Data writing method, electronic equipment, storage medium and program product
By distinguishing data types and performing file-level encryption on sensitive data, the problem of low data writing efficiency in the existing technology is solved, and efficient writing of non-sensitive data is achieved.
Patent Information
- Application Number
- CN202510703013.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-28
- Publication Date
- 2025-09-12
AI Technical Summary
In the prior art, during the data writing process, file-level encryption technology needs to be activated to determine whether the data to be written needs to be encrypted, resulting in low data writing efficiency.
Sensitive and non-sensitive data are distinguished based on data type. Sensitive data is encrypted using file-level encryption technology and then written to the physical storage partition. Non-sensitive data is directly written to the interval storage partition, skipping the file-level encryption process.
Improves the efficiency of data writing, especially when the data type is non-sensitive, and can be written directly to the interval storage partition without encryption, which improves the writing speed.
Smart Images

Figure CN120632906A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of data processing, and in particular to a data writing method, electronic equipment, storage medium, and program product. Background Art
[0002] File-Based Encryption (FBE) technology is a storage security technology that encrypts files at the granularity of a single file. It can assign independent keys to different users, applications, or data categories to achieve fine-grained access control.
[0003] In related technologies, when processing data to be written, FBE technology must be enabled. FBE technology is used to determine whether each data to be written requires encryption. The data that requires encryption is then encrypted before being written to the physical storage partition. However, FBE must be enabled before writing the data, either encrypted or unencrypted, resulting in low data writing efficiency. Summary of the Invention
[0004] The embodiments of the present application provide a data writing method, an electronic device, a storage medium, and a program product to improve the data writing efficiency.
[0005] In a first aspect, an embodiment of the present application provides a method for writing data, which is applied to a terminal device, wherein the terminal device includes a physical storage partition, and the method includes:
[0006] Determine the data type of the data to be written;
[0007] If the data type of the data to be written is a sensitive type, encrypting the data to be written using a file-level encryption technology to obtain encrypted data, and writing the encrypted data into the physical storage partition;
[0008] If the data type of the data to be written is a non-sensitive type, the data to be written is written into the interval storage partition of the physical storage partition.
[0009] In one possible implementation, writing the encrypted data into the physical storage partition includes:
[0010] Determining a first storage location corresponding to the encrypted data in a first direction of the physical storage partition, one end of the physical storage partition including the interval storage partition, the first direction being a direction from a non-interval storage partition of the physical storage partition toward the interval storage partition;
[0011] The encrypted data is written to the first storage location.
[0012] In a possible implementation, writing the to-be-written data into the interval storage partition of the physical storage partition includes:
[0013] Determining a second storage location of the to-be-written data in a second direction of the interval storage partition, where the second direction is a direction from the interval storage partition to the non-interval storage partition;
[0014] The data to be written is written into the second storage location.
[0015] In a possible implementation, when writing encrypted data in the first direction of the physical storage partition, if the storage location of the storage partition corresponding to the non-interval storage partition is insufficient, the encrypted data is written into the interval storage partition.
[0016] In one possible implementation, determining the data type of the data to be written includes:
[0017] If the data to be written is data that meets the preset condition, determining the data type of the data to be written as the non-sensitive type;
[0018] If the data to be written is data that does not meet the preset condition, the data type of the data to be written is determined to be the sensitive type.
[0019] In a possible implementation, the preset condition includes at least one of the following:
[0020] The data to be written is data encrypted by the application, or the data to be written is preset file data, wherein the preset file data includes at least one of the following: application package file, bytecode file, local machine code file, shared object library file.
[0021] In a second aspect, an embodiment of the present application provides a method for reading and writing data, which is applied to a terminal device, and the method includes:
[0022] Determine the data type of the data to be read;
[0023] If the data type of the data to be read is a sensitive type, obtaining encrypted data corresponding to the data to be read from the physical storage partition, and decrypting the encrypted data using file-level encryption technology to obtain the data to be read;
[0024] If the data type of the data to be read is a non-sensitive type, the data to be read is read from the interval storage partition.
[0025] In a third aspect, an embodiment of the present application provides a data writing device, which is applied to a terminal device, wherein the terminal device includes a physical storage partition. The device includes a first determination module, an encryption module, a first writing module, and a second writing module:
[0026] The first determining module is used to determine the data type of the data to be written;
[0027] The encryption module is used to encrypt the data to be written using file-level encryption technology to obtain encrypted data if the data type of the data to be written is a sensitive type;
[0028] The first writing module is used to write the encrypted data into the physical storage partition;
[0029] The second writing module is configured to write the data to be written into the interval storage partition of the physical storage partition if the data type of the data to be written is a non-sensitive type.
[0030] In a possible implementation manner, the first writing module is specifically configured to:
[0031] Determining a first storage location corresponding to the encrypted data in a first direction of the physical storage partition, one end of the physical storage partition including the interval storage partition, the first direction being a direction from a non-interval storage partition of the physical storage partition toward the interval storage partition;
[0032] The encrypted data is written to the first storage location.
[0033] In a possible implementation manner, the first writing module is specifically configured to:
[0034] Determining a second storage location of the to-be-written data in a second direction of the interval storage partition, where the second direction is a direction from the interval storage partition to the non-interval storage partition;
[0035] The data to be written is written into the second storage location.
[0036] In a possible implementation, when writing encrypted data in the first direction of the physical storage partition, if the storage location of the storage partition corresponding to the non-interval storage partition is insufficient, the encrypted data is written into the interval storage partition.
[0037] In a possible implementation manner, the first determining module is specifically configured to:
[0038] If the data to be written is data that meets the preset condition, determining the data type of the data to be written as the non-sensitive type;
[0039] If the data to be written is data that does not meet the preset condition, the data type of the data to be written is determined to be the sensitive type.
[0040] In a possible implementation, the preset condition includes at least one of the following:
[0041] The data to be written is data encrypted by the application, or the data to be written is preset file data, wherein the preset file data includes at least one of the following: application package file, bytecode file, local machine code file, shared object library file.
[0042] In a fourth aspect, an embodiment of the present application provides a data reading device, which is applied to a terminal device. The device includes a second determination module, an acquisition module, a decryption module, and a reading module.
[0043] The second determining module is used to determine the data type of the data to be read;
[0044] The acquisition module is configured to acquire, from a physical storage partition, encrypted data corresponding to the data to be read if the data type of the data to be read is a sensitive type;
[0045] The decryption module is used to decrypt the encrypted data using file-level encryption technology to obtain the data to be read;
[0046] The reading module is configured to read the data to be read from the interval storage partition if the data type of the data to be read is a non-sensitive type.
[0047] In a fifth aspect, an embodiment of the present application provides a ... device, comprising: a memory, a processor;
[0048] The memory stores computer-executable instructions;
[0049] The processor executes the computer-executable instructions stored in the memory, so that the processor executes the above first aspect and / or various possible implementations of the first aspect.
[0050] In a sixth aspect, an embodiment of the present application provides a computer-readable storage medium, in which computer-executable instructions are stored. When the computer-executable instructions are executed by a processor, they are used to implement the first aspect above and / or various possible implementation methods of the first aspect.
[0051] In a seventh aspect, an embodiment of the present application provides a computer program product, including a computer program, which, when executed by a processor, implements the above first aspect and / or various possible implementation methods of the first aspect.
[0052] The data writing method, electronic device, storage medium, and program product provided in the embodiments of the present application can determine the data type of the data to be written. If the data type of the data to be written is sensitive, the data to be written is encrypted using file-level encryption technology to obtain encrypted data, and the encrypted data is written to a physical storage partition. If the data type of the data to be written is non-sensitive, the data to be written is written to an interval storage partition of the physical storage partition. When the data type is non-sensitive, the file-level encryption technology can be skipped and the data to be written can be directly written to the interval storage partition of the physical storage partition, which can improve the efficiency of data writing. BRIEF DESCRIPTION OF THE DRAWINGS
[0053] The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate embodiments consistent with the present application and, together with the description, serve to explain the principles of the present application.
[0054] Figure 1 A schematic diagram of an application scenario provided in an embodiment of the present application;
[0055] Figure 2 A flowchart of a method for writing data provided in an embodiment of the present application;
[0056] Figure 3 A schematic diagram of the architecture of a data writing method provided in an embodiment of the present application;
[0057] Figure 4 A schematic diagram of the structure of a physical storage partition provided in an embodiment of the present application;
[0058] Figure 5 A flowchart of a data reading method provided in an embodiment of the present application;
[0059] Figure 6 A schematic diagram of an architecture for reading and writing data provided in an embodiment of the present application;
[0060] Figure 7 A schematic diagram of another data reading and writing architecture provided in an embodiment of the present application;
[0061] Figure 8 A schematic structural diagram of a data writing device provided in an embodiment of the present application;
[0062] Figure 9 A schematic diagram of the structure of a data reading device provided in an embodiment of the present application;
[0063] Figure 10 A schematic diagram of the structure of an electronic device provided in an embodiment of the present application.
[0064] The above drawings illustrate specific embodiments of the present application, which will be described in more detail below. These drawings and the textual description are not intended to limit the scope of the present application in any way, but rather to illustrate the concepts of the present application to those skilled in the art by reference to specific embodiments. DETAILED DESCRIPTION
[0065] Exemplary embodiments will be described in detail herein, with examples illustrated in the accompanying drawings. In the following description, when referring to the drawings, identical numerals in different figures represent identical or similar elements, unless otherwise indicated. The embodiments described in the following exemplary embodiments are not intended to represent all embodiments consistent with the present application. Rather, they are merely examples of apparatus and methods consistent with certain aspects of the present application, as detailed in the appended claims.
[0066] Figure 1 This is a schematic diagram of an application scenario provided by an embodiment of this application. Figure 1 In the terminal device 100, the operating system can divide the kernel space and the user space through permission control. The kernel space is the memory area where the operating system kernel runs, and the user space is the memory area where ordinary applications run. The application permissions are limited and cannot directly operate the hardware or kernel data.
[0067] The kernel space includes a flash memory chip, which can be divided into different physical partitions. Each physical partition can correspond to a different address range and usage purpose. The physical storage partitions of multiple physical partitions of the flash memory chip can be used to store data in the user space.
[0068] When storing data in user space in a physical storage partition, file-based encryption (FBE) can be used to encrypt the data before writing it to the physical storage partition. File-based encryption is a storage security technology that encrypts individual files at the granularity. It can assign independent keys to different users, applications, or data categories, enabling fine-grained access control.
[0069] In file-level encryption technology, physical storage partitions can be mounted in a data directory (for example, / data / ). Under the data directory, targets can be divided into two categories: encrypted directories (for example, / data / app, / data / dalvik-cache / , / data / data / , etc.) and non-encrypted directories (for example, / data / lost+found / , / data / preloads / , etc.). Data written to encrypted directories is encrypted, while data written to non-encrypted directories is not encrypted.
[0070] In the operating system's initialization configuration file init.rc, you can use the mkdir command to create a directory. The encryption parameter is used to specify the directory encryption policy. Specifically, the command mkdir / data / cache 0770 systemcache encryption = Require is used to force encryption of the directory, and the command mkdir / data / cache0770 system cache encryption = None is used to specify that the directory is not encrypted.
[0071] Encryption policies can be set using the ioctl command. The ioctl Application Programming Interface (API) facilitates interaction between user space and kernel space. For example, the encryption policy can be: a) If the parent directory is encrypted, the subdirectory automatically inherits the parent directory's encryption policy when it is created (in this case, it cannot be changed to a different encryption policy or set to no encryption); b) If the parent directory is not encrypted, the subdirectory is created without encryption by default. If encryption is required for the subdirectory, the encryption policy can be set using the ioctl API.
[0072] Based on the above scenario, it can be seen that in related technologies, when processing data to be written, file-level encryption technology needs to be activated. File-level encryption technology is used to determine whether each data to be written needs to be encrypted. The data that needs to be encrypted is then encrypted before being written to the physical storage partition. However, before writing the data to be written encrypted or unencrypted, file-level encryption technology needs to be activated, which reduces the efficiency of data writing.
[0073] The data writing method provided in the embodiments of the present application can determine the data type of the data to be written. If the data type of the data to be written is sensitive, the data to be written is encrypted using file-level encryption technology to obtain encrypted data, and the encrypted data is written to the physical storage partition. If the data type of the data to be written is non-sensitive, the data to be written is written to the interval storage partition of the physical storage partition. When the data type is non-sensitive, the file-level encryption technology can be skipped and the data to be written can be directly written to the interval storage partition of the physical storage partition, which can improve the efficiency of data writing.
[0074] The following specific embodiments describe in detail the technical solution of the present application and how the technical solution of the present application solves the above-mentioned technical problems. The following specific embodiments can be combined with each other, and the same or similar concepts or processes may not be repeated in some embodiments. The embodiments of the present application will be described below in conjunction with the accompanying drawings.
[0075] Figure 2This is a flow chart of the data writing method provided in the embodiment of the present application. Figure 2 , the method comprising:
[0076] S201: Determine the data type of the data to be written.
[0077] The execution subject of the embodiment of the present application can be a terminal device or a chip of the terminal device, or a data writing device set in a processing device or a chip of the processing device. The data writing device can be implemented by software or a combination of software and hardware.
[0078] The data to be written may be data in various applications, and the data types of the data to be written may include sensitive types and non-sensitive types.
[0079] In some possible embodiments, if the data to be written is data that meets preset conditions, the data type of the data to be written is determined to be a non-sensitive type; if the data to be written is data that does not meet the preset conditions, the data type of the data to be written is determined to be a sensitive type.
[0080] The preset conditions include at least one of the following: the data to be written is data that has been encrypted by the application, or the data to be written is preset file data.
[0081] The preset file data may be program data related to the user in the application, but does not involve information about the user himself. The preset file data includes at least one of the following: application package file, bytecode file, local machine code file, shared object library file, etc.
[0082] The application package file may be an APK (Android Package) file, which is an installation package file of an application.
[0083] Bytecode files can include DEX files (Dalvik EXecutable), ODEX files (Optimized DEX), and VDEX files (Verifiable DEX). Bytecode files can improve operating efficiency.
[0084] The local machine code file can be an OAT file (ART Ahead-Of-Time Binary, ART precompiled binary). The local machine code file can improve application performance.
[0085] The shared object library file may be a shared object library (SO) file, which may provide hardware acceleration or cross-platform functionality.
[0086] S202: If the data type of the data to be written is a sensitive type, the data to be written is encrypted using a file-level encryption technology to obtain encrypted data, and the encrypted data is written into a physical storage partition.
[0087] The physical storage partition is a physical partition in the flash memory chip of the terminal device for storing user data. The physical storage partition may include multiple data blocks, and the encrypted data may be written into the corresponding data blocks.
[0088] S203: If the data type of the data to be written is a non-sensitive type, the data to be written is written into the interval storage partition of the physical storage partition.
[0089] The interval storage partition is a part of the physical storage partition. The interval storage partition is used to store non-sensitive user data. This data does not need to be encrypted and can be directly written into the interval storage partition.
[0090] Figure 3 This is a schematic diagram of the architecture of a data writing method provided in an embodiment of the present application. Figure 3 During the execution of an application (APP), if data to be written needs to be written to a target directory, the application can determine whether the data type is sensitive. If it is, the data to be written is encrypted to obtain encrypted data, and the encrypted data is written to the physical storage partition corresponding to the target directory, and the process ends. If not, the target directory is determined to be updated to a range directory, and the data to be written is written to the range storage partition corresponding to the range directory, and the process ends.
[0091] Among them, the target directory can include the / data / app directory, the / data / dalvik-cache / directory, and the / data / data / directory, etc., among which the interval directory corresponding to the / data / app directory is the / data / app-unencrypt / directory, the interval directory corresponding to the / data / dalvik-cache / directory is the / data / dalvik-cache—unencrypt / directory, and the interval directory corresponding to the / data / data / directory is the / data / app-unencrypt / directory.
[0092] That is, the target directory may be an encrypted directory under the data directory, and an interval directory is added under the data directory. The interval directory is used to indicate that data is written to the interval storage partition, and the FBE technology is not started in the interval storage partition.
[0093] To check whether the mounted partition corresponding to a directory has FBE technology enabled, you can use the mount command to check whether the mount option contains the inlinecrypt keyword.
[0094] Specifically, you can use the df command to view the partition mounted on the target directory, and use the mount command to check whether the partition has the inlinecrypt keyword. If the inlinecrypt keyword does not exist, the FBE technology is not started in the partition. If the inlinecrypt keyword exists, the FBE technology is started in the partition.
[0095] The data writing method provided in the embodiment of the present application uses file-level encryption technology to encrypt the data to be written when the data type of the data to be written is a sensitive type, obtains encrypted data, and writes the encrypted data into a physical storage partition; when the data type of the data to be written is a non-sensitive type, the file-level encryption technology can be skipped, and the data to be written can be directly written into the interval storage partition of the physical storage partition, which can improve the efficiency of data writing.
[0096] Next, combine Figure 4 , further explains the physical storage partitions and interval storage partitions provided in the embodiments of the present application.
[0097] Figure 4 This is a schematic diagram of the structure of a physical storage partition provided in an embodiment of the present application. Figure 4 ,The bottom part is the physical storage partition, which is the actual physical storage area on the flash memory chip, and is used to store encrypted data. The physical storage partition corresponds to the first mapping volume, which is used for logical volume management. The first mapping volume is mounted on the data directory, and file-level encryption is enabled for encryption.
[0098] One end of the physical storage partition is the interval storage partition, which corresponds to the second mapped volume. The second mapped volume can be mounted on an interval directory. The interval storage partition is used to store unencrypted data. The interval directories can be / data / app-unencrypt / , / data / dalvik-cache-unencrypt / , and / data / data-unencrypt / . The / data / app-unencrypt / directory is the unencrypted application data directory, the / data / dalvik-cache-unencrypt / directory is the unencrypted Dalvik cache directory, and the / data / data-unencrypt / directory is the unencrypted data directory.
[0099] In this application, the device mapping mechanism can be used to achieve flexible management of physical storage partitions. By storing non-encrypted data in interval storage partitions, the efficiency of data writing is improved while taking security into consideration, ensuring performance requirements.
[0100] In some embodiments, when writing encrypted data into a physical storage partition, a first storage location corresponding to the encrypted data may be determined in a first direction of the physical storage partition, and the encrypted data may be written into the first storage location.
[0101] The first direction can be from a non-interval storage partition of a physical storage partition to an interval storage partition, for example, see Figure 4 ,The first direction is from left to right in the physical storage partition.
[0102] When writing encrypted data in the first direction of the physical storage partition, if the storage location of the storage partition corresponding to the non-interval storage partition is insufficient, the encrypted data may be written into the interval storage partition.
[0103] In this application, when the space in the non-interval storage partition is insufficient, the free space in the interval storage partition is used to avoid the situation where the application cannot be installed or run when the non-interval storage partition space is insufficient and the interval storage partition space is sufficient, thereby improving the stability of the application operation.
[0104] In some embodiments, when writing the data to be written into the interval storage partition, a second storage location of the data to be written may be determined in a second direction of the interval storage partition, and the data to be written may be written into the second storage location.
[0105] The second direction can be from the interval storage partition to the non-interval storage partition. For example, see Figure 4 , the second direction is the direction from right to left in the interval storage interval.
[0106] In the present application, the data to be written is stored sequentially in the interval storage partition along the second direction, and a storage location can be reserved for the encrypted data in the first direction. This can facilitate the storage of encrypted data in the first direction of the interval storage partition when there is insufficient space in the non-interval storage partition, thereby improving the efficiency of reading and writing data.
[0107] In contrast, after writing the encrypted data and the non-encrypted data (ie, the data to be written) into the physical storage partition, it is necessary to read the data in the physical storage partition. Figure 5 The data reading method provided in the embodiment of the present application is described.
[0108] Figure 5 This is a flow chart of a data reading method provided in an embodiment of the present application. Figure 5 , the method may include:
[0109] S501: Determine the data type of the data to be read.
[0110] In the user space of the terminal device, when an application needs to read data to be read, it can obtain a designated directory corresponding to the data to be read, and determine the data type of the data to be read based on the designated directory.
[0111] For example, assume that the encrypted data storage directory is / data / , and the unencrypted data storage directories are / data / app-unencrypt, / data / dalvik-cache-unencrypt / , and / data / data-unencrypt / . If the specified directory is / data / , the data type to be read is sensitive. If the specified directory is any one of / data / app-unencrypt, / data / dalvik-cache-unencrypt / , and / data / data-unencrypt / , the data type to be read is non-sensitive.
[0112] S502: If the data type of the data to be read is a sensitive type, the encrypted data corresponding to the data to be read is obtained from the physical storage partition, and the encrypted data is decrypted using file-level encryption technology to obtain the data to be read.
[0113] S503: If the data type of the data to be read is a non-sensitive type, the data to be read is read from the interval storage partition.
[0114] The data reading method provided in the embodiments of the present application stores non-sensitive data directly in the interval storage partition. If the data type to be read is non-sensitive, the data to be read can be read from the interval storage partition without decrypting the data, thereby improving data reading efficiency. In addition, sensitive data is stored in the physical storage partition and non-sensitive data is stored in the interval storage partition. When reading data, data can be obtained from different partitions according to the data type, which can also improve data efficiency.
[0115] For ease of understanding, the following Figure 6 and Figure 7 , a comparison is given between the application reading and writing data provided in the embodiment of the present application and the data reading and writing in the related art.
[0116] Figure 6 This is a schematic diagram of the architecture for reading and writing data provided in this application embodiment. Figure 6The terminal device includes user space and kernel space. In user space, the app writes sensitive data, which is encrypted within the app to obtain first encrypted data. In related technologies, after entering kernel space, the first encrypted data is encrypted again using file-level encryption (i.e., FBE encryption) to obtain second encrypted data, which is then written to the flash memory chip. In this application, after entering kernel space, if the data to be written is the first encrypted data, which is already encrypted by the app, encryption using file-level encryption is skipped and the first encrypted data is directly written to the flash memory chip.
[0117] When an app reads sensitive data, related technologies require reading the second encrypted data from the flash memory chip and then decrypting it using file-level encryption (FBE) to obtain the first encrypted data. In this application, the first encrypted data can be directly retrieved from the flash memory space. After entering the user space, the app then decrypts the first encrypted data to obtain the sensitive data.
[0118] Figure 7 This is a schematic diagram of another data reading and writing architecture provided in an embodiment of the present application. Figure 7 The terminal device includes user space and kernel space. In the user space, the data to be written by the APP is non-sensitive data, which is a type of pre-screened file data. In related technologies, after entering the kernel space, it is necessary to encrypt the non-sensitive data using file-level encryption technology to obtain third encrypted data, and then write the third encrypted data to the flash memory chip. In this application, the file-level encryption technology can be skipped and the non-sensitive data can be directly written to the flash memory chip.
[0119] When the APP reads non-sensitive data, in the related art, the third encrypted data is read from the flash memory chip, and then the third encrypted data is decrypted using file-level encryption technology to obtain the non-sensitive data. In this application, non-sensitive data can be read directly from the flash memory chip.
[0120] Figure 8 This is a schematic diagram of the structure of a data writing device provided in an embodiment of the present application. Figure 8 The data writing device 800 includes a first determining module 801, an encryption module 802, a first writing module 803 and a second writing module 804:
[0121] The first determining module 801 is used to determine the data type of the data to be written;
[0122] The encryption module 802 is used to encrypt the data to be written using file-level encryption technology to obtain encrypted data if the data type of the data to be written is a sensitive type;
[0123] The first writing module 803 is used to write the encrypted data into the physical storage partition;
[0124] The second writing module 804 is configured to write the data to be written into the interval storage partition of the physical storage partition if the data type of the data to be written is a non-sensitive type.
[0125] In a possible implementation, the first writing module 803 is specifically configured to:
[0126] Determining a first storage location corresponding to the encrypted data in a first direction of the physical storage partition, where one end of the physical storage partition includes the interval storage partition, and the first direction is a direction from a non-interval storage partition of the physical storage partition to the interval storage partition;
[0127] The encrypted data is written to the first storage location.
[0128] In a possible implementation, the first writing module 803 is specifically configured to:
[0129] Determine a second storage location for the data to be written in a second direction of the interval storage partition, where the second direction is a direction from the interval storage partition to the non-interval storage partition;
[0130] The data to be written is written into the second storage location.
[0131] In a possible implementation, when writing encrypted data in a first direction of a physical storage partition, if the storage location of the storage partition corresponding to the non-interval storage partition is insufficient, the encrypted data is written into the interval storage partition.
[0132] In a possible implementation, the first determining module 801 is specifically configured to:
[0133] If the data to be written meets the preset conditions, the data type of the data to be written is determined to be a non-sensitive type;
[0134] If the data to be written does not meet the preset conditions, the data type of the data to be written is determined to be a sensitive type.
[0135] In one possible implementation, the preset condition includes at least one of the following:
[0136] The data to be written is data encrypted by the application, or the data to be written is preset file data, wherein the preset file data includes at least one of the following: an application package file, a bytecode file, a local machine code file, and a shared object library file.
[0137] The data writing device provided in this embodiment can execute the method provided by the terminal device in the above embodiment. Its implementation principle and technical effects are similar and will not be described in detail in this embodiment.
[0138] Figure 9 This is a schematic diagram of the structure of a data reading device provided in an embodiment of the present application. Figure 9 The data reading device 900 includes a second determination module 901, an acquisition module 902, a decryption module 903 and a reading module 904.
[0139] The second determining module 901 is used to determine the data type of the data to be read;
[0140] The acquisition module 902 is configured to acquire the encrypted data corresponding to the data to be read from the physical storage partition if the data type of the data to be read is a sensitive type;
[0141] The decryption module 903 is used to decrypt the encrypted data using file-level encryption technology to obtain the data to be read;
[0142] The reading module 904 is configured to read the data to be read from the interval storage partition if the data type of the data to be read is a non-sensitive type.
[0143] Figure 10 This is a schematic diagram of the structure of an electronic device provided in an embodiment of the present application. Figure 10 The electronic device 1000 may include a processor 1001 and a memory 1002. Exemplarily, the processor 1001 and the memory 1002 are interconnected via a bus 1003.
[0144] Memory 1002 stores computer-executable instructions;
[0145] The processor 1001 executes the computer-executable instructions stored in the memory 1002 , so that the processor 1001 executes the data writing method shown in the above embodiment.
[0146] The electronic device may be a chip, a module, an integrated development environment (IDE), etc.
[0147] Accordingly, an embodiment of the present application provides a chip, which includes at least one processor, and the processor is used to execute computer-executable instructions to implement the data writing method or data reading method of the above method embodiment.
[0148] Accordingly, an embodiment of the present application provides a computer-readable storage medium, which stores computer-executable instructions. When the computer-executable instructions are executed by a processor, they are used to implement the data writing method or data reading method of the above method embodiment.
[0149] Accordingly, an embodiment of the present application may also provide a computer program product, including a computer program. When the computer program is executed by a processor, it can implement the data writing method or data reading method shown in the above method embodiment.
[0150] The computer-readable storage medium and computer program product of the embodiments of the present application can execute the methods provided in the above embodiments. The specific implementation process and beneficial effects thereof are described above and will not be repeated here.
[0151] All or part of the steps of the above-described embodiments may be implemented by hardware associated with program instructions. The aforementioned program may be stored in a readable memory. When executed, the program performs the steps of the above-described embodiments. The aforementioned memory (storage medium) includes: read-only memory (ROM), random access memory (RAM), flash memory, hard disk, solid-state drive, magnetic tape, floppy disk, optical disk, and any combination thereof.
[0152] The embodiments of the present application are described with reference to the flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to the embodiments of the present application. It should be understood that each process and / or box in the flowchart and / or block diagram, as well as the combination of the processes and / or boxes in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processing unit of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processing unit of the computer or other programmable data processing device generate instructions for implementing the steps in the process. Figure 1 a process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.
[0153] These computer program instructions may also be stored in a computer readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 a process or multiple processes and / or boxes Figure 1 The function specified in one or more boxes.
[0154] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operational steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing the instructions executed on the computer or other programmable device for implementing the process. Figure 1 a process or multiple processes and / or boxes Figure 1 A step that specifies a function in one or more boxes.
[0155] Obviously, those skilled in the art may make various changes and modifications to the embodiments of the present application without departing from the spirit and scope of the present application. Thus, if these modifications and variations of the embodiments of the present application fall within the scope of the claims of the present application and their equivalents, the present application is intended to include such modifications and variations.
Claims
1. A method for writing data, characterized in that: Applied to a terminal device, the terminal device including a physical storage partition, the method comprising: Determine the data type of the data to be written; If the data type of the data to be written is a sensitive type, encrypting the data to be written using a file-level encryption technology to obtain encrypted data, and writing the encrypted data into the physical storage partition; If the data type of the data to be written is a non-sensitive type, the data to be written is written into the interval storage partition of the physical storage partition.
2. The method according to claim 1, characterized in that Writing the encrypted data into the physical storage partition comprises: Determining a first storage location corresponding to the encrypted data in a first direction of the physical storage partition, one end of the physical storage partition including the interval storage partition, the first direction being a direction from a non-interval storage partition of the physical storage partition toward the interval storage partition; The encrypted data is written to the first storage location.
3. The method according to claim 2, characterized in that Writing the data to be written into the interval storage partition of the physical storage partition includes: Determining a second storage location of the to-be-written data in a second direction of the interval storage partition, where the second direction is a direction from the interval storage partition to the non-interval storage partition; The data to be written is written into the second storage location.
4. The method according to claim 3, characterized in that When writing encrypted data in the first direction of the physical storage partition, if the storage location of the storage partition corresponding to the non-interval storage partition is insufficient, the encrypted data is written into the interval storage partition.
5. The method according to claim 1, wherein Determine the data type of the data to be written, including: If the data to be written is data that meets the preset condition, determining the data type of the data to be written as the non-sensitive type; If the data to be written is data that does not meet the preset condition, the data type of the data to be written is determined to be the sensitive type.
6. The method according to claim 5, characterized in that The preset conditions include at least one of the following: The data to be written is data encrypted by the application, or the data to be written is preset file data, wherein the preset file data includes at least one of the following: application package file, bytecode file, local machine code file, shared object library file.
7. A method for reading data, characterized in that: Applied to a terminal device, the method includes: Determine the data type of the data to be read; If the data type of the data to be read is a sensitive type, obtaining encrypted data corresponding to the data to be read from the physical storage partition, and decrypting the encrypted data using file-level encryption technology to obtain the data to be read; If the data type of the data to be read is a non-sensitive type, the data to be read is read from the interval storage partition.
8. A data writing device, characterized in that: Applied to a terminal device, the terminal device includes a physical storage partition, and the apparatus includes a determination module, an encryption module, a first writing module, and a second writing module: The determining module is used to determine the data type of the data to be written; The encryption module is used to encrypt the data to be written using file-level encryption technology to obtain encrypted data if the data type of the data to be written is a sensitive type; The first writing module is used to write the encrypted data into the physical storage partition; The second writing module is configured to write the data to be written into the interval storage partition of the physical storage partition if the data type of the data to be written is a non-sensitive type.
9. A data reading device, characterized in that: Applied to a terminal device, the apparatus includes a second determination module, an acquisition module, a decryption module, and a reading module. The second determining module is used to determine the data type of the data to be read; The acquisition module is configured to acquire, from a physical storage partition, encrypted data corresponding to the data to be read if the data type of the data to be read is a sensitive type; The decryption module is used to decrypt the encrypted data using file-level encryption technology to obtain the data to be read; The reading module is configured to read the data to be read from the interval storage partition if the data type of the data to be read is a non-sensitive type.
10. A chip, characterized in that: The chip comprises at least one processor configured to execute computer-implemented instructions to perform the method according to any one of claims 1 to 7.
11. An electronic device, characterized in that: include: Processor, memory; The memory stores a computer program; The processor calls the computer program stored in the memory, causing the electronic device to execute the method according to any one of claims 1 to 7.
12. A computer-readable storage medium, characterized in that The computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the method according to any one of claims 1 to 7 is implemented.
13. A computer program product, characterized in that The invention comprises a computer program, which implements the method according to any one of claims 1 to 7 when the computer program is executed by a processor.