Secure mobile storage device and method integrating multiple self-destruction and protection mechanisms

Through the five-layer composite protection architecture and multi-stage self-destruction mechanism, the data security problem of mobile storage devices in the face of physical attacks and complex threats is solved, and a comprehensive and multi-level security protection is achieved to ensure the security and reliability of data in complex environments.

CN120429902APending Publication Date: 2025-08-05GUANGXI POWER GRID CORP
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510501602.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-21
Publication Date
2025-08-05

AI Technical Summary

Technical Problem

Existing mobile storage device security protection technology is difficult to effectively ensure data security when facing physical attacks and complex threats. Logical protection solutions are powerless at the physical level. A single self-destruct mechanism is easily bypassed and cannot meet the growing data security needs.

Method used

The five-layer composite protection architecture is adopted, including a micron-level pressure and temperature sensor in the shell layer, a polymorphic thyristor array in the protective circuit layer, a dynamic encryption module based on FPGA chaotic mapping algorithm, a 3D XPoint medium in the core storage layer and a nano-level corrosive gas microcapsule of the self-destruction execution unit. Combining the threat scoring model and a multi-stage self-destruction mechanism, it achieves all-round and multi-level security protection.

Benefits of technology

Effectively resist all kinds of attacks, ensure data security and integrity, and reduce the risk of data leakage through real-time perception of physical tampering, millisecond-level circuit breaking protection, rapid overwriting and physical destruction, and improve the reliability and security of equipment in complex environments.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120429902A_ABST
    Figure CN120429902A_ABST
Patent Text Reader

Abstract

The invention discloses a secure mobile storage device and method integrating multiple self-destruction and protection mechanisms, and belongs to the field of mobile storage security. Aiming at the problem of insufficient safety protection of the existing mobile storage equipment, a five-layer composite protection framework is adopted. A shell layer is integrated with micron-sized pressure and temperature sensors to monitor physical tampering; the protection circuit layer realizes millisecond-level circuit break protection by using a multi-state silicon controlled rectifier array; the dynamic encryption module is used for dynamically refreshing a secret key based on an FPGA and a chaotic mapping algorithm; the core storage layer adopts a 3D XPoint medium to support rapid overwriting; and the self-destruction execution unit is used for physically destroying the data by utilizing the nanoscale corrosive gas micro-capsule. And defining a threat scoring model, dynamically adjusting a threshold value, and implementing a multi-stage self-destruction mechanism. An improved Logistic-Tent double-chaos system is combined with real-time entropy source modulation of an acceleration sensor to generate a secret key, so that the safety and the randomness are enhanced. The security and reliability of the mobile storage device are improved, and the data security is effectively guaranteed.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of mobile storage device security protection, and in particular to a device and method for ensuring data security of mobile storage devices by integrating multiple self-destruction and protection mechanisms. Background Art

[0002] With the rapid development of information technology, mobile storage devices (such as USB flash drives and external hard drives) are increasingly used in many sensitive fields, including military, finance, healthcare, and power grids. However, their physical portability also poses a serious risk of data leakage. Currently, existing security protection technologies mainly rely on the following two types of solutions:

[0003] Logical protection: Common solutions include AES-256 encryption and digital certificate authentication. These solutions provide some protection for data at the logical level, but are powerless against physical attacks (such as brute force disassembly and side-channel analysis) and cannot effectively guarantee data security.

[0004] Single self-destruct mechanism: Some mobile storage devices use electrical fuses or data overwrite mechanisms to mitigate security threats. However, these mechanisms are triggered by relatively simple conditions, typically only in specific circumstances, such as exceeding a certain number of incorrect password attempts. These mechanisms can be easily bypassed by specialized tools, making them ineffective in preventing complex attacks.

[0005] In summary, existing mobile storage device security technologies have significant flaws and shortcomings, making them unable to meet the growing demand for data security. In real-world applications, if a device is subjected to a physical attack or faces complex security threats, the risk of data leakage is extremely high, potentially causing serious losses to related sectors.

[0006] Full terms and abbreviations

[0007] ●FPGA: Field-Programmable Gate Array, an integrated circuit with high flexibility and parallel processing capabilities that can be programmed to implement various digital logic functions.

[0008] NIST SP 800-88: Special Publication 800-88, published by the National Institute of Standards and Technology (NIST), specifies standard methods for data erasure and destruction.

[0009] SHA-3: Secure Hash Algorithm 3, used to extract a fixed-length hash value from data to ensure data integrity and security.

[0010] ●ADC: Analog-to-Digital Converter, which converts analog signals into digital signals for easy processing and analysis by digital systems.

[0011] ●Hamming distance: In information theory, the Hamming distance between two strings of equal length is the number of different characters in corresponding positions of the two strings. It is often used to measure the degree of difference between two data. Summary of the Invention

[0012] The purpose of the present invention is to provide a secure mobile storage device and method that integrates multiple self-destruction and protection mechanisms, aiming to address the shortcomings of existing mobile storage device security protection technology. Through innovative device structure, self-destruction trigger logic and encryption algorithm, a comprehensive, multi-level security protection system is constructed to effectively ensure the security and integrity of data in mobile storage devices.

[0013] Technical Solution

[0014] The secure mobile storage device and method proposed in this invention integrates multiple self-destruction and protection mechanisms. They mainly cover three core parts: device structure design, self-destruction trigger logic, and dynamic encryption algorithm. Through the coordinated operation of these parts, high-security protection for mobile storage devices is achieved:

[0015] 1 Equipment structure design

[0016] This device adopts an innovative five-layer composite protection architecture (see Figure 1 ), each layer works closely together to build a comprehensive, multi-level security protection system for storage devices.

[0017] 1.1 Outer shell

[0018] As the outermost layer of protection for the device, the outer shell plays a key role in detecting physical tampering. By integrating micron-level pressure and temperature sensors, it enables real-time perception of the physical state of the device's environment.

[0019] Among them, the micron-level pressure sensor has extremely high sensitivity and an accuracy of up to ±0.1N. This feature enables it to accurately capture extremely subtle pressure changes, whether it is the large pressure applied instantly during external violent disassembly, or the tiny pressure fluctuations caused by collision and extrusion during daily use. For example, in actual application scenarios, when using tools such as hydraulic pliers to disassemble the device casing, the pressure sensor can respond in a very short time (such as detecting >50N pressure within 0.3ms in the case), providing key signals for subsequent protective actions.

[0020] The temperature sensor operates within a range of -40°C to 120°C and can effectively monitor changes in the ambient temperature around the device. Extremely low or high temperatures can threaten the stability of the device's internal electronic components and stored data. Abnormal temperature fluctuations can also indicate a specific attack vector (such as an attempt to damage the device or obtain data through a thermal attack). This temperature sensor can promptly detect temperature anomalies and, together with data from the pressure sensor, serve as an important basis for determining whether the device has been physically tampered with.

[0021] 1.2 Protection circuit layer

[0022] The protective circuit layer, located within the outer shell, houses a polymorphic thyristor array, a core component that provides rapid circuit-breaking protection for the device. The polymorphic thyristor array possesses unique electrical characteristics, enabling it to trip within milliseconds upon receiving a specific trigger signal.

[0023] When the device detects a potential data security threat (for example, if the threat score model S(t) exceeds a threshold, indicating a high risk of attack), the protective circuit layer responds quickly. Upon receiving the control signal, the polymorphic thyristor array instantly disconnects critical circuits, preventing further current flow. This prevents data within the storage device from being illegally read or corrupted by external attacks (such as short circuits, overvoltage, and other malicious operations). This millisecond-level disconnection response significantly improves the device's self-protection capabilities in the face of sudden dangers, effectively reducing the risk of data leakage.

[0024] 1.3 Dynamic Encryption Module

[0025] The dynamic encryption module is based on an FPGA (Field Programmable Gate Array) and uses advanced chaotic mapping algorithms to provide high-strength encryption protection for data stored on storage devices. The FPGA's high flexibility and parallel processing capabilities enable rapid execution of complex encryption algorithms, meeting the device's requirements for encryption speed and real-time performance.

[0026] The keys generated using the chaotic mapping algorithm are highly random and complex. The dynamic key refresh cycle can be flexibly adjusted within a range of 1ms to 1s. This dynamic refresh mechanism allows encryption keys to continuously change over time. Even if an attacker attempts to crack the key by analyzing encrypted data over a period of time, the frequent key updates make cracking exponentially more difficult. For example, in military or financial scenarios where data security is paramount, frequent key updates can effectively defend against various time-based attacks, ensuring data security during transmission and storage.

[0027] 1.4 Core Storage Layer

[0028] The core storage layer uses 3D XPoint non-volatile storage media, which has excellent performance advantages. It supports block-level fast overwrite with an overwrite speed of ≥10GB / s and is based on Intel Optane TM The measured overwrite speed of 3D XPoint media is 12.4GB / s, meeting the ≥10GB / s requirement. This feature is crucial when a device performs a self-destruct operation or updates data.

[0029] When the device triggers the self-destruct mechanism, the core storage layer can quickly overwrite the stored data. According to the NIST SP 800-88 standard, overwriting the storage area multiple times (such as 3 times) can effectively ensure that the original data cannot be recovered. Taking a defense-level test as an example, after the self-destruct mechanism is triggered, the core storage layer can quickly complete the data overwrite, and cooperate with other self-destruct measures to ensure that the probability of data recovery is less than the theoretical value of 10 -9 At the same time, during normal use, the fast block-level overwrite capability also helps improve the efficiency of data updates and ensure the overall performance of the device.

[0030] 1.5 Self-destruction execution unit

[0031] The self-destruct actuator is the last line of defense for device safety. It contains nano-scale corrosive gas microcapsules, each with a capacity of 0.5ml. The microcapsules use double-layer nano-polymer encapsulation technology. The inner layer encapsulates 0.5ml of iron oxide powder (Fe2O3) and acidic electrolyte (HCl solution, concentration 5%), and the outer layer is a pressure-resistant ceramic shell (compressive strength ≥ 200MPa). When triggered, a high-voltage electric pulse breaks through the inner polymer layer, triggering a chemical reaction:

[0032] Fe2O3+6HCl→2FeCl3+3H2O

[0033] The generated FeCl3 solution reacts with the storage medium (GaAs) to completely oxidize the data storage layer. The reaction equation is:

[0034] 2GaAs+6FeCl3→2GaCl3+2As↓+6FeCl2

[0035] At the same time, the microcapsule has a built-in neutralization device (alkaline filter element). When the released gas passes through the filter element, it reacts with NaOH to generate harmless salts:

[0036] HCl + NaOH → NaCl + H2O

[0037] When the device is determined to be under serious threat and the threat score model S(t) exceeds the threshold, the self-destruct execution unit is triggered. Once triggered, the nano-scale corrosive gas microcapsules will rapidly release corrosive gases. Within 30 seconds, these gases can chemically react with the storage medium, completely oxidizing the storage medium, destroying its physical structure, and the data stored in it will be irrecoverable. For example, when a brute force cracking attempt is attempted in a low-temperature environment (-30°C), the temperature sensor and error count jointly trigger the self-destruct mechanism, and the nano-scale corrosive gas microcapsules are released within 2 seconds to ensure the security and irrecoverability of the data. This irreversible physical destruction method, combined with the self-destruction operation of the logic layer (such as overwriting the storage area), provides the device with extremely reliable self-destruction protection, effectively preventing data leakage.

[0038] The reaction system complies with Category 8 (corrosive substances) of the Regulations on the Management of Hazardous Chemicals, and the products FeCl3 and NaCl are both environmentally friendly substances.

[0039] 2 Self-destruction trigger logic

[0040] In order to accurately determine whether the device is facing risks that threaten data security and initiate the self-destruction program in a timely manner, this device innovatively defines a threat scoring model as the basis for triggering multi-stage self-destruction.

[0041] 2.1 Threat Score Model

[0042] Comprehensive assessment principle: The threat score model expression is:

[0043]

[0044] The model achieves a dynamic assessment of the threat level faced by the device by comprehensively considering the current real-time monitoring data of sensors and historical attack situations.

[0045] Parameter meaning:

[0046] w i Represents the weight of the i-th threat category, and its value is set based on the severity of the threat to data security. For example, disassembly and temperature anomalies pose a significant threat to data security, so w1 = 0.4. While temperature anomalies pose a less significant threat, they can also pose data risks, so w2 = 0.3. These weights were determined through extensive experimentation and theoretical analysis to ensure they accurately reflect the importance of each threat.

[0047] f i(t) is the real-time sensor signal. The original signal from the pressure sensor, temperature sensor, etc. is normalized to the range [0,1]. The purpose of this is to make the sensor signals of different types and different magnitudes have a unified quantitative standard, which is convenient for comprehensive calculation in the model. For example, the pressure value detected by the pressure sensor will be converted to a value within [0,1] according to its range and sensitivity. If the current pressure value approaches or reaches a level that may damage the equipment, f i The value of (t) will approach 1.

[0048] g(τ) is a historical attack strength memory function that records the strength of attacks experienced by a device at the past τ time intervals. This function allows the device to "remember" past attacks and avoid underreacting to repeated or persistent attacks. For example, if a device has experienced multiple brute force cracking attempts, g(τ) will reflect the strength and frequency of these attacks, increasing vigilance against similar attacks in subsequent assessments.

[0049] α = 0.2 and β = 0.5 are decay coefficients. α adjusts the influence of the historical attack intensity memory function on the current threat score, while β determines the rate at which historical attack intensity decays over time. These two coefficients have been carefully tuned to ensure that historical attack information has a certain reference value for the current score while ensuring that recent attacks have a more significant impact on the score, allowing the model to better adapt to the ever-changing threat environment.

[0050] The Bayesian network is used to fuse multi-sensor data. When the pressure and temperature signals conflict, the sensor with the higher probability weight prevails (e.g., pressure signal weight w1 = 0.4 > temperature signal w2 = 0.3).

[0051] 2.2 Threshold Setting and Dynamic Adjustment

[0052] When S(t) > θ, the device triggers a multi-stage self-destruct sequence. The threshold θ is not fixed but dynamically adjusted, with an initial value of 1.2. This dynamic adjustment mechanism is based on the device's historical attack patterns (reflected by the integral term g(τ)) and adaptively changes the threshold based on the actual threat situation the device faces. Compared to traditional static threshold schemes, dynamic threshold adjustment reduces false alarm rates by 42%. For example, in environments where devices are frequently attacked, the threshold is appropriately lowered to enable a more rapid response to threats. In relatively safe environments, the threshold is moderately increased to reduce unnecessary self-destruct triggers and improve device availability.

[0053] When S(t) exceeds the threshold for the first time, the device enters a warning state (LED flashes red), and the user is required to enter an authorization code (such as biometrics or physical button) within 30 seconds to confirm self-destruction; if there is no confirmation, only the logic layer self-destruction is triggered.

[0054] 2.3 Multi-stage self-destruction mechanism

[0055] Logical layer self-destruction: Once the threat score exceeds the threshold, the logical layer self-destruction is initiated first. According to the NIST SP 800-88 standard, the storage area is overwritten three times. This operation completely overwrites the original data by writing specific data to the storage area, making it impossible to recover. It takes time Where V is the capacity of the storage device, and R = 10GB / s is the block-level overwrite speed of the core storage layer. For example, if the device capacity is 100GB, then the time it takes for the logical layer to self-destruct is This fast logical overwrite operation can effectively clear data in the storage area in a short period of time, providing the first layer of protection for data security.

[0056] Physical layer self-destruction: Simultaneously with the logical layer self-destruction, the physical layer self-destructs simultaneously. Upon receiving the self-destruct signal, the thyristors in the protective circuit layer rapidly fuse critical circuits, cutting off power to the device and preventing any further data readout or transmission. Simultaneously, the self-destruct execution unit releases corrosive gas from its nano-sized microcapsules. Within 30 seconds, the released corrosive gas chemically reacts with the storage media, completely oxidizing it and physically destroying the storage device's structure, rendering data irrecoverable.

[0057] Hierarchical self-destruction strategy:

[0058] Low-risk scenario (S(t)∈[1.2,1.5]): Only logic layer self-destruction (3 overwrites) is performed;

[0059] High-risk scenario (S(t)>1.5): Synchronous triggering of logical and physical layer self-destruction.

[0060] 3 Dynamic Encryption Algorithm

[0061] To ensure the security of data in storage devices, this device uses an improved Logistic-Tent dual chaotic system to generate keys. This algorithm combines the real-time entropy source modulation of the device's acceleration sensor, greatly enhancing the security and randomness of the key.

[0062] 3.1 Principle of the Improved Logistic-Tent Dual Chaotic System

[0063] (1) Iterative formula: The improved Logistic-Tent dual chaotic system generates the key sequence through two interrelated iterative formulas, namely

[0064]

[0065] (2) Chaotic characteristics: Logistic mapping and Tent mapping have chaotic characteristics, that is, they are extremely sensitive to initial conditions. Small differences in initial values will produce completely different results after multiple iterations. In the improved Logistic-Tent dual chaotic system, x n+1 The calculation of not only depends on its own value x at the previous moment n , and y n Related; similarly, y n+1 The calculation of y n and x n This mutual coupling further enhances the chaotic nature of the system. By continuously iterating these two formulas, sequences with high randomness and complexity can be generated. These sequences can be used as encryption keys after specific processing.

[0066] (3) Encryption Advantages: Compared with traditional single chaotic systems, the improved Logistic-Tent dual chaotic system generates a larger key space and more complex and diverse key changes. This makes it difficult for attackers to crack the encryption algorithm by analyzing the patterns of key sequences, greatly improving the security of data encryption. For example, when facing brute force cracking, due to the complexity of the key, the attacker needs to try more key combinations, and the time and computing resources required for cracking increase exponentially.

[0067] 3.2 Parameter Modulation Mechanism

[0068] The parameter modulation mechanism process is as follows Figure 2 shown.

[0069] After the accelerometer signal is sampled by the ADC (sampling rate 1kHz), the entropy value is extracted using the SHA-3 algorithm to generate a 128-bit random number, which is mapped to the parameter range:

[0070] r=3.7+0.3×(entropy value 0-63 mod 1000) / 1000

[0071] μ=0.3×(entropy value 64-127 mod 1000) / 1000

[0072] The parameters are updated every 10ms to ensure that the key changes dynamically.

[0073] (1) Real-time entropy source modulation: Parameters r∈(3.7,4) and μ∈(0,0.3) are modulated by the real-time entropy source of the device's accelerometer. The accelerometer can sense the device's motion state in real time, and the signal it generates contains rich random information, which is used as the entropy source. Since the device's motion state during actual use is unpredictable, such as shaking and collisions during transportation, the entropy source output by the accelerometer has a strong randomness.

[0074] (2) Dynamic parameter changes: By utilizing the real-time entropy source of the accelerometer to modulate the parameters r and μ, these two parameters can change in real time with the motion state of the device during the encryption process. Each time the encryption operation is performed, the random information generated by the entropy source is different due to the different motion state of the device, and the modulated r and μ are also different, which leads to different generated key sequences. Even if the same data is encrypted multiple times in a short period of time, the keys used each time will be different, further increasing the security and unpredictability of the encryption. For example, in different usage scenarios, the motion state of the device is different. It may be used on a stable desk once and on a bumpy vehicle another time. The entropy source collected by the accelerometer is different, the modulated parameters r and μ are different, and the generated keys are also completely different, effectively resisting the attacker's attack methods against fixed parameter encryption algorithms. The details are as follows:

[0075] (3) Anti-side-channel attack capability: This method of binding chaotic encryption parameters with sensor noise (the real-time entropy source of the acceleration sensor can be regarded as a noise signal) has been verified by the Hamming distance test, making the sample size required for cracking reach O(2 128 This means that if an attacker wants to collect enough sample data to analyze key patterns, they need to obtain an extremely large amount of data, which is almost impossible to achieve in practice. This effectively improves the device's ability to resist side-channel attacks.

[0076] 4. Innovation

[0077] The present invention demonstrates innovation in many aspects, with significant breakthroughs in device structure, self-destruction logic, and encryption algorithm, effectively improving the security and reliability of mobile storage devices.

[0078] (1) Innovative five-layer composite protection architecture: The device adopts a unique five-layer composite protection architecture with each layer working in collaboration. The outer shell integrates micron-level pressure and temperature sensors to accurately sense physical tampering; the polymorphic thyristor array in the protection circuit layer can disconnect in milliseconds; the dynamic encryption module is based on FPGA and chaotic mapping algorithm, and the key is dynamically refreshed; the 3DXPoint media in the core storage layer supports fast overwrite; the nano-level corrosive gas microcapsules in the self-destruct execution unit can physically destroy data, forming a comprehensive, multi-layered security protection system.

[0079] (2) Advanced self-destruct triggering logic: A threat scoring model is defined to comprehensively assess threats and dynamically adjust thresholds, reducing false alarm rates by 42% compared to traditional static threshold solutions. A multi-stage self-destruct mechanism is implemented based on the severity of the threat, with coordinated self-destruction at the logical and physical layers. Compared to a single fuse mechanism, this reduces the false trigger rate by 42%.

[0080] (3) Improved dynamic encryption algorithm: An improved Logistic-Tent dual chaotic system is used to generate keys, combined with the acceleration sensor's real-time entropy source modulation parameters to make the keys more secure and random. The key space is large and complex, and the key is highly resistant to side-channel attacks. The sample size required for cracking is O(2^128).

[0081] (4) New security mechanisms: Introducing multi-sensor arbitration logic and using Bayesian network data fusion to resolve sensor signal conflicts. Setting up a soft self-destruct mode to meet special audit requirements.

[0082] Beneficial effects

[0083] The present invention has the following beneficial effects:

[0084] (1) Comprehensive security protection: A unique five-layer composite protection architecture with clear division of labor and coordinated work at each layer. The outer shell layer senses physical tampering in real time, the protection circuit layer provides millisecond-level circuit breaker protection, the dynamic encryption module provides high-strength encryption, the core storage layer enables rapid data overwrite, and the self-destruct execution unit physically destroys data, building a comprehensive, multi-layered security protection system that effectively resists all types of attacks. In the military field, even if the equipment falls into the hands of the enemy, it can ensure that the data cannot be stolen and the data is completely destroyed through the self-destruct mechanism.

[0085] (2) Precise self-destruct control: Advanced self-destruct trigger logic uses a threat scoring model to comprehensively assess threats, dynamically adjust thresholds, and reduce false alarm rates. A multi-stage self-destruct mechanism is implemented based on the severity of the threat, with coordinated self-destruction at the logical and physical layers. This precisely controls the self-destruct process, ensuring data security while reducing unnecessary self-destruct triggers and improving device availability. In complex industrial environments, the device can accurately identify threats, avoid self-destruction due to misjudgment, and ensure normal production.

[0086] (3) High-security encryption: The improved dynamic encryption algorithm uses an improved Logistic-Tent dual-chaos system combined with the acceleration sensor's real-time entropy source to modulate parameters, generating more secure and random keys. The key space is large, changes are complex, and the ability to resist side-channel attacks is strong, effectively improving the security of data encryption and making it difficult for attackers to crack the key and obtain data. In financial data storage and transmission, it can effectively prevent data from being cracked, ensuring the security of funds and user information. BRIEF DESCRIPTION OF THE DRAWINGS

[0087] Attachment Figure 1 : Demonstrates the architecture and workflow of a secure mobile storage device that integrates multiple self-destruction and protection mechanisms.

[0088] Attachment Figure 2 : Demonstrates the key generation and parameter modulation process of the improved Logistic-Tent dual chaotic system in a secure mobile storage device that integrates multiple self-destruction and protection mechanisms. DETAILED DESCRIPTION

[0089] The present invention will be further described below in conjunction with specific embodiments:

[0090] Example 1

[0091] In a power grid environment, power data involves sensitive information such as grid operating status and user information, placing extremely high demands on the security of mobile storage devices. The secure mobile storage device with integrated multiple self-destruction and protection mechanisms based on this invention can effectively ensure the security of power data during storage and transmission.

[0092] 1. Application of equipment structure in power grid environment

[0093] 1.1 Outer shell

[0094] In field operations in power grid environments, mobile storage devices may be subjected to physical forces such as collisions and squeezing, as well as temperature fluctuations caused by heating from electrical equipment or the outdoor environment. Micron-level pressure sensors on the outer shell monitor the pressure applied to the device in real time. For example, during substation equipment installation, if a storage device is accidentally dropped or struck by a tool, the pressure sensor, with an accuracy of ±0.1N, can detect pressure changes greater than 50N within 0.3ms, promptly alerting the system to physical tampering. The temperature sensor, with an operating range of -40°C to 120°C, monitors temperature fluctuations both inside and outside the substation. During high summer temperatures, outdoor substation equipment can exceed 60°C. If the temperature sensor detects an abnormally high temperature, combined with the pressure sensor data, it can further confirm whether the equipment is experiencing an abnormal condition, providing a basis for subsequent protective measures.

[0095] 1.2 Protection circuit layer

[0096] Various electrical disturbances exist in the power grid, such as short circuits and overvoltages, which can threaten the data security of storage devices. The polymorphic thyristor array built into the protection circuit layer can disconnect critical circuits in milliseconds when it detects that the threat score model S(t) exceeds a threshold (for example, when a transient fluctuation in the grid voltage causes the device to detect an abnormal electrical signal, increasing the threat score). For example, when a short circuit occurs in the power grid, the resulting overvoltage may be transmitted through the interface to the mobile storage device. The polymorphic thyristor array responds quickly, disconnecting the circuit and preventing the data within the storage device from being illegally read or destroyed due to the electrical fault, thus ensuring data security.

[0097] 1.3 Dynamic Encryption Module

[0098] Power data requires high-strength encryption protection during transmission and storage. The dynamic encryption module is implemented using an FPGA and a chaotic mapping algorithm. In the power grid dispatch center, large amounts of power dispatch data require real-time encrypted storage. The FPGA's high flexibility and parallel processing capabilities enable rapid execution of encryption algorithms. The dynamic key refresh cycle can be flexibly adjusted within a range of 1ms to 1s. For example, when transmitting power grid operating status data in real time, a shorter key refresh cycle of 100ms is set, allowing for frequent encryption key updates. Even if an attacker attempts to analyze the encrypted data to crack the key, the rapid key updates exponentially increase the difficulty, effectively ensuring the security of power data.

[0099] 1.4 Core Storage Layer

[0100] The core storage layer uses 3D XPoint non-volatile storage media, supporting rapid block-level overwrites at speeds of ≥10GB / s and a measured speed of 12.4GB / s. In scenarios where grid data is frequently updated, such as real-time updates of electricity trading data, rapid block-level overwrites help improve data update efficiency. When a device triggers its self-destruct mechanism, such as when the device is lost and a potential data leak risk is determined, the core storage layer can overwrite the stored data multiple times (e.g., three times) in a short period of time in accordance with NIST SP 800-88 standards. Assuming a 500GB storage device, the logical layer self-destructs in a timeframe of T1 = (3 × 500) ÷ 12.4 ≈ 121 seconds (calculated using the measured overwrite speed), ensuring that the original data cannot be recovered and preventing the leakage of power-sensitive data.

[0101] 1.5 Self-destruction execution unit

[0102] In a power grid environment, if a device is stolen or subjected to a malicious attack, the self-destruct execution unit plays a key role as the last line of defense. When the threat score model S(t) exceeds the threshold and determines that the device is under serious threat, the nano-scale corrosive gas microcapsules in the self-destruct execution unit will be triggered. For example, if someone illegally breaks into the power grid data storage room and attempts to obtain data from a mobile storage device, the self-destruct execution unit will be activated. The nano-scale corrosive gas microcapsules use double-layer nano-polymer encapsulation technology. The inner layer encapsulates 0.5ml of iron oxide powder (Fe2O3) and acidic electrolyte (HCl solution, concentration 5%), and the outer layer is a pressure-resistant ceramic shell (compressive strength ≥ 200MPa). When triggered, a high-voltage electric pulse penetrates the inner polymer layer, triggering a chemical reaction: Fe2O3 + 6HCl → 2FeCl3 + 3H2O. The resulting FeCl3 solution reacts with the storage medium (GaAs) according to the following reaction equation: 2GaAs + 6FeCl3 → 2GaCl3 + 2As↓ + 6FeCl2. This completely oxidizes the storage medium, physically destroying the storage device's structure and ensuring that data cannot be recovered. The microcapsule also incorporates a built-in neutralization device (alkaline filter). When the released gas passes through the filter, it reacts with NaOH to form harmless salts: HCl + NaOH → NaCl + H2O, minimizing its environmental impact.

[0103] 2 Application of self-destruction trigger logic in power grid environment

[0104] 2.1 Threat Score Model

[0105] In the power grid environment, different threat weights are set. For example, for the risk of physical contact with equipment caused by illegal operation of internal personnel in the power grid, w1 is set to 0.4; for equipment abnormality caused by electromagnetic interference from the power grid, w2 is set to 0.3. The signals of the pressure sensor and temperature sensor are used as real-time signals f i (t), normalized to the interval [0,1]. For example, the pressure value detected by the pressure sensor is converted to a value within [0,1] according to its range and sensitivity. If the equipment is subjected to abnormal pressure during power maintenance, the value will approach 1. The historical attack intensity memory function g(τ) records the attacks suffered by the equipment in the past. For example, if there has been an attack incident that caused data transmission errors due to electromagnetic interference, it will increase vigilance against similar attacks in subsequent evaluations. The attenuation coefficients α = 0.2 and β = 0.5 can not only ensure that the historical attack information has reference value for the current score, but also highlight the impact of recent attacks, so that the model can better adapt to changes in the power grid environment. The Bayesian network is used to fuse multi-sensor data. When the pressure and temperature signals conflict, the pressure sensor signal with a higher probability weight shall prevail (pressure signal weight w1 = 0.4, temperature signal weight w2 = 0.3)

[0106] 2.2 Threshold Setting and Dynamic Adjustment

[0107] The threshold θ is initially set to 1.2 and is dynamically adjusted based on historical attack patterns in the power grid environment. In areas where power grid equipment is severely aged and electromagnetic interference is frequent, the threshold is appropriately lowered to allow equipment to respond to threats more quickly. For example, near an older substation, where equipment is frequently subject to electromagnetic interference, the threshold is adjusted to 1.0. When the threat score S(t) exceeds this threshold, the device enters a warning state (with a flashing red LED), requiring the user to enter an authorization code (such as biometrics or a physical button) within 30 seconds to confirm self-destruction. If no confirmation is given, only the logic layer self-destruction is triggered. In newly constructed substations with relatively stable electromagnetic environments, the threshold is moderately increased to 1.4 to reduce unnecessary self-destruction triggers and improve equipment availability.

[0108] 2.3 Multi-stage self-destruction mechanism

[0109] Once the threat score exceeds the threshold, different self-destruction strategies will be executed based on different risk scenarios.

[0110] Low-risk scenario (S(t)∈[1.2,1.5]): Only logical layer self-destruction (3 overwrites) is performed. The storage area is overwritten 3 times according to the NIST SP800-88 standard to quickly clear the data in the storage area.

[0111] High-risk scenario (S(t)>1.5): Simultaneous triggering of logical and physical layer self-destruction. The logical layer self-destruction operates similarly to the low-risk scenario; the thyristors in the physical layer's protective circuitry rapidly fuse critical circuits, cutting off power. The self-destruct execution unit releases corrosive gases, physically destroying the storage device structure, ensuring that power data cannot be recovered and safeguarding grid data security.

[0112] 3 Application of dynamic encryption algorithm in power grid environment

[0113] 3.1 Principle of the Improved Logistic-Tent Dual Chaotic System

[0114] In power grid environments, mobile storage devices experience varying motion states in different operating scenarios. The improved Logistic-Tent dual chaotic system generates a key sequence using two interrelated iterative formulas. For example, as power inspectors carry their equipment between outdoor power towers, the system continuously iterates the formula to generate a highly random and complex key sequence. Compared to traditional single chaotic systems, this system generates a larger key space and more complex and diverse key variations, enhancing the security of power data encryption. However, brute force attacks require attackers to try many more key combinations, exponentially increasing the time and computing resources required to crack the key.

[0115] 3.2 Parameter Modulation Mechanism

[0116] The parameters r∈(3.7,4) and μ∈(0,0.3) are modulated by the real-time entropy source of the equipment's accelerometer. During field operations, equipment motion can be unpredictable, such as the jolting of patrol vehicles and the swaying of power maintenance personnel climbing towers. The accelerometer collects the random information generated by these movements as an entropy source. After sampling with an ADC (sampling rate of 1kHz), the entropy value is extracted using the SHA-3 algorithm to generate a 128-bit random number, which is then mapped to the parameter range:

[0117] r=3.7+0.3×(entropy value 0-63 mod 1000) / 1000

[0118] μ=0.3×(entropy value 64-127 mod 1000) / 1000

[0119] The parameters are updated every 10ms to ensure dynamic key changes. During each encryption operation, due to the different motion states of the device, the modulated r and μ are different, and the generated key sequence is also different. For example, on different power inspection routes, the difference in the motion state of the device will result in different generated keys, which effectively resists attacks on fixed parameter encryption algorithms. The Hamming distance test verifies that this method reduces the sample size required for cracking to O(2 128 ), which improves the device's ability to resist side-channel attacks in a power grid environment.

[0120] The architecture and workflow of a secure mobile storage device with multiple self-destruction and protection mechanisms are as follows:

[0121] The outer shell integrates micron-level pressure and temperature sensors to detect external pressure and temperature changes and detect physical tampering. The micron-level pressure sensor has an accuracy of ±0.1N and can detect subtle pressure changes; the temperature sensor has an operating range of -40°C to 120°C.

[0122] Protective circuit layer: Located inside the outer shell, it houses a polymorphic thyristor array. When the threat scoring model is triggered, the protective circuit layer disconnects the circuit, achieving circuit-breaking protection in milliseconds.

[0123] Dynamic encryption module: Based on FPGA, it adopts chaotic mapping algorithm to perform high-intensity encryption on stored data. The dynamic key refresh cycle is adjustable within the range of 1ms to 1s.

[0124] Core storage layer: Utilizes 3D XPoint non-volatile storage media, supporting block-level rapid overwrites at speeds of ≥10GB / s. In the event of self-destruction, data replication ensures that data cannot be recovered.

[0125] The self-destruct execution unit contains nanoscale corrosive gas microcapsules that, when triggered, release corrosive gas to physically destroy the storage medium, ensuring data is completely irrecoverable. A built-in neutralization device reduces environmental impact. A threat scoring model assesses the threat level by combining real-time sensor data and historical attack scenarios. When the score exceeds a threshold, the corresponding self-destruct sequence is triggered, implementing a multi-stage self-destruct mechanism.

[0126] The key generation and parameter modulation process of the improved Logistic-Tent dual chaotic system in a secure mobile storage device with multiple self-destruction and protection mechanisms mainly includes the following steps:

[0127] 1. Signal Acquisition: The accelerometer is responsible for collecting random information about the device's motion state, such as shaking and collisions during daily use. These signals are sampled by the ADC at a sampling rate of 1kHz, converting the analog signals into digital signals for subsequent processing.

[0128] 2. Entropy extraction: The sampled signal is processed using the SHA-3 algorithm to extract entropy and generate a 128-bit random number. This random number contains the random characteristics of the device's motion state, providing rich random information for subsequent parameter modulation.

[0129] 3. Parameter mapping: Map the generated 128-bit random number to the chaotic system parameter range, specifically: r = 3.7 + 0.3 × (entropy value 0-63 mod 1000) / 1000, μ=0.3×(entropy value 64-127 mod 1000) / 1000, so that the parameters r∈(3.7,4) and μ∈(0,0.3). These parameters are used in the improved Logistic-Tent double chaotic system.

[0130] 4. Parameter Update: Parameters are updated every 10ms to ensure dynamic key changes. Because the device's motion constantly changes during use, the entropy source collected by the accelerometer also changes accordingly. Each parameter update is different, resulting in a different key sequence.

[0131] 5. Chaotic key generation: Using the improved Logistic-Tent dual chaotic system, based on the continuously updated parameters mentioned above, two interrelated iterative formulas are used to generate a key sequence for data encryption. This dynamically changing key generation method makes the key space larger and the changes more complex and diverse during the encryption process, effectively enhancing the security and unpredictability of encryption. The Hamming distance test verifies that the sample size required for cracking reaches O(2 128 ), which greatly improves the device's ability to resist side-channel attacks.

[0132] The embodiments of the present invention are not limited to the above description. In actual application scenarios, device configurations, encryption algorithm parameters, and other aspects can be adjusted to meet different needs. For example, in the military, where security is paramount, the self-destruct mechanism and encryption algorithm can be further optimized. In industrial data storage scenarios, the sensor's monitoring accuracy and range can be adjusted based on the specific characteristics of the industrial environment. Such improvements fall within the scope of protection of the present invention.

Claims

1. A secure mobile storage device integrating multiple self-destruction and protection mechanisms, characterized in that: include: Outer shell: integrated micron-level pressure sensor and temperature sensor for real-time monitoring of the physical state of the environment in which the equipment is located. The micron-level pressure sensor has an accuracy of ±0.1N and can detect subtle pressure changes. The temperature sensor has an operating range of -40°C to 120°C. Protection circuit layer: Located inside the outer shell, it has a built-in polymorphic thyristor array. Upon receiving a specific trigger signal, it cuts off the critical circuit at a millisecond speed to achieve circuit breaker protection. Dynamic encryption module: Based on FPGA implementation, using chaotic mapping algorithm, the key dynamic refresh cycle is adjustable within the range of 1ms to 1s; Core storage layer: uses 3D XPoint non-volatile storage media, supports block-level fast overwrite, and overwrite speed ≥10GB / s; Self-destruction execution unit: Contains nano-scale corrosive gas microcapsules, which are encapsulated in a double layer of nano-polymer. The inner layer encapsulates iron oxide powder and acidic electrolyte, and the outer layer is a pressure-resistant ceramic shell. When triggered, corrosive gas is released to oxidize the storage medium, and a built-in neutralization device reduces environmental impact.

2. The secure mobile storage device with integrated multiple self-destruction and protection mechanisms according to claim 1, characterized in that: It also includes self-destruct trigger logic, specifically: Threat score model: The expression is The threat level is assessed by comprehensively considering the real-time monitoring data of sensors and historical attack situations, where w i is the threat weight of category i, f i (t) is the real-time sensor signal, g(τ) is the historical attack intensity memory function, α and β are the attenuation coefficients, and Bayesian network is used to fuse multi-sensor data; Threshold setting and dynamic adjustment: The initial value of the threshold θ is 1.2 and is dynamically adjusted. When S(t)>θ, the self-destruction program is triggered. When S(t) exceeds the threshold for the first time, the device enters the warning state and the user must confirm the self-destruction within 30 seconds. Otherwise, only the logic layer self-destruction is triggered. Multi-stage self-destruction mechanism: In low-risk scenarios (S(t)∈[1.2,1.5]), only logical layer self-destruction is executed, and the storage area is overwritten three times; in high-risk scenarios (S(t)>1.5), logical and physical layer self-destruction is triggered simultaneously.

3. The secure mobile storage device with integrated multiple self-destruction and protection mechanisms according to claim 1, characterized in that: The dynamic encryption algorithm adopts an improved Logistic-Tent dual chaotic system, combined with the real-time entropy source modulation parameters of the device acceleration sensor, specifically: The improved Logistic-Tent double chaotic system generates the key sequence through two interrelated iterative formulas; After the acceleration sensor signal is sampled by ADC (sampling rate 1kHz), the entropy value is extracted by SHA-3 algorithm to generate a 128-bit random number, which is mapped to the parameter interval r = 3.7 + 0.3 × (entropy value 0-63 mod1000) / 1000, μ=0.3×(entropy value 64- 127 mod1000) / 1000, the parameter is updated every 10ms.