that the first data processing unit requests to communicate with the second data processing unit. Furthermore, the management server can use the first authentication information to verify the identity of the first data processing unit, and after the identity verification is passed, use the communication information to allocate the first preset key and return it.

[0054] Based on this, the method may further include: S341: Send its own first authentication information and the communication information of the second data processing unit to the management server, so that the management server can use the first authentication information to verify the identity of the first data processing unit and allocate the first preset key by using the communication information after the identity verification is passed; S342: Receive the first preset key sent by the management server and save it.

[0055] It should be noted that the specific form of the first authentication information is not limited in this embodiment and can be set according to actual application requirements. For example, the first authentication information can be a CA certificate (Certificate Authority), an identity Token (token) information, etc.

[0056] Further, to improve the security of data transmission, the first preset key may include validity period information. When the first preset key expires, the first data processing unit will not be able to use the key for data encryption. Therefore, the first data processing unit can judge whether the first preset key has expired according to the validity period information. If it is determined that the key has expired, the key can be requested from the management server again.

[0057] Based on this, the first preset key includes validity period information. The method may further include: S351: Judge whether the first preset key has expired according to the validity period information; S352: If it is determined that the first preset key has expired, enter the step of sending its own first authentication information and the communication information of the second data processing unit to the management server.

[0058] It should be noted that the specific validity period of the first preset key is not limited in this embodiment and can be set according to actual application requirements.

[0059] Based on the above embodiments, the execution logic of the second data processing unit will be introduced in detail below. Please refer to Figure 4 , Figure 4 which is a flowchart of a data processing method applied to the second data processing unit provided by an embodiment of the present invention. This method may include: S41. Receive the first ciphertext data sent by the first data processing unit, decrypt the first ciphertext data into first plaintext data by using a first preset key and first preset encryption parameters, and send the first plaintext data to the storage controller.

[0060] S42. Receive the second plaintext data sent by the storage controller, encrypt the second plaintext data into second ciphertext data by using the first preset key and first preset encryption parameters, and send the second ciphertext data to the first data processing unit.

[0061] It should be noted that the first plaintext data is sent by the server to the first data processing unit. In this embodiment, the interaction data between the server and the storage controller is related to the data storage service. The first plaintext data sent by the server may be a read request or a write request, and the second plaintext data returned by the storage controller may be a request response to the read request or the write request. The first preset encryption parameters are parameters required for data encryption and decryption, such as algorithm type, algorithm mode, data block size, etc. The first preset encryption parameters may be built into the second data processing unit, or may be provided by the storage controller or the management server. The first preset key is a communication key used for encrypting and transmitting the interaction data, which may be built into the second data processing unit, or may be provided by the storage controller or the management server.

[0062] In this step, when receiving the ciphertext data sent by the first data processing unit, the second data processing unit may decrypt the ciphertext data into plaintext data by using the first preset key and first preset encryption parameters, and send the plaintext data to the storage controller. In addition, when receiving the plaintext data sent by the storage controller, the second data processing unit may encrypt the plaintext data into ciphertext data by using the first preset key and first preset encryption parameters, and send the ciphertext data to the first data processing unit. In this way, the data transmission security between the server and the storage controller can be ensured.

[0063] It is worth pointing out that the second data processing unit sends the plaintext data to the storage controller for processing, rather than sending the ciphertext data to the storage controller for processing. Therefore, the storage controller can process the plaintext data according to mechanisms such as data caching, data organization, and data protection, which can avoid the damage to the plaintext data characteristics caused by data encryption, and further avoid the problem that the storage controller cannot normally execute the storage service processing due to data encryption.

[0064] It should be noted that in the actual application scenario, steps S41 and S42 can be executed in a disordered manner. Further, considering the correlation between the data encryption service and the storage service performance. To facilitate the user to manually optimize the encryption and decryption methods, the first preset encryption parameter of the second data processing unit can be issued by the storage controller.

[0065] Based on this, the method may further include: S431: Receive the first preset encryption parameter issued by the storage controller and save it.

[0066] In this step, the second data processing unit can receive the first preset encryption parameter issued by the storage controller to understand how the storage controller hopes to communicate with the server in an encrypted manner.

[0067] It should be noted that the above first preset encryption parameter can be dynamically adjusted by the storage controller. Further, to separate the data encryption and decryption services from the server, the storage system may also include a management server that can provide the first preset key for the second data processing unit. Specifically, the second data processing unit can request the first preset key from the management server by using its own second authentication information and the communication information of the first data processing unit. Among them, the second authentication information is used to indicate the identity of the second data processing unit, and the communication information of the first data processing unit is used to indicate that the second data processing unit requests to communicate with the first data processing unit. Furthermore, the management server can use the second authentication information to verify the identity of the second data processing unit, and after the identity verification is passed, allocate the first preset key by using the communication information and return it.

[0068] Based on this, the method may further include: S441: Send its own second authentication information and the communication information of the first data processing unit to the management server, so that the management server can use the second authentication information to verify the identity of the second data processing unit and allocate the first preset key by using the communication information after the identity verification is passed; S442: Receive the first preset key sent by the management server and save it.

[0069] It should be noted that this embodiment does not limit the specific form of the second authentication information, which can be set according to the actual application requirements. For example, the second authentication information can be a CA certificate (Certificate Authority), an identity Token information, etc.

[0070] Further, to enhance the security of data transmission, the first preset key may include validity period information. When the first preset key expires, the second data processing unit will not be able to use the key for data encryption. Therefore, the second data processing unit can determine whether the first preset key has expired based on the validity period information. If it is determined that the key has expired, the second data processing unit can request a key from the management server again.

[0071] Based on this, the first preset key includes validity period information; the method may further include: S451: Determine whether the first preset key has expired based on the validity period information; S452: If it is determined that the first preset key has expired, enter the step of sending the second authentication information of itself and the communication information of the first data processing unit to the management server.

[0072] Based on the above embodiments, the execution logic of the third data processing unit will be introduced in detail below. Please refer to Figure 5 , Figure 5 which is the flowchart of the data processing method applied to the third data processing unit provided by the embodiments of the present invention. The method may include: S51. Receive the third plaintext data sent by the storage controller, encrypt the third plaintext data into the third ciphertext data by using the second preset key and the second preset encryption parameters, and send the third ciphertext data to the fourth data processing unit.

[0073] S52. Receive the fourth ciphertext data sent by the fourth data processing unit, decrypt the fourth ciphertext data into the fourth plaintext data by using the second preset key and the second preset encryption parameters, and send the fourth plaintext data to the storage controller.

[0074] It should be noted that the fourth plaintext data is sent from the disaggregated storage to the fourth data processing unit.

[0075] In this embodiment, the interaction data between the storage controller and the disaggregated storage is related to the data storage service. For example, it may be the data to be written into the disaggregated storage, or the data read from the disaggregated storage. The second preset encryption parameters are the parameters required for data encryption and decryption, such as the algorithm type, algorithm mode, data block size, etc. The second preset encryption parameters may be built into the third data processing unit, or provided by the storage controller or the management server. The second preset key is the communication key used for encrypting and transmitting the interaction data between the storage controller and the disaggregated storage, and may be built into the third data processing unit, or provided by the storage controller or the management server.

[0076] In this step, when receiving the plaintext data sent by the storage controller, the third data processing unit can encrypt the plaintext data into ciphertext data by using the second preset key and the second preset encryption parameter, and send the ciphertext data to the fourth data processing unit. In addition, when receiving the ciphertext data sent by the fourth data processing unit, the third data processing unit can decrypt the ciphertext data into plaintext data by using the second preset key and the second preset encryption parameter, and send the plaintext data to the storage controller. In this way, the data transmission security between the storage controller and the discrete storage can be ensured.

[0077] It should be noted that in the actual application scenario, steps S51 and S52 can be executed out of order.

[0078] Furthermore, considering that there is an association between the data encryption service and the storage service performance. To facilitate the user to manually optimize the encryption and decryption methods, the second preset encryption parameter of the third data processing unit can be sent by the storage controller.

[0079] Based on this, the method can further include: S531: Receive the second preset encryption parameter sent by the storage controller and save it.

[0080] In this step, the third data processing unit can receive the second preset encryption parameter sent by the storage controller to understand how the storage controller hopes to communicate with the discrete storage in an encrypted manner.

[0081] It should be noted that the above-mentioned second preset encryption parameter can be dynamically adjusted by the storage controller.

[0082] Furthermore, to separate the data encryption and decryption services from the server, the storage system can also include a management server, which can provide the second preset key for the third data processing unit. Specifically, the third data processing unit can request the second preset key from the management server by using its own third authentication information and the communication information of the fourth data processing unit. Among them, the third authentication information is used to indicate the identity of the third data processing unit, and the communication information of the fourth data processing unit is used to indicate that the third data processing unit requests to communicate with the fourth data processing unit. Furthermore, the management server can use the third authentication information to verify the identity of the third data processing unit, and after the identity verification is passed, allocate the second preset key by using the communication information and return it.

[0083] Based on this, the method can further include: S541: Send its own third authentication information and the communication information of the fourth data processing unit to the management server, so that the management server can use the third authentication information to verify the identity of the third data processing unit and allocate the second preset key by using the communication information after the identity verification is passed; S542: Receive the second preset key sent by the management server and save it.

[0084] It should be noted that this embodiment does not limit the specific form of the third authentication information, which can be set according to actual application requirements. For example, the third authentication information can be a CA certificate (Certificate Authority), an identity Token information, etc.

[0085] Furthermore, to enhance the security of data transmission, the second preset key may include validity period information. When the second preset key expires, the third data processing unit will not be able to use this key for data encryption. Therefore, the third data processing unit can determine whether the second preset key has expired according to the validity period information. If it is determined that the key has expired, it can request a key from the management server again.

[0086] Based on this, the second preset key includes validity period information. This method may further include: S551: Determine whether the second preset key has expired according to the validity period information; S552: If it is determined that the second preset key has expired, then enter the step of sending the third authentication information of itself and the communication information of the fourth data processing unit to the management server.

[0087] It should be noted that this embodiment does not limit the specific validity period duration of the second preset key, which can be set according to actual application requirements.

[0088] Based on the above embodiments, the execution logic of the fourth data processing unit will be introduced in detail below. Please refer to Figure 6 , Figure 6 which is the flowchart of the data processing method applied to the fourth data processing unit provided by the embodiment of the present invention. This method may include: S61: Receive the third ciphertext data sent by the third data processing unit, decrypt the third ciphertext data into the third plaintext data by using the second preset key and the second preset encryption parameters, encrypt the third plaintext data into the fifth ciphertext data by using the third preset key, and write the fifth ciphertext data into the discrete storage.

[0089] S62: Receive the sixth ciphertext data sent by the discrete storage, decrypt the sixth ciphertext data into the fourth plaintext data by using the third preset key, encrypt the fourth plaintext data into the fourth ciphertext data by using the second preset key and the second preset encryption parameters, and send the fourth ciphertext data to the third data processing unit.

[0090] It should be pointed out that the third plaintext data is sent by the storage controller to the third data processing unit.

[0091] In this embodiment, the interaction data between the storage controller and the discrete storage is related to the data storage service. For example, it can be the data to be written into the discrete storage, or the data read from the discrete storage. The second preset encryption parameter is the parameter required for data encryption and decryption, such as the algorithm type, algorithm mode, data block size, etc. The second preset encryption parameter can be built into the fourth data processing unit, or provided by the discrete storage or the management server. The second preset key is the communication key used for encrypting the interaction data between the storage controller and the discrete storage. It can be built into the fourth data processing unit, or provided by the storage controller or the management server. The third preset key is the storage key used for encrypting the data in the discrete storage. It can be built into the fourth data processing unit, or provided by the storage controller or the management server.

[0092] In this step, when receiving the ciphertext data sent by the third data processing unit, the fourth data processing unit can use the second preset key and the second preset encryption parameter to decrypt the ciphertext data into plaintext data. Subsequently, the plaintext data can be encrypted into ciphertext data again using the third preset key and written into the discrete storage. In addition, when reading the ciphertext data from the discrete storage, the fourth data processing unit can use the third preset key to decrypt the ciphertext data into plaintext data, and then use the second preset key and the second preset encryption parameter to encrypt the plaintext data into ciphertext data and send the ciphertext data to the third data processing unit. In this way, the data transmission security between the storage controller and the discrete storage can be ensured, and at the same time, the discrete storage can securely store data. Of course, since some memories support self-encryption, that is, the memory will encrypt the written data by itself. Therefore, the fourth data processing unit can determine whether the discrete storage supports self-encryption, and can only encrypt the data written into the discrete storage using the third preset key when it does not support self-encryption.

[0093] Based on this, before encrypting the third plaintext data into the fifth ciphertext data using the third preset key and writing the fifth ciphertext data into the discrete storage, it can further include: S6211: Determine whether the discrete storage is set with self-encryption; S6212: If self-encryption is set, send the third plaintext data to the discrete storage; S6213: If self-encryption is not set, enter the step of encrypting the third plaintext data into the fifth ciphertext data using the third preset key and writing the fifth ciphertext data into the discrete storage.

[0094] Before receiving the sixth ciphertext data sent by the discrete storage and encrypting the fifth plaintext data into the fourth plaintext data using the third preset key, it can further include: S6221: Determine whether the discrete storage is set with self-encryption; S6222: If self-encryption is set, receive the fourth plaintext data sent by the discrete storage; S6223: If self-encryption is not set, enter the step of receiving the sixth ciphertext data sent by the discrete storage and decrypting the sixth ciphertext data into the fourth plaintext data using the third preset key.

[0095] It should be noted that in the actual application scenario, steps S41 and S42 can be executed in disorder.

[0096] Furthermore, considering that there is an association between the data encryption service and the storage service performance. To facilitate the user to manually optimize the encryption and decryption methods, the second preset encryption parameter of the fourth data processing unit can be issued by the discrete storage.

[0097] Based on this, this method can also include: S631: Receive the second preset encryption parameter issued by the discrete storage and save it.

[0098] In this step, the fourth data processing unit can receive the second preset encryption parameter issued by the discrete storage to understand how the discrete storage hopes to perform encrypted communication with the storage controller.

[0099] It should be noted that the above second preset encryption parameter can be dynamically adjusted by the storage controller.

[0100] Furthermore, to separate the data encryption and decryption services from the server, the storage system can also include a management server that can provide the second preset key for the fourth data processing unit. Specifically, the fourth data processing unit can request the second preset key from the management server using its own fourth authentication information and the communication information of the third data processing unit. Among them, the fourth authentication information is used to indicate the identity of the fourth data processing unit, and the communication information of the third data processing unit is used to indicate that the fourth data processing unit requests to communicate with the third data processing unit. Furthermore, the management server can use the fourth authentication information to verify the identity of the fourth data processing unit, and after the identity verification is passed, allocate the second preset key using the communication information and return it.

[0101] Based on this, this method can also include: S641: Send its own fourth authentication information and the communication information of the third data processing unit to the management server, so that the management server can use the fourth authentication information to verify the identity of the fourth data processing unit, and after the identity verification is passed, allocate the second preset key using the communication information and return it; S642: Receive the second preset key sent by the management server and save it.

[0102] It should be noted that the specific form of the fourth authentication information is not limited in this embodiment and can be set according to actual application requirements. For example, the fourth authentication information can be a CA certificate (Certificate Authority), an identity Token information, etc.

[0103] Furthermore, to enhance the security of data transmission, the second preset key may include validity period information. When the second preset key expires, the fourth data processing unit will not be able to use this key for data encryption. Therefore, the fourth data processing unit can determine whether the second preset key has expired according to the validity period information. If it is determined that the key has expired, the fourth data processing unit can request a key from the management server again.

[0104] Based on this, the second preset key includes validity period information; the method may further include: S651: Determine whether the second preset key has expired according to the validity period information; S652: If it is determined that the second preset key has expired, enter the step of sending the fourth authentication information of itself and the communication information of the third data processing unit to the management server.

[0105] Based on the above embodiments, the above data processing process will be introduced below based on specific data writing processing procedures and data reading processing procedures.

[0106] 1) The specific data writing processing procedure is as follows: 1. In the server, send the plaintext data and the encryption instruction to the first data processing unit installed in the server, where the encryption instruction includes the encryption algorithm, encryption mode, and data block size.

[0107] 2. After step 1 is completed, the first data processing unit in the server obtains the built-in key from the server; or obtains the key from an external key management server; which specific method to adopt depends on whether the external key management server is included in the system configuration.

[0108] 3. The first data processing unit encrypts the data based on the data, instructions, and keys obtained in steps 1 and 2 to generate ciphertext.

[0109] 4. The first data processing unit sends the ciphertext generated in step 3 to the ciphertext data receiving and storing controller.

[0110] 5. The second data processing unit in the storage controller receives the ciphertext data from the server.

[0111] 6. The second data processing unit in the storage controller obtains a key from the key management within the storage controller or from an external key management server. Which method to adopt specifically depends on whether the external key management server is included in the system configuration.

[0112] 7. The second data processing unit in the storage controller decrypts the above ciphertext into plaintext data.

[0113] 8. The storage controller processes the plaintext data according to mechanisms such as data caching, data organization, and data protection.

[0114] 9. The storage controller sends the plaintext data and the encryption instruction generated in step 8 to the third data processing unit installed in the storage controller, where the encryption instruction includes the encryption algorithm, encryption mode, and data block size.

[0115] 10. After step 9 is completed, the third data processing unit in the storage controller obtains the built-in key from the storage controller or obtains the key from the external key management server. Which method to adopt specifically depends on whether the external key management server is included in the system configuration.

[0116] 11. Based on the data, instructions, and keys obtained in steps 9 and 10, the third data processing unit performs data encryption to generate ciphertext.

[0117] 12. The third data processing unit sends the ciphertext generated in step 11 to the data receiving and separating storage of the ciphertext.

[0118] 13. The fourth data processing unit in the separating storage receives the ciphertext data from the storage controller.

[0119] 14. The fourth data processing unit in the separating storage obtains the key from the key management within the separating storage or obtains the key from the external key management server. Which method to adopt specifically depends on whether the external key management server is included in the system configuration.

[0120] 15. The fourth data processing unit in the separating storage decrypts the above ciphertext into plaintext data.

[0121] 16. The separating storage processes the plaintext data according to the original logic of the storage software, including protocol parsing, data distribution organization, etc.

[0122] 17.1 If the separating storage adopts the self-encrypting drive (SED) method, then for the keys used in the data encryption and decryption processes, there is no need to obtain them from the key management server, and the keys are stored in the SED in ciphertext form.

[0123] 17.2 If the discrete storage adopts the SSD method without encryption function, the fourth data processing unit needs to be used to continue the data encryption operation.

[0124] 18. Based on step 17.2, the fourth data processing unit encrypts the data in XTS mode and obtains the key from the key management inside the discrete storage; or obtains the key from an external key management server; which specific method to adopt depends on whether the external key management server is included in the system configuration.

[0125] 19. The fourth data processing unit writes the generated ciphertext into the SSD inside the discrete storage.

[0126] 2) The data reading processing procedure The specific steps for the entire data reading processing are as follows: 1. In the server, the I / O request for reading data is sent out through the first data processing unit.

[0127] 2. The second data processing unit in the storage controller receives the I / O request from the server.

[0128] 3. The storage controller processes the I / O request according to mechanisms such as data caching, data organization, and data protection, and obtains the location information of the data to be read.

[0129] 4. The storage controller sends the address information of the I / O request to the fourth data processing unit of the discrete storage through the third data processing unit.

[0130] 5. The fourth data processing unit of the discrete storage reads the corresponding data according to the address information of the I / O.

[0131] 6.1 In the discrete storage, if SED self-encrypting SSD is used, the data obtained by the DPU is the already decrypted plaintext data.

[0132] 6.2 In the discrete storage, if SED is not used, the DPU decrypts the data in XTS mode to obtain the plaintext data.

[0133] 7. The discrete storage encapsulates the above plaintext data into a data packet for network transmission.

[0134] 8. The fourth data processing unit in the discrete storage obtains the key from the key management inside the discrete storage; or obtains the key from an external key management server; which specific method to adopt depends on whether the external key management server is included in the system configuration.

[0135] 9. The fourth data processing unit in the discrete storage encrypts the above plaintext into ciphertext data.

[0136] 10. The storage controller receives the ciphertext data through the third data processing unit. If the key management within the storage controller obtains the key; or obtains the key from an external key management server; which specific method to adopt depends on whether the system configuration includes an external key management server.

[0137] 11. The storage controller decrypts the ciphertext data.

[0138] 12. The storage controller processes the plaintext data according to mechanisms such as data caching, data organization, and data protection.

[0139] 13. The storage controller encrypts the plaintext data processed in step 12 through the second data processing unit. If the key management within the storage controller obtains the key; or obtains the key from an external key management server; which specific method to adopt depends on whether the system configuration includes an external key management server.

[0140] 14. The server receives the ciphertext data sent by the storage controller through the first data processing unit. If the key management within the storage controller obtains the key; or obtains the key from an external key management server; which specific method to adopt depends on whether the system configuration includes an external key management server.

[0141] 15. The server decrypts the ciphertext data through the first data processing unit to obtain the plaintext data.

[0142] Through the description of the above embodiments, those skilled in the art can clearly understand that the method according to the above embodiments can be implemented by means of software plus a necessary general hardware platform. Of course, it can also be implemented by hardware, but in many cases the former is a better implementation method.

[0143] The embodiments of the present invention also provide a data processing unit. Please refer to Figure 7 , Figure 7 which is a structural block diagram of a data processing unit provided by an embodiment of the present invention. The data processing unit 5 may include: A processor module 51, the processor module having an encryptor; A programmable logic device module 52, the programmable logic device module having a network transmission module and being connected to a server, a storage controller, or a discrete storage; The processor module and the programmable logic device module are used to execute the above data processing method.

[0144] It should be noted that this embodiment does not limit how the programmable logic device module 52 is connected to the server, the storage controller, or the discrete storage. For example, it can be connected based on a bus interface (such as a PCIe bus). In addition, the network transmission module can support TCP and RDMA (RoCEv2) protocols.

[0145] Please refer to Figure 8 , Figure 8 which is a structural block diagram of another data processing unit provided by an embodiment of the present invention. Among them, the processor module 51 may include a processor 511, an encryptor 512, and a memory 513. The programmable logic device 52 may include a programmable logic device 521 (FPGA). The programmable logic device 521 and the processor 511 may be connected through a bus structure (such as a PCIe bus). In addition, the data processing unit 5 further includes a network interface 54 and a bus interface 53. The programmable logic device 521 is connected to the network interface 54 and the bus interface 53. The network interface 54 is used for network data transmission, and the bus interface 53 is used to connect to a server, a storage controller, or a discrete storage.

[0146] Please refer to Figure 9 , Figure 9 which is a processing flowchart of a data processing unit provided by an embodiment of the present invention. Taking writing data as an example, the internal data processing flow of the data processing unit is as follows: 1. The programmable logic device notifies the processor to write data; 2. The processor uses DMA (Direct Memory Access) to transfer the original data to the memory; 3. The data is transferred to the CPU memory through DMA; 4. The CPU executes data encryption / decryption + data packaging; 5. The processor notifies the programmable logic device to complete data encryption / decryption and returns the data address, etc.; 6. The processor notifies the programmable logic device to read data; 7. The programmable logic device reads data from the memory to complete data writing.

[0147] An embodiment of the present invention also provides a computer-readable storage medium, in which a computer program is stored. The computer program is configured to execute the steps in any of the above-mentioned data processing method embodiments when running.

[0148] In an exemplary embodiment, the above-mentioned computer-readable storage medium may include, but is not limited to: various media such as a USB flash drive, a read-only memory (ROM for short), a random access memory (RAM for short), a mobile hard disk, a magnetic disk, or an optical disc that can store computer programs.

[0149] An embodiment of the present invention further provides a computer program product. The computer program product includes a computer program, and when the computer program is executed by a processor, the steps in any of the above-described data processing method embodiments are implemented.

[0150] An embodiment of the present invention further provides another computer program product, including a non-volatile computer-readable storage medium. The non-volatile computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the steps in any of the above-described data processing method embodiments are implemented.

[0151] Those skilled in the art can further realize that the units and algorithm steps of each example described in combination with the embodiments disclosed herein can be implemented by electronic hardware, computer software, or a combination of the two. To clearly illustrate the interchangeability of hardware and software, the components and steps of each example have been generally described according to their functions in the above description. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Skilled professionals can use different methods for each specific application to implement the described functions, but such implementation should not be considered to exceed the scope of the present invention.

[0152] The above has introduced in detail a storage system, a data processing method, a data processing unit, and a program product provided by the present invention. Specific examples are used herein to elaborate on the principles and implementation manners of the present invention. The description of the above embodiments is only used to help understand the method and its core idea of the present invention. It should be noted that for those of ordinary skill in the art in the technical field, without departing from the principle of the present invention, several improvements and modifications can be made to the present invention, and these improvements and modifications also fall within the protection scope of the present invention.

Claims

1. A storage system, characterized in that, Including a server, a storage controller, and a discrete storage, the server has a first data processing unit, the storage controller has a second data processing unit and a third data processing unit, and the discrete storage has a fourth data processing unit; Either end of the first data processing unit and the second data processing unit is used to encrypt the interaction data between the server and the storage controller by using a first preset key and a first preset encryption parameter and transmit it to the other end of the first data processing unit and the second data processing unit, and decrypt the interaction data between the server and the storage controller sent by the other end; Either end of the third data processing unit and the fourth data processing unit is used to encrypt the interaction data between the storage controller and the discrete storage by using a second preset key and a second preset encryption parameter and transmit it to the other end of the third data processing unit and the fourth data processing unit, and decrypt the interaction data between the storage controller and the discrete storage sent by the other end; The fourth data processing unit is further used to encrypt the data written into the discrete storage by using a third preset key and decrypt the data read out from the discrete storage.

2. The storage system according to claim 1, wherein It further includes a management server; The first data processing unit is further used to obtain the first preset key from the management server according to the communication information of the second data processing unit; The second data processing unit is further used to obtain the first preset key from the management server according to the communication information of the first data processing unit; The third data processing unit is further used to obtain the second preset key from the management server according to the communication information of the fourth data processing unit; The fourth data processing unit is further used to obtain the second preset key from the management server according to the communication information of the third data processing unit, and obtain the third preset key from the management server.

3. A data processing method, characterized in that, Applied to the first data processing unit in the storage system as described in claim 1 or 2, the method includes: Receiving the first plaintext data sent by the server, encrypting the first plaintext data into first ciphertext data by using a first preset key and a first preset encryption parameter, and sending the first ciphertext data to the second data processing unit; Receiving the second ciphertext data sent by the second data processing unit, decrypting the second ciphertext data into second plaintext data by using the first preset key and the first preset encryption parameter, and sending the second plaintext data to the server.

4. The data processing method according to claim 3, wherein It further includes: Receiving the first preset encryption parameter sent by the server and saving it.

5. The data processing method according to claim 3 or 4, characterized in that The storage system further includes a management server; The method further includes: Sending its own first authentication information and the communication information of the second data processing unit to the management server, so that the management server uses the first authentication information to verify the identity of the first data processing unit, and distributes the first preset key by using the communication information after the identity verification passes; Receiving the first preset key sent by the management server and saving it.

6. The data processing method according to claim 5, wherein The first preset key includes validity period information; The method further includes: Judging whether the first preset key has expired according to the validity period information; If it is determined that the first preset key has expired, then enter the step of sending its own first authentication information and the communication information of the second data processing unit to the management server.

7. A data processing method, characterized in that, Applied to the second data processing unit in the storage system as described in claim 1 or 2, the method includes: Receiving the first ciphertext data sent by the first data processing unit, decrypting the first ciphertext data into first plaintext data by using the first preset key and the first preset encryption parameter, and sending the first plaintext data to the storage controller; Receiving the second plaintext data sent by the storage controller, encrypting the second plaintext data into second ciphertext data by using the first preset key and the first preset encryption parameter, and sending the second ciphertext data to the first data processing unit.

8. The data processing method according to claim 7, wherein It further includes: Receiving and saving the first preset encryption parameter sent by the storage controller.

9. The data processing method according to claim 7 or 8, characterized in that The storage system further includes a management server; The method further includes: Sending its own second authentication information and the communication information of the first data processing unit to the management server, so that the management server uses the second authentication information to verify the identity of the second data processing unit, and after the identity verification is passed, uses the communication information to allocate the first preset key; Receiving and saving the first preset key sent by the management server.

10. The data processing method according to claim 9, wherein The first preset key includes validity period information; The method further includes: Judging whether the first preset key has expired according to the validity period information; If it is determined that the first preset key has expired, then enter the step of sending its own second authentication information and the communication information of the first data processing unit to the management server.

11. A data processing method, characterized in that, Applied to the third data processing unit in the storage system as described in claim 1 or 2, the method includes: Receiving the third plaintext data sent by the storage controller, encrypting the third plaintext data into third ciphertext data by using the second preset key and the second preset encryption parameter, and sending the third ciphertext data to the fourth data processing unit; Receiving the fourth ciphertext data sent by the fourth data processing unit, decrypting the fourth ciphertext data into fourth plaintext data by using the second preset key and the second preset encryption parameter, and sending the fourth plaintext data to the storage controller.

12. The data processing method according to claim 11, wherein It further includes: Receiving and saving the second preset encryption parameter sent by the storage controller.

13. The data processing method according to claim 11 or 12, characterized in that, The storage system further includes a management server; The method further includes: Sending its own third authentication information and the communication information of the fourth data processing unit to the management server, so that the management server uses the third authentication information to verify the identity of the third data processing unit, and after the identity verification is passed, uses the communication information to allocate the second preset key; Receiving and saving the second preset key sent by the management server.

14. The data processing method according to claim 13, wherein The second preset key includes validity period information; The method further includes: Judging whether the second preset key has expired according to the validity period information; If it is determined that the second preset key has expired, proceed to the step of sending one's own third authentication information and the communication information of the fourth data processing unit to the management server.

15. A data processing method, characterized in that, A fourth data processing unit applied to the storage system according to claim 1 or 2, the method comprising: Receiving third ciphertext data sent by a third data processing unit, decrypting the third ciphertext data into third plaintext data by using a second preset key and second preset encryption parameters, encrypting the third plaintext data into fifth ciphertext data by using a third preset key, and writing the fifth ciphertext data into a discrete storage; Receiving sixth ciphertext data sent by the discrete storage, decrypting the sixth ciphertext data into fourth plaintext data by using the third preset key, encrypting the fourth plaintext data into fourth ciphertext data by using the second preset key and the second preset encryption parameters, and sending the fourth ciphertext data to the third data processing unit.

16. The data processing method according to claim 15, wherein Further comprising: Receiving and saving the second preset encryption parameters sent by the discrete storage.

17. The data processing method according to claim 15, wherein Before encrypting the third plaintext data into fifth ciphertext data by using the third preset key and writing the fifth ciphertext data into the discrete storage, further comprising: Determining whether the discrete storage is set for self-encryption; If self-encryption is set, sending the third plaintext data to the discrete storage; If self-encryption is not set, proceed to the step of encrypting the third plaintext data into fifth ciphertext data by using the third preset key and writing the fifth ciphertext data into the discrete storage; Before receiving the sixth ciphertext data sent by the discrete storage and decrypting the sixth ciphertext data into fourth plaintext data by using the third preset key, further comprising: Determining whether the discrete storage is set for self-encryption; If self-encryption is set, receiving the fourth plaintext data sent by the discrete storage; If self-encryption is not set, proceed to the step of receiving the sixth ciphertext data sent by the discrete storage and decrypting the sixth ciphertext data into fourth plaintext data by using the third preset key.

18. The data processing method according to any one of claims 15 to 17, characterized in that, The storage system further comprises a management server; The method further comprises: Sending one's own fourth authentication information and the communication information of the third data processing unit to the management server, so that the management server verifies the identity of the fourth data processing unit by using the fourth authentication information, and after the identity authentication is passed, allocates the second preset key by using the communication information and returns; Receiving and saving the second preset key sent by the management server.

19. The data processing method according to claim 18, wherein The second preset key contains validity period information; The method further comprises: Judging whether the second preset key has expired according to the validity period information; If it is determined that the second preset key has expired, proceed to the step of sending one's own fourth authentication information and the communication information of the third data processing unit to the management server.

20. A data processing unit, characterized in that, Comprising: A processor module, the processor module having an encryptor; A programmable logic device module, the programmable logic device module having a network transmission module and being connected to a server, a storage controller or a discrete storage; The processor module and the programmable logic device module are used to execute the data processing method according to any one of claims 3 to 6, or execute the data processing method according to any one of claims 7 to 10, or execute the data processing method according to any one of claims 11 to 14, or execute the data processing method according to any one of claims 15 to 19.

21. A computer program product, comprising a computer program or instructions, characterized in that, When the computer program or instruction is executed by a processor, it implements the data processing method according to any one of claims 3 to 6, or the data processing method according to any one of claims 7 to 10, or the data processing method according to any one of claims 11 to 14, or the data processing method according to any one of claims 15 to 19.

22. A non-volatile computer-readable storage medium, characterized in that, The non-volatile computer-readable storage medium stores computer-executable instructions, and when the computer-executable instructions are loaded and executed by a processor, it implements the data processing method according to any one of claims 3 to 6, or the data processing method according to any one of claims 7 to 10, or the data processing method according to any one of claims 11 to 14, or the data processing method according to any one of claims 15 to 19.

Citation Information

Patent Citations

  • Data read-write method of distributed storage system

    CN110650191A

  • Storage controller, client system, and method of operating storage controller

    CN113946840A

  • Data self-encryption device and method

    CN115865448A

  • Data encryption and decryption method and device

    CN115943381A

  • Data reading and writing method, device, equipment, system, storage medium and storage system

    CN117234427A