Data secrecy method and device based on permission sharing operation of encrypted PSSD and medium

By performing permission partitioning and group permission management on PSSD, combined with digital certificate or token verification, the problem of sensitive data leakage and inefficiency of encrypted PSSD when shared by multiple people is solved, and flexible data sharing and security management is achieved.

CN120337269AActive Publication Date: 2025-07-18HUBEI CHANGJIANG WANRUN SEMICON TECH CO LTD
View PDF 7 Cites 0 Cited by

Patent Information

Application Number
CN202510828803.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-20
Publication Date
2025-07-18
Estimated Expiration
2045-06-20

AI Technical Summary

Technical Problem

When existing encrypted PSSDs are shared by multiple people or teams, there is a problem of risk of sensitive data breaches and inefficient verification.

Method used

Permission partitioning of PSSD, setting the characteristic attributes of the encryption area, and generating the user's authentication key through group numbers, member numbers and permission values, combining digital certificates or tokens for permission verification, recording error counts to adjust the permission level, ensuring the security and flexibility of data sharing.

Benefits of technology

It realizes step-by-step data sharing and management among multiple members, flexibly manages disk space according to permission levels, and improves the security and verification efficiency of data sharing.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120337269A_ABST
    Figure CN120337269A_ABST
Patent Text Reader

Abstract

The invention discloses a data secrecy method and device based on permission sharing operation of an encrypted PSSD and a medium. The method comprises the following steps: 1) performing permission partitioning on the PSSD; 2) setting an encryption area feature attribute; an attribute structure Lij is set for each encryption area, and accessible user groups and corresponding lowest user permissions of the encryption areas are specified in the structure; 3) allocating unlocking permissions to each group of users; 3) when a request of accessing the encryption area by the user is received, performing access permission verification on the user; and 4) if the identity authority level of the user executing unlocking currently is greater than the encrypted disk partition authority and the accessible user group is matched, automatically unlocking the disk space with the matched authority, otherwise, sending verification failure information, and recording error counting for each verification failure. According to the method, stepped data sharing and management of personnel among the groups can be achieved, reading and writing of data among the groups are achieved according to user permission, and disk encryption space can be managed more flexibly.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to data security technology, and in particular, to a data confidentiality method, device and medium for permission sharing operations based on encrypted PSSD. Background Art

[0002] In the field of mobile PSSD (Portable Solid State Drive), currently, the data hard disks on the market usually have at most two partitions: a data area and a CD ROM area. Among them, the CD ROM area has a fixed size and is a read-only area for storing corresponding manufacturer software and instructions; the data area can be used to store user data. At the same time, the data area can be partitioned by the operating system into multiple system drive letters, and users can classify the data to be stored and store it in different logical partitions according to their preferences.

[0003] In order to prevent the risk of data leakage, R & D personnel of mobile PSSD manufacturers will add various physical unlocking verifications to the original SSD. For example, authentication and unlocking of disk space can be completed through methods such as fingerprint, digital password, NFC, Bluetooth, etc. Data transmission can also be encrypted through full algorithm encryption such as AES-256 data encryption and SM4 algorithm encryption. There are also manufacturers who combine the two to make the security higher. Even more, hardware encryption is introduced to make the overall security of encrypted PSSD higher.

[0004] The PSSD encrypted by the above security scheme can well protect the data in the disk and will not be read even in the case of hardware replacement without key authentication. However, this type of encrypted PSSD is often not suitable for multiple people or teams to share. The reason is that after obtaining the key for such an encrypted hard disk, all data can be read, regardless of whether the person who unlocks has the permission to operate the relevant content.

[0005] Therefore, in a team, if this single encrypted PSSD is shared, there may be a risk that some sensitive data will be disclosed by people without permission. If multiple encrypted PSSDs are used, in the whole team, due to the large number of personnel for authentication, encryption and decryption, the mutual reading and copying of data may affect the efficiency of the entire system operation. Summary of the Invention

[0006] The technical problem to be solved by the present invention is to provide a data confidentiality method, device and medium for permission sharing operations based on encrypted PSSD in view of the defects in the prior art.

[0007] The technical solution adopted by the present invention to solve its technical problems is: A data confidentiality method for permission sharing operations based on encrypted PSSD, including the following steps 1) Partition the permissions of the PSSD, including: a CD ROM area, a shared non-encrypted area, and multiple encrypted areas; Set the permissions for each partition as follows: For the CD ROM area and the shared non-encrypted area, every user can directly access them. For the encrypted areas, permission verification is required. Among them, the CD ROM area is set to read-only, the shared non-encrypted area is set to read-write, and for the encrypted areas, they are set to be readable and writable after the user passes the verification; 2) Set the characteristic attributes of the encrypted areas; Set an attribute structure L for each encrypted area ij , which specifies the accessible user groups of the encrypted area and the corresponding minimum user permissions within the structure; 3) Assign unlocking permissions to the preset groups of users, and set the authentication key permission level for each user. The authentication key permission level includes the user's group number, the user's internal group number, and the permission value; 3) When receiving a request from a user to access an encrypted area, verify the user's access permissions; 4) If the identity permission level of the currently executing unlocking user is greater than the permission of the accessed encrypted area and the accessible user groups match, automatically unlock the disk space with the matching permissions, thereby enabling data to be readable and writable. Otherwise, send a verification failure message and record the error count for each verification failure.

[0008] According to the above solution, in step 2), L ij = (c, d), where: c represents the user's group number; d is composed of the group c and the minimum read-write opening permission m in this group; d = Encrypt(c||m) Among them, || represents string concatenation; Encrypt represents an encryption function.

[0009] According to the above solution, when the identity permission level of the currently executing unlocking user is greater than the permission of the encrypted disk partition and the accessible user groups match, that is, Acess(G ij , L ij ) = 1, indicating that the permission match is successful. The verification conditions are as follows: 1) The group match is successful: Satisfy c = floor(a / 8), where floor is the floor function; 2) The permission level check passes: Satisfy j ≥ m, that is, Decrypt(b) ≥ Decrypt(d), where Decrypt is the decryption function corresponding to Encrypt.

[0010] According to the above solution, in step 3), the authentication key permission level of each user is set as follows: The authentication key permission level assigned to each user is G ij ; G ij = (a, b); Among them, a represents the member number of the user, a = g * 8 + i; where g is the group number of the user and i is the number within the member group; b is the permission value, generated according to the combined member number i and the assigned permission level j: b = Encrypt(i || j || k); Among them, k is a system key, || represents string concatenation; Encrypt represents the encryption function.

[0011] According to the above solution, each user in step 3) will be assigned a digital certificate or token T ij , T ij contains the user's permission information and signature; T ij = Sign ( G ij , v ); Among them, v is a multi-valued field, containing one or more verification information; the verification information includes: key, fingerprint ID, one-time password.

[0012] According to the above solution, in step 2), d is composed of the group c, the lowest read / write enable permission m in the group, and the combined verification identifier n; d = Encrypt(c || m || n) Among them, || represents string concatenation; Encrypt represents the encryption algorithm; n is a combined verification identifier, an 8-bit binary data, used to mark whether the disk is in the combined unlocking mode, for mapping with the digital certificate or token T ij ; when n is marked as non-0, the disk verification will match whether the token marked by n passes the verification. Only when all tokens pass can the disk be unlocked.

[0013] According to the above solution, Acess(G ij , L ij ) = 1 indicates that the permission match is successful, and the verification conditions are as follows: 1) The group match is successful: satisfying c = floor(a / 8), where floor is the floor function; 2) The permission level check passes: j≥m is satisfied, that is, Decrypt(b) ≥ Decrypt(d), where Decrypt is the decryption function corresponding to Encrypt; 3) The token T corresponding to bit(n) is satisfied ij The verification passes, and bit is the binary bit-taking 1 sequence function.

[0014] According to the above solution, in step 4), the error count of the current level verification permission is greater than the verification quantity threshold of the corresponding set permission level, and the L corresponding to this disk ij The unlock permission of the level needs to be increased by 1 level, that is, the minimum read / write enable permission m = m + 1 until the highest level permission; After the verification error count of the highest level permission exceeds the set threshold, all data on the disk will be automatically destroyed.

[0015] The present invention also provides an electronic device, including: One or more processors; And A storage device for storing one or more programs, wherein, when the one or more programs are executed by the one or more processors, the one or more processors are caused to execute the method described in any one of the above solutions.

[0016] The present invention also provides a computer-readable storage medium, on which a computer program is stored, and when the computer program is executed by a processor, the method described in any one of the above solutions is implemented.

[0017] The beneficial effects produced by the present invention are: 1. The present invention provides a method implementation for multi-member sharing of encrypted data according to permission levels, which can achieve stepped data sharing and management among group members, and read and write group data according to user permissions, so as to manage the disk encryption space more flexibly; 2. The present invention provides a disk unlocking method of combined verification, making the usage scenario more flexible and the verification method more secure. BRIEF DESCRIPTION OF THE DRAWINGS

[0018] The present invention will be further described below in conjunction with the drawings and embodiments. In the drawings: Figure 1 is the method flow chart of the embodiment of the present invention; Figure 2 is the permission matching method flow chart of the embodiment of the present invention; Figure 3 is the token verification schematic diagram of the embodiment of the present invention; Figure 4 is the permission verification result schematic diagram of the embodiment of the present invention. Detailed implementation manners

[0019] In order to make the objectives, technical solutions and advantages of the present invention more clear and understandable, the present invention will be further described in detail below in conjunction with embodiments. It should be understood that the specific embodiments described herein are only used to explain the present invention and are not used to limit the present invention.

[0020] Embodiment 1: As Figure 1 shown, a data confidentiality method for permission sharing operations based on encrypted PSSD includes the following steps 1) Perform permission partitioning on PSSD, including: CD ROM area, shared non-encrypted area, and multiple encrypted areas; The permissions for each partition are set as follows: For the CD ROM area and the shared non-encrypted area, each user can directly access. For the encrypted area, permission verification is required; among them, the CD ROM area is set to read-only, the shared non-encrypted area is set to read-write, and for the encrypted area, it is set to read-write after the user passes the verification; 2) Set the characteristic attributes of the encrypted area; Each encrypted area is provided with an attribute structure L ij , and the accessible user groups and the corresponding minimum user permissions of the specified encrypted area are included in this structure; L ij = (c, d), where: c represents the group number of the user; d is composed of the group c and the minimum read-write enable permission m in this group; d = Encrypt( c||m) where, || represents string concatenation; Encrypt represents an encryption function; 3) Assign unlocking permissions to each group of users and enter the identification information; among them, each group of users is formed by grouping multiple members according to work needs; The identification information includes the authentication key permission level G ij assigned to each user; and the identity authentication information of each user, such as fingerprint information; G ij = (a, b); where, a represents the member number of the user, a = g*8 + i; where, g is the group number of the user, and i is the number within the member group; b is the permission value, which is generated by combining the member number i and the permission level j: b = Encrypt( i||j||k); Among them, k is a system key, || represents string concatenation; Encrypt represents an encryption function; 3) When receiving a request from a user to access the encrypted area, verify the user's access permission; Before verifying the permission, the user's personal identity information can be verified first, such as fingerprint verification; 4) If the user identity permission level currently performing the unlocking is greater than the encrypted disk partition permission and the accessible user group matches, that is, Acess(G ij ,L ij ) = 1, automatically unlock the disk space with the matching permission, so as to realize the read and write of data. Otherwise, send a verification failure message and record the error count for each verification failure.

[0021] Acess(G ij ,L ij ) = 1 indicates that the permission match is successful, and the verification conditions are as follows: 4.1) The group match is successful: satisfy c = floor(a / 8), where floor is the floor function; 4.2) The permission level check passes: satisfy j ≥ m, that is, Decrypt(b) ≥ Decrypt(d), where Decrypt is the decryption function corresponding to Encrypt.

[0022] The error count of the current level verification permission is greater than the verification quantity threshold corresponding to the set permission level. The L corresponding to this disk ij level unlocking permission is increased by 1 level, that is, the lowest read and write opening permission m = m + 1 until the highest level permission; When the verification error count of the highest level permission exceeds the set threshold, all data on the disk will be automatically destroyed.

[0023] Embodiment 2: As Figure 1 shown, a data confidentiality method for permission sharing operations based on an encrypted PSSD includes the following steps 1) Perform permission partitioning on the PSSD, including: CD ROM area, shared non-encrypted area, and multiple encrypted areas; The permissions for each partition are set as follows: For the CD ROM area and the shared non-encrypted area, every user can directly access. For the encrypted area, the permission needs to be verified. Among them, the CD ROM area is set to read-only, the shared non-encrypted area is set to read-write, and for the encrypted area, it is set to read-write after the user passes the verification; 2) Set the characteristic attributes of the encrypted area; For each encrypted area, there is an attribute structure L ij, the accessible user groups and corresponding minimum user permissions within this structure are specified; L ij = (c,d), where: c represents the group number of the user; d consists of the group c, the minimum read / write enable permission m in this group, and the combined verification identifier n; d = Encrypt( c||m||n) where, || represents string concatenation; Encrypt represents an encryption algorithm; n is a combined verification identifier, which is an 8-bit binary data and is used to mark whether the disk is in the combined unlocking mode and is used for mapping with the digital certificate or token T ij ; when n is marked as non-0, the disk verification will match whether the token marked by n passes the verification. Only when all tokens pass can the disk be unlocked.

[0024] 3) Assign unlocking permissions to each group of users and enter the identification information; The identification information includes the authentication key permission level G assigned to each user ij ; and the identity authentication information of each user, such as fingerprint information; G ij = (a,b); where, a represents the member number of the user, a = g*8+i; where, g is the group number of the user and i is the number within the member group; b is the permission value, which is generated by combining the member number i and the permission level j: b=Encrypt( i||j||k); where, k is a system key, || represents string concatenation; Encrypt represents an encryption function; In this embodiment, before each access, each user is also assigned a digital certificate or token T ij , T ij contains the user's permission information and signature; T ij = Sign ( G ij , v ); where, v is a multi-valued field that contains one or more verification information; the verification information includes: one or more of a key, a fingerprint ID, and a one-time password.

[0025] 4) When receiving a request from a user to access the encrypted area, verify the user's access permissions; Before permission verification, user identity information verification can be performed first, such as fingerprint verification; 5) If the user identity permission level for the current unlocking is greater than the encrypted disk partition permission and the accessible user group matches, that is, Acess(G ij ,L ij ) = 1, the disk space with the matching permission is automatically unlocked, thus enabling read and write access to the data. Otherwise, a verification failure message is sent, and an error count is recorded for each verification failure.

[0026] Such as Figure 2 , Acess(G ij ,L ij ) = 1 indicates successful permission matching. The verification conditions are as follows: 1) Successful group matching: Satisfy c = floor(a / 8), where floor is the floor function; 2) Passed permission level check: Satisfy j ≥ m, that is, Decrypt(b) ≥ Decrypt(d), where Decrypt is the decryption function corresponding to Encrypt; 3) The token T corresponding to bit(n) passes the verification, where bit is the binary bit-taking 1 sequence function; ij The verification passes, and bit is the binary bit-taking 1 sequence function; When n is marked as non-zero, the disk verification will check whether the token marked by n passes the verification. Only when all tokens pass can the disk be unlocked, as Figure 3 shown.

[0027] Acess(G ij ,L ij ) = 0 indicates failed permission matching and inability to access, as Figure 4 shown; When the error count of the current level verification permission is greater than the verification quantity threshold corresponding to the set permission level, the unlocking permission of the disk corresponding to L ij level needs to be increased by 1 level, that is, the minimum read and write opening permission m = m + 1 until the highest level permission; For the error counting and permission adjustment mechanism, each time a verification fails, the error count Ne of the corresponding encrypted area is increased, and the threshold is set to s. When Ne > s, G ij ' is recalculated and generated. At this time, b' = Encrypt(i||(m + 1)||k).

[0028] When the verification error count of the highest level permission exceeds the set threshold, all data on the disk will be automatically destroyed.

[0029] For the operator with the highest permission, the threshold M top can be set separately. When the error count Ne top>M top When top is triggered, the disk data destruction mechanism will clear all partition information settings and verification methods on the disk from the bottom layer.

[0030] It should be understood that those of ordinary skill in the art can make improvements or transformations according to the above description, and all such improvements and transformations shall fall within the protection scope of the appended claims of the present invention.

Claims

1. A data confidentiality method for permission sharing operations based on encrypted PSSD, characterized in that, It includes the following steps: 1) Perform permission partitioning on the PSSD, including: a CD ROM area, a shared non-encrypted area, and multiple encrypted areas; The permissions for each partition are set as follows: For the CD ROM area and the shared non-encrypted area, each user can directly access. For the encrypted areas, permission verification is required. Among them, the CD ROM area is set to read-only, the shared non-encrypted area is set to read-write, and for the encrypted areas, they are set to be read-write after the user passes the verification; 2) Set the characteristic attributes of the encrypted areas; For each encrypted area, there is an attribute structure L ij , which specifies the accessible user groups of the designated encrypted area and the corresponding minimum user permissions; 3) Assign unlocking permissions to the preset groups of users, and set the authentication key permission level for each user. The authentication key permission level includes the group number of the user, the in-group number of the user, and the permission value; 3) When receiving a request from a user to access an encrypted area, perform access permission verification on the user; 4) If the identity permission level of the currently executing unlocking user is greater than the permission of the accessed encrypted area and the accessible user group matches, unlock the disk space with the matching permission, so as to achieve readable and writable data. Otherwise, send a verification failure message and record the error count for each verification failure.

2. The data confidentiality method for permission sharing operations based on encrypted PSSD according to claim 1, wherein In step 2), L ij = (c, d), where: c represents the group number of the user; d is composed of the group c and the lowest read-write enable permission m in this group; d = Encrypt( c||m) Among them, || represents string concatenation; Encrypt represents the encryption function.

3. The data confidentiality method for permission sharing operations based on encrypted PSSD according to claim 2, characterized in that, In step 4), Acess(G ij ,L ij ) = 1 indicates that the permission match is successful, and the verification conditions are as follows: 1) The group match is successful: It satisfies c = floor(a / 8), where floor is the floor function; 2) The permission level check passes: It satisfies j≥m, that is, Decrypt(b) ≥Decrypt(d), and Decrypt is the decryption function corresponding to Encrypt.

4. The data confidentiality method for permission sharing operations based on encrypted PSSD according to claim 1, characterized in that In step 3) above, the authentication key permission level for each user is set as follows: The authentication key permission level assigned to each user personnel is G ij ; G ij = (a, b); Among them, a represents the member number of the user, a = g*8 + i; where g is the group number of the user and i is the in-group number; b is the permission value, which is generated according to the combined member number i and the assigned permission level j: b = Encrypt( i||j||k); Among them, k is a system key, || represents string concatenation; Encrypt represents the encryption function.

5. The data confidentiality method for permission sharing operation based on encrypted PSSD according to claim 1 or 4, characterized in that, In step 3), each user is assigned a digital certificate or token T ij , T ij which contains the user's permission information and signature; T ij = Sign ( G ij , v ); Among them, v is a multi-valued field, containing one or more verification information; the verification information includes: key, fingerprint ID, one-time password.

6. The data confidentiality method for permission sharing operation based on encrypted PSSD according to claim 5, characterized in that, In step 2) above, d is composed of the group c, the lowest read-write enable permission m in this group, and the combined verification identifier n; d = Encrypt( c||m||n) Among them, || represents string concatenation; Encrypt represents an encryption algorithm; n is a combined verification identifier, which is an 8-bit binary data and is used to mark whether the disk is in the combined unlocking mode and is used for mapping with the digital certificate or token T ij ; when n is marked as non-0, the disk verification will match whether the token marked by n passes the verification. Only when all tokens pass can the disk be unlocked.

7. The data confidentiality method for permission sharing operation based on encrypted PSSD according to claim 6, characterized in that, In step 4), when the user identity permission level currently performing unlocking is greater than the encrypted disk partition permission and the accessible user group matches, i.e., Acess(G ij ,L ij ) = 1, it indicates that the permission match is successful, and the verification conditions are as follows: 1) The group match is successful: It satisfies c = floor(a / 8), where floor is the floor function; 2) The permission level check passes: It satisfies j≥m, that is, Decrypt(b) ≥Decrypt(d), and Decrypt is the decryption function corresponding to Encrypt; 3) Meet the token T corresponding to bit(n) ij Verification passed. bit is a binary bit-taking 1 sequence function.

8. The data confidentiality method for permission sharing operations based on encrypted PSSD according to claim 1, characterized in that, In step 4), the error count of the current level verification permission is greater than the verification quantity threshold corresponding to the set permission level, and the L corresponding to this disk ij The unlock permission level of the level needs to be increased by 1 level, that is, the minimum read / write enable permission m = m + 1 until the highest level permission; When the number of verification errors at the highest level of permission exceeds the set threshold, all the data on the disk will be automatically destroyed.

9. An electronic device, characterized in that it includes: one or more processors; and a storage device for storing one or more programs, Wherein, when the one or more programs are executed by the one or more processors, the one or more processors are caused to execute the method according to any one of claims 1 to 8.

10. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, the method according to any one of claims 1 to 8 is implemented.

Citation Information

Patent Citations

  • Equipment sharing realization method and system

    CN107087009A

  • SSD multi-partition login method based on BIOS security mechanism and storage medium

    CN111079106A

  • File sharing method and device, equipment and storage medium

    CN116578543A

  • Data encryption method and device for eMMC storage device

    CN119293832A

  • Docking station remote control system based on cloud management

    CN120030523A