System partition starting method and device capable of achieving dual encryption, equipment and product
Through dual encryption of the system storage unit and the configuration file storage unit, the problem of data security of the operating system in different application scenarios is solved, independent protection of system partitions and efficient data isolation are achieved, and the needs of multiple application scenarios are adapted.
Patent Information
- Application Number
- CN202510845806.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-24
- Publication Date
- 2025-07-22
- Estimated Expiration
- 2045-06-24
AI Technical Summary
In the prior art, it is difficult to achieve independent and non-interference in different application scenarios of data security of operating systems. Block device encryption method cannot protect the entire system partition, and file system-level encryption method poses security risks.
The dual encryption method is adopted to encrypt the system storage unit and the configuration file storage unit respectively. The key is stored in the configuration file storage unit or the key storage device by using the LUKS encryption method and the file system-level encryption method, and the decryption key is obtained through the grub startup item for mounting.
It realizes data isolation and confidentiality of multiple system storage units, improves data confidentiality and reliability, adapts to the needs of different application scenarios, and enhances security.
Smart Images

Figure CN120353515A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of system encryption, and in particular relates to a system partition startup method, device, equipment and product capable of dual encryption. Background Art
[0002] With the rapid development of information technology, data security has become an important issue that cannot be ignored in various fields, especially the data security of operating systems has received more extensive attention. Usually, users have different computing performance and data security requirements for computer operating systems in different application scenarios, and the data in each operation scenario needs to be independent and non-interfering with each other. For example, the same computer is used by multiple users or teams, and each user team needs to ensure the mutual isolation and protection of its internal data.
[0003] Under the existing technical conditions, to meet the above requirements, the dual-system block device encryption method or the file system-level encryption method is usually used. However, the file system-level encryption method can usually only encrypt a single file or directory and cannot protect the entire system partition. Some data in system usage records and related metadata do not have privacy; while the block device encryption method only encrypts a single system partition, and the decryption script or key file exists in the temporary root file system in plain text, so there are also relatively large security risks. Summary of the Invention
[0004] In view of this, the present invention aims to overcome the defects in the prior art and proposes a system partition startup method, device, equipment and product capable of dual encryption.
[0005] To achieve the above object, the technical solution of the present invention is realized as follows: In a first aspect, the present invention discloses a system partition startup method capable of dual encryption, including: Establish a plurality of system storage units including partitions, and establish corresponding configuration file storage units for each system storage unit. The partition mounting configuration files of the system storage units are stored in the corresponding configuration file storage units; Use a first encryption method to encrypt the system storage units respectively, and store the keys in the corresponding configuration file storage units or key storage devices; Use a second encryption method to encrypt the configuration file storage units, and store the keys at a preset key acquisition address; When selecting any grub startup item to start, obtain the key according to the preset key acquisition address corresponding to the grub startup item to decrypt the corresponding configuration file storage unit and obtain the partition mounting configuration file; Use the key obtained from the key storage device or the decrypted configuration file storage unit to decrypt the system storage unit, and mount the decrypted system storage unit according to the corresponding partition mount configuration file.
[0006] In an embodiment of the present invention, when any grub boot item is selected to start, obtaining the key to decrypt the corresponding configuration file storage unit according to the preset key acquisition address corresponding to the grub boot item includes: establishing an associated configuration file, which is used to record the correspondence among the grub boot item, the preset key acquisition address, and the configuration file storage unit. When any grub boot item is selected to start, query the associated configuration file, and obtain the key to decrypt the corresponding configuration file storage unit according to the corresponding preset key acquisition address.
[0007] In an embodiment of the present invention, the first encryption method is the LUKS encryption method, and the second encryption method is the file system-level encryption method.
[0008] In an embodiment of the present invention, the system storage unit includes a ROOT system root partition and a DATA data partition.
[0009] In an embodiment of the present invention, the configuration file storage unit is stored in the temporary root file system.
[0010] In an embodiment of the present invention, establishing a plurality of system storage units and encrypting the system storage units respectively using the first encryption method includes: the keys of different system storage units are different.
[0011] In an embodiment of the present invention, the key storage device includes any one of a Ukey, a trusted module platform device, and a password server.
[0012] In a second aspect, the present invention discloses a system partition startup device capable of dual encryption. The device includes: A building module, which is used to build a plurality of system storage units including partitions, establish a corresponding configuration file storage unit for each system storage unit, and the partition mount configuration file of the system storage unit is stored in the corresponding configuration file storage unit; A first encryption module, which is used to encrypt the system storage units respectively using the first encryption method, and the key is stored in the corresponding configuration file storage unit or the key storage device; A second encryption module, which is used to encrypt the configuration file storage unit using the second encryption method, and the key is stored at the preset key acquisition address; A startup module, which is used to obtain the key to decrypt the corresponding configuration file storage unit according to the preset key acquisition address corresponding to the grub boot item when any grub boot item is selected to start, and obtain the partition mount configuration file; A mounting module is used to decrypt the system storage unit by using the key obtained from the key storage device or the decrypted configuration file storage unit, and mount the decrypted system storage unit according to the corresponding partition mounting configuration file.
[0013] In a third aspect, the present invention discloses an electronic device, including: one or more processors; a storage device for storing one or more programs, wherein when the one or more programs are executed by the one or more processors, the one or more processors are caused to execute the above method.
[0014] In a fourth aspect, the present invention discloses a computer program product, including a computer program which, when executed by a processor, implements the above method.
[0015] Compared with the prior art, the present invention has the following advantages: The present invention discloses a system partition startup method, device, equipment and product capable of dual encryption, including establishing a plurality of system storage units each containing partitions, and establishing a corresponding configuration file storage unit for each system storage unit; encrypting the system storage units respectively by using a first encryption method, and storing the key in the corresponding configuration file storage unit or the key storage device; encrypting the configuration file storage unit by using a second encryption method, and storing the key at a preset key acquisition address; decrypting the system storage unit by using the key obtained from the key storage device or the decrypted configuration file storage unit, and mounting the decrypted system storage unit according to the corresponding partition mounting configuration file. The present invention discloses a system partition startup method, device, equipment and product capable of dual encryption, which can perform the first encryption on a plurality of system storage units, and can perform the second encryption on the configuration file storage unit storing the key. The setting of a plurality of system storage units can realize the selection of mounting different systems according to the requirements of application scenarios, so as to realize the mutual isolation and confidentiality of data; the setting of dual encryption further improves the confidentiality effect of data, and has the characteristics of good confidentiality effect, wide application range and high reliability. BRIEF DESCRIPTION OF THE DRAWINGS
[0016] The drawings constituting a part of the present invention are used to provide a further understanding of the present invention. The schematic embodiments of the present invention and their descriptions are used to explain the present invention and do not constitute an improper limitation to the present invention.
[0017] In the drawings: Figure 1 is a schematic diagram of the principle of a system partition startup method capable of dual encryption according to an embodiment of the present invention; Figure 2 is a schematic diagram of a system partition startup method capable of dual encryption according to an embodiment of the present invention; Figure 3 Schematic diagram of the configuration file associated with a system partition startup method capable of dual encryption according to an embodiment of the present invention; Figure 4 Schematic diagram of the system storage unit of a system partition startup method capable of dual encryption according to an embodiment of the present invention; Figure 5 Schematic diagram of a system partition startup device capable of dual encryption according to an embodiment of the present invention; Figure 6 Schematic diagram of an electronic device for system partition startup capable of dual encryption according to an embodiment of the present invention. Detailed implementation manners
[0018] It should be noted that, without conflict, the embodiments in the present invention and the features in the embodiments may be combined with each other.
[0019] In the description of the present invention, it should be further noted that the terms "first", "second", etc. are only used for descriptive purposes and cannot be understood as indicating or implying relative importance or implicitly specifying the quantity of the indicated technical features. Thus, the features defined with "first", "second", etc. may explicitly or implicitly include one or more of such features. In the description of the present invention, unless otherwise specified, the meaning of "a plurality of" is two or more.
[0020] The principles of a system partition startup method, device, equipment, and product capable of dual encryption disclosed in the present invention are as follows Figure 1 shown. In the prior art, dual systems are usually implemented through block device encryption or file system level encryption. However, the file system level encryption can usually only encrypt a single file or directory and cannot protect the entire system partition. While the block device encryption only encrypts a single system partition, and the decryption script or key file exists in the temporary root file system in plain text, which also has relatively large security risks. The present invention discloses a system partition startup method, device, equipment, and product capable of dual encryption, which can perform the first encryption on multiple system storage units and can perform the second encryption on the configuration file storage unit storing the key. The setting of multiple system storage units can realize the selection of different systems to be mounted according to the requirements of the application scenario to achieve mutual isolation and confidentiality of data. The setting of dual encryption further improves the confidentiality effect of data, and has the characteristics of good confidentiality effect, wide application range, and high reliability.
[0021] The present invention will be described in detail below with reference to the accompanying drawings and in conjunction with the embodiments.
[0022] An embodiment disclosed by the present invention, as Figure 2 shown, a system partition startup method capable of dual encryption includes: Step S201: Establish a number of system storage units each containing partitions, and establish a corresponding configuration file storage unit for each system storage unit. The partition mounting configuration of the system storage unit is stored in the corresponding configuration file storage unit. In this embodiment, step S201 is executed during the system installation phase.
[0023] In this embodiment, the system storage unit includes a ROOT system root partition and a DATA data partition. Exemplarily, as Figure 4 shown, in one system storage unit, there is one ROOT system root partition and several DATA data partitions, and the ROOT system root partition and the DATA data partitions use the same key.
[0024] The ROOT system root partitions of several system storage units all store a complete set of operating system data. The operating system data of each ROOT system root partition can be exactly the same, or there can be differences according to usage scenarios and different user requirements. The DATA data partition of the system storage unit stores system user data.
[0025] The configuration file storage unit is stored in the temporary root file system initramfs.
[0026] In this embodiment, the keys of different system storage units are different. Each system storage unit is independent and encrypted, so that even if one system storage unit has a problem, it will not affect other system storage units.
[0027] In this embodiment, if the system storage units need to be shared, only the keys need to be stored in different key slots of the shared system storage unit.
[0028] Step S202: Encrypt the system storage units respectively using the first encryption method, and store the key in the corresponding configuration file storage unit or in a key storage device. In this embodiment, exemplarily, the key storage device is any one of a Ukey, a trusted module platform device, and a password server.
[0029] In another embodiment, the configuration file storage unit stores a decryption configuration file, which records the type of the key storage device where the key is located and the specific storage address. Further, the key is obtained through the record in the decryption configuration file, where the type of the key storage device can be any one of a Ukey, a trusted module platform device, and a password server.
[0030] Step S203: Encrypt the configuration file storage unit using the second encryption method, and store the key at a preset key acquisition address. In this embodiment, the first encryption method is the LUKS encryption method, and the second encryption method is the file system-level encryption method. Exemplarily, the file system-level encryption method can be any one of ecryptfs, EncFS, gocryptfs, and CryFs.
[0031] In this embodiment, if the ROOT system root partition and the DATA data partition of the system storage unit are built on the same physical partition, a single LUKS encryption key, a single encryption algorithm, and a key storage acquisition method are directly used to directly build a LUKS encrypted format partition on this physical partition, and the ROOT system root partition and the DATA data partition are built on the decryption mapping device of the LUKS device. If the ROOT system root partition and the DATA data partition of the system storage unit exist in the form of physical partitions respectively, a unified LUKS encryption key, a single encryption algorithm, and a key storage acquisition method are used to respectively build LUKS format partitions on each physical partition within the same system storage unit, and the ROOT system root partition and the DATA data partition are respectively built on the decryption mapping devices of each LUKS device.
[0032] In this embodiment, the data of each system storage unit is effectively isolated. Each user or team can have its own independent root partition and data partition, effectively protecting the data privacy between users or teams. For different application scenarios, the system performance can be optimized by selecting different system storage units. For example, for tasks that require high-performance computing, a system storage unit with a higher configuration can be selected; while for tasks that store a large amount of data, a system storage unit with a larger storage space can be selected.
[0033] In this embodiment, exemplarily, the preset key acquisition address can correspond to any one of a Ukey, a trusted module platform device, and a password server.
[0034] Step S204, when any grub startup item is selected to start, obtain the key to decrypt the corresponding configuration file storage unit according to the preset key acquisition address corresponding to the grub startup item, and obtain the partition mounting configuration file; In another embodiment, a decryption configuration file can also be obtained from the configuration file storage unit. The decryption configuration file records the type of key storage device where the system storage unit key is located and the specific storage address.
[0035] Step S205, use the key obtained from the key storage device or the decrypted configuration file storage unit to decrypt the system storage unit, and mount the decrypted system storage unit according to the corresponding partition mounting configuration file.
[0036] In this embodiment, the key can be obtained through a pre-acquired key storage device, or the stored key can be obtained from the configuration file storage unit; In another embodiment, a decryption configuration file is stored in the configuration file storage unit. The decryption configuration file records the type of key storage device where the key is located and the specific storage address. Further, the key is obtained through the records in the decryption configuration file. Among them, the type of key storage device can be any one of Ukey, trusted module platform device, and password server.
[0037] This embodiment can perform the first encryption on multiple system storage units, and can perform the second encryption on the configuration file storage unit storing the key. The setting of multiple system storage units can realize the selection of different systems to be mounted according to the requirements of the application scenario, and has the characteristics of good confidentiality, wide application range, and high reliability.
[0038] For the technical solution disclosed in this embodiment, the attacker cannot obtain the decryption key of the system storage unit, which increases the difficulty of the attack. At the same time, the mounted configuration file cannot be obtained either. For the storage units with high confidentiality in multiple system storage units, the storage unit with high confidentiality can be better hidden among the storage units, further enhancing the protection of key data.
[0039] On the basis of the previous embodiment, in another embodiment of the present invention, as Figure 2 and Figure 3 , step S204, when any grub boot item is selected to start, obtaining the key to decrypt the corresponding configuration file storage unit according to the preset key acquisition address corresponding to the grub boot item includes: establishing an associated configuration file, where the associated configuration file is used to record the correspondence among the grub boot item, the preset key acquisition address, and the configuration file storage unit. When any grub boot item is selected to start, query the associated configuration file, and obtain the key to decrypt the corresponding configuration file storage unit according to the corresponding preset key acquisition address.
[0040] In this embodiment, an associated configuration file is established in the temporary root file system initramfs.
[0041] In this embodiment, when the grub boot item starts, the partition mounting configuration file and the key are transplanted to the normal path, including: transplanting the crypttab file to the / cryptroot directory of initramfs, transplanting the fstab file to the / etc directory of initramfs, and transplanting the key to the / scripts directory of initramfs. After decrypting the system storage unit, mount operations are performed on each partition in the system storage unit, so as to successfully start the system of the selected grub boot item.
[0042] In this embodiment, by establishing an associated configuration file, unified mounting management of all GRUB boot items can be achieved, with internal data isolated from each other, and it features fast startup speed, good security, and reliable performance.
[0043] In one embodiment of the present invention, as Figure 1 shown: During the system installation phase, the administrator selects to create three system storage units, and sets the number and capacity of the specific ROOT system root partition and DATA data partition for each system storage unit. For example, the system storage unit 1 is created, and its ROOT system root partition and DATA data partition are set, and the configuration file storage unit 1 is set. Further, for example, in the system storage unit 1, all partitions (one ROOT system root partition and one DATA data partition) in the system storage unit 1 are encrypted one by one with the same key using LUKS encryption, and the key is saved in a preset manner; in the system storage unit 2, all partitions in the system storage unit 2 are encrypted one by one with another key different from that in the system storage unit 1 using LUKS encryption, and the key is stored in a preset manner.
[0044] Configuration file storage units of each system storage unit are generated in the temporary file system initramfs, and are encrypted respectively using the file system-level encryption method, and the key is stored at the preset key acquisition address.
[0045] An associated configuration file is generated in the temporary file system initramfs, which exists in the form of a list. For example, the first line records: "GRUB boot item 1; configuration file storage unit 1; preset key acquisition address.
[0046] After the system installation is completed, for example, when the user selects the GRUB boot item 1, the init program in the temporary file system initramfs finds the entry of the GRUB boot item 1 in the associated configuration file, obtains the configuration file storage unit 1 and the preset key acquisition address, obtains the key according to the preset key acquisition address, decrypts the configuration file storage unit 1, obtains the partition mounting configuration file, and cooperates with the key obtained in the configuration file storage unit or the key storage device to decrypt the system storage unit 1, and mounts the ROOT system root partition and DATA data partition in the system storage unit 1 to realize the operation of the selected system and complete the startup of the GRUB boot item 1.
[0047] As Figure 5 shown, the present invention also discloses a system partition startup device capable of dual encryption, including: A building module 501 is used to build a number of system storage units including partitions. A corresponding configuration file storage unit is built for each system storage unit. The partition mounting configuration file of the system storage unit is stored in the corresponding configuration file storage unit. A first encryption module 502 is used to encrypt the system storage units respectively by using a first encryption method, and the encryption key is stored in the corresponding configuration file storage unit or in a key storage device. A second encryption module 503 is used to encrypt the configuration file storage unit by using a second encryption method, and the encryption key is stored at a preset key acquisition address. A startup module 504 is used to, when any grub startup item is selected for startup, obtain the key according to the preset key acquisition address corresponding to the grub startup item to decrypt the corresponding configuration file storage unit and obtain the partition mounting configuration file. A mounting module 505 is used to decrypt the system storage unit by using the key obtained from the key storage device or the decrypted configuration file storage unit, and mount the decrypted system storage unit according to the corresponding partition mounting configuration file.
[0048] The present invention also discloses an electronic device, as Figure 6 shown, which discloses an embodiment, a block diagram of an electronic device applicable to the system partition startup capable of dual encryption as described above.
[0049] The electronic device 60 in this embodiment includes a processor 601, which can perform various appropriate actions and processes according to the program stored in the ROM 602 or the program loaded from the storage section 608 into the RAM 603. The processor 601 can include, for example, a general microprocessor, an instruction set processor, and / or a related chipset, and / or a dedicated microprocessor, etc. The processor 601 can also include on-board memory for caching purposes. The processor 601 can include a single processing unit or multiple processing units for performing different actions of the method flow according to the embodiments of the present invention.
[0050] In the RAM 603, various programs and data required for the operation of the electronic device 60 are stored. The processor 601, the ROM 602, and the RAM 603 are connected to each other through a bus 604. The processor 601 performs various operations of the method flow according to the embodiments of the present invention by executing the programs in the ROM 602 and / or the RAM 603. It should be noted that the program can also be stored in one or more memories other than the ROM 602 and the RAM 603, and the processor 601 can also perform various operations of the method flow according to the embodiments of the present invention by executing the programs stored in one or more memories.
[0051] According to an embodiment of the present invention, the electronic device 60 may further include an I / O interface 605, and the I / O interface 605 is also connected to the bus 604. The electronic device 60 may further include one or more of the following components connected to the I / O interface 605: an input portion 606 including a keyboard, a mouse, etc.; an output portion 607 including a cathode ray tube, a liquid crystal display, a speaker, etc.; a storage portion 608 including a hard disk, etc.; and a communication portion 609 including a network interface card such as a LAN card, a modem, etc. The communication portion 609 performs communication processing via a network such as the Internet. The drive 6010 is also connected to the I / O interface 605 as needed. A removable medium 6011, such as a magnetic disk, an optical disk, a magneto-optical disk, a semiconductor memory, etc., is installed on the drive 6010 as needed so that a computer program read from it is installed into the storage portion 608 as needed.
[0052] The present invention also provides a computer-readable storage medium.
[0053] The computer-readable storage medium may be included in the electronic device / device system described in the above embodiment; or it may exist separately without being assembled into the electronic device / device. The above computer-readable storage medium carries one or more programs, and when the one or more programs are executed, the method according to the embodiment of the present invention is implemented.
[0054] According to an embodiment of the present invention, the computer-readable storage medium may be a non-volatile computer-readable storage medium. For example, it may include but is not limited to: a portable computer disk, a hard disk, a random access memory RAM, a read-only memory ROM, an erasable programmable read-only memory EPROM or a flash memory, a portable compact disk read-only memory CDROM, an optical storage device, a magnetic storage device, or any suitable combination of the above. In the present invention, the computer-readable storage medium may be any tangible medium that contains or stores a program, and the program may be used by or in combination with an instruction execution system, apparatus, or device.
[0055] An embodiment of the present invention further includes a computer program product.
[0056] The computer program product includes a computer program, and the computer program contains program code for executing the method provided by the embodiment of the present invention. When the computer program product runs on an electronic device, the program code is used to cause the electronic device to implement the method provided by the embodiment of the present invention.
[0057] In one embodiment, the computer program may rely on tangible storage media such as optical storage devices and magnetic storage devices. In another embodiment, the computer program may also be transmitted and distributed in the form of signals on a network medium. The program code included in the computer program may be transmitted using any suitable network medium, including but not limited to: wireless, wired, etc., or any suitable combination of the above.
[0058] According to embodiments of the present invention, the program code for executing the computer program provided by the embodiments of the present invention may be written in any combination of one or more programming languages. Specifically, these computing programs may be implemented using high-level procedures and / or object-oriented programming languages. Programming languages include but are not limited to, such as Java, C++, Python, C language, or similar programming languages. The program code may be executed entirely on the user's computing device, partially on the user's device, partially on a remote computing device, or entirely on a remote computing device or server. In the case of a remote computing device, the remote computing device may be connected to the user's computing device through any type of network, including a local area network or a wide area network, or may be connected to an external computing device.
[0059] The flowcharts and block diagrams in the accompanying drawings illustrate the possible architectures, functions, and operations of systems, methods, and computer program products according to various embodiments of the present invention. In this regard, each block in the flowchart or block diagram may represent a module, a program segment, or a part of code that contains one or more executable instructions for implementing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks may occur in a different order than marked in the accompanying drawings. For example, two consecutive blocks shown may actually be executed substantially in parallel, and they may sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in the block diagram or flowchart, and the combination of blocks in the block diagram or flowchart, may be implemented by a dedicated hardware-based system for performing the specified functions or operations, or may be implemented by a combination of dedicated hardware and computer instructions. Those skilled in the art can understand that the features described in the various embodiments and / or claims of the present invention can be combined and / or combined in various ways, even if such combinations or combinations are not explicitly described in the present invention. In particular, without departing from the spirit and teachings of the present invention, the features described in the various embodiments and / or claims of the present invention can be combined and / or combined in various ways. All such combinations and / or combinations fall within the scope of the present invention.
[0060] The embodiments of the present invention have been described above. However, these embodiments are merely for illustrative purposes and not for limiting the scope of the present invention. Although the embodiments have been described separately above, this does not mean that the measures in each embodiment cannot be used advantageously in combination. The scope of the present invention is defined by the appended claims and their equivalents, and without departing from the scope of the present invention, those skilled in the art can make various substitutions and modifications, and all such substitutions and modifications should fall within the scope of the present invention.
Claims
1. A system partition startup method capable of dual encryption, characterized in that, Including: Establish a number of system storage units including partitions, and establish a corresponding configuration file storage unit for each of the system storage units. The partition mounting configuration file of the system storage unit is stored in the corresponding configuration file storage unit. Use the first encryption method to encrypt the system storage units respectively, and the key is stored in the corresponding configuration file storage unit or the key storage device. Use the second encryption method to encrypt the configuration file storage unit, and the key is stored at the preset key acquisition address. When selecting any grub boot item to start, obtain the key according to the preset key acquisition address corresponding to the grub boot item to decrypt the corresponding configuration file storage unit to obtain the partition mounting configuration file. Use the key obtained from the key storage device or the decrypted configuration file storage unit to decrypt the system storage unit, and mount the decrypted system storage unit according to the corresponding partition mounting configuration file.
2. The method for booting a system partition capable of dual encryption according to claim 1, wherein The step of, when selecting any grub boot item to start, obtaining the key according to the preset key acquisition address corresponding to the grub boot item to decrypt the corresponding configuration file storage unit includes: establishing an association configuration file for recording the correspondence among the grub boot item, the preset key acquisition address, and the configuration file storage unit. When selecting any of the grub boot items to start, query the association configuration file and obtain the key according to the corresponding preset key acquisition address to decrypt the corresponding configuration file storage unit.
3. A system partition startup method capable of dual encryption according to claim 1, characterized in that, The first encryption method is the LUKS encryption method, and the second encryption method is the file system-level encryption method.
4. A method for booting a system partition capable of dual encryption according to claim 1, characterized in that, The system storage unit includes a ROOT system root partition and a DATA data partition.
5. A method for starting a system partition capable of dual encryption according to claim 1, characterized in that, The configuration file storage unit is stored in the temporary root file system.
6. A method for booting a system partition capable of dual encryption according to claim 1, characterized in that, The step of establishing a number of system storage units and using the first encryption method to encrypt the system storage units respectively includes: different system storage units have different keys.
7. A method for booting a system partition capable of dual encryption according to claim 1, characterized in that, The key storage device includes any one of a Ukey, a trusted module platform device, and a password server.
8. A system partition startup device capable of dual encryption, characterized in that: The device includes: A establishing module for establishing a number of system storage units including partitions, and establishing a corresponding configuration file storage unit for each of the system storage units. The partition mounting configuration file of the system storage unit is stored in the corresponding configuration file storage unit. A first encryption module for using the first encryption method to encrypt the system storage units respectively, and the key is stored in the corresponding configuration file storage unit or the key storage device. A second encryption module for using the second encryption method to encrypt the configuration file storage unit, and the key is stored at the preset key acquisition address. A starting module for, when selecting any grub boot item to start, obtaining the key according to the preset key acquisition address corresponding to the grub boot item to decrypt the corresponding configuration file storage unit to obtain the partition mounting configuration file. A mounting module, which is used to decrypt the system storage unit by using the key obtained from the key storage device or the decrypted configuration file storage unit, and mount the decrypted system storage unit according to the corresponding partition mounting configuration file.
9. An electronic device, characterized in that, Comprising: One or more processors; A storage device for storing one or more programs, wherein when the one or more programs are executed by the one or more processors, the one or more processors are caused to execute the method according to any one of claims 1 to 7.
10. A computer program product comprising a computer program, characterized in that, When the computer program is executed by a processor, the method according to any one of claims 1 to 7 is implemented.
Citation Information
Patent Citations
hard disk partition encryption method and system under a K-UX system
CN109583242A
Linux system safe starting method and system based on encryption and decryption
CN111209572A
Method and device for protecting configuration file
CN111831978A
Encrypted partition access control method and system based on domain management platform, and computing device
CN114329574A
Workflow-based application configuration file analysis method and device, equipment and medium
CN117193837A