USB flash disk dynamic encryption method and system based on cloud edge collaboration
Through the cloud-edge collaborative dynamic encryption method, dynamic keys are generated using multiple verifications of mobile APP and cloud server, which solves the problem of insufficient reliability and security of existing encrypted USB flash drives and realizes high reliability and high security dynamic encryption of USB flash drives.
Patent Information
- Application Number
- CN202510831854.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-20
- Publication Date
- 2025-09-23
AI Technical Summary
Existing encrypted USB flash drives rely on users entering passwords or simple local authentication. They lack trusted joint authentication of the USB flash drive identity and the user identity, making them easily cracked or bypassed. This results in poor reliability and an inability to verify the legitimacy of the device.
A dynamic encryption method based on cloud-edge collaboration is adopted. A connection is established with the encrypted USB flash drive through the mobile APP to perform user biometric authentication and encrypted USB flash drive identification. The cloud server generates a cloud dynamic key after multiple verifications, and negotiates a temporary session key through Bluetooth and BLE to realize the generation of USB flash drive dynamic keys and data decryption.
It achieves high-reliability and high-security dynamic encryption of USB flash drives, prevents forgery and replay attacks, ensures trusted joint authentication of device legitimacy and user identity, and improves the security and flexibility of encrypted USB flash drives.
Smart Images

Figure CN120692549A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of data security, and specifically relates to a USB flash drive dynamic encryption method and system based on cloud-edge collaboration. Background Art
[0002] Data security is of paramount importance today. Encrypted USB flash drives are widely used as portable and secure storage devices. Existing encrypted USB flash drives typically utilize hardware encryption chips (such as controllers supporting AES / XTS algorithms) to implement static encryption protection for stored data. Unlocking is accomplished by user input of a password or physical verification.
[0003] However, existing encrypted USB flash drives still have some problems. Most rely solely on user-entered passwords or simple local authentication methods. They lack trusted joint authentication of the USB flash drive and the user's identity, making them susceptible to cracking or bypassing. Furthermore, they cannot verify the legitimacy of the device itself. Consequently, existing encrypted USB flash drives are relatively unreliable and are no longer suitable for today's security requirements. Summary of the Invention
[0004] One of the purposes of the present invention is to provide a USB flash drive dynamic encryption method based on cloud-edge collaboration with high reliability and good security.
[0005] The second purpose of the present invention is to provide a system for implementing the U disk dynamic encryption method based on cloud-edge collaboration.
[0006] The present invention provides a method for dynamically encrypting a USB flash drive based on cloud-edge collaboration, comprising the following steps:
[0007] S1. When the encrypted USB drive is inserted into the computer host, the mobile app establishes a connection with the encrypted USB drive and identifies the encrypted USB drive;
[0008] S2. The mobile app authenticates the user and sends the user information and encrypted USB flash drive information to the cloud server.
[0009] S3. After the cloud server performs multiple verifications, it generates a cloud-based dynamic key and sends it to the mobile app.
[0010] S4. The mobile app sends the received data to the encrypted USB drive;
[0011] S5. The encrypted USB drive generates a dynamic key for the USB drive, verifies it with the received dynamic key from the cloud, and decrypts its own data based on the verification result.
[0012] When the encrypted USB flash drive is inserted into the computer host, the mobile APP establishes a connection with the encrypted USB flash drive and identifies the encrypted USB flash drive, specifically including the following steps:
[0013] When the encrypted USB drive is inserted into the computer host, the encrypted USB drive activates its own Bluetooth;
[0014] The encrypted USB drive starts BLE broadcasting; the broadcast content includes the device UUID, a dynamic HMAC generated based on the timestamp and serial number, and the service identifier;
[0015] The mobile app scans the BLE broadcast, confirms that the encrypted USB drive is legitimate, and then initiates a BLE connection request to the encrypted USB drive;
[0016] The mobile app establishes a connection with the encrypted USB drive;
[0017] The mobile app reads the public key of the encrypted USB drive and generates a temporary session key through ECDH negotiation with the encrypted USB drive.
[0018] The mobile APP in step S2 performs user identity authentication and sends the user information and encrypted USB disk information to the cloud server, which specifically includes the following steps:
[0019] The mobile app calls the WebAuthn interface on the mobile side to perform biometric authentication on the mobile user;
[0020] After the user passes the biometric authentication, the mobile app generates a signature assertion; the signature assertion includes the user ID, timestamp and random factor;
[0021] The mobile APP sends the user information and encrypted USB disk information to the cloud server and sends an authentication request to the cloud at the same time; the user information and encrypted USB disk information include user ID, encrypted USB disk UUID, signature assertion, dynamic HMAC and timestamp.
[0022] After the cloud server performs multiple verifications in step S3, it generates a cloud dynamic key and sends it to the mobile app, which specifically includes the following steps:
[0023] The cloud server performs multiple verifications, including verification of user identity authenticity, verification of the legitimacy of the encrypted USB drive, and verification of the validity of access rights.
[0024] After the cloud server performs multiple verifications and passes the verification, it generates a cloud dynamic key based on the synchronous dynamic key change mechanism, packages the cloud dynamic key into an authorization token, and sends it to the mobile APP.
[0025] The user identity authenticity verification specifically includes verifying the signature legitimacy and validity period of the signature assertion based on WebAuthn, the signature assertion, and the user ID, and ensuring that the mobile app initiating the request has passed biometric identification;
[0026] The encrypted USB drive legitimacy verification specifically includes verifying whether the UUID and dynamic HMAC broadcast by the encrypted USB drive match the cloud registration record, and checking the device certificate chain and online status to prevent forgery or replay attacks;
[0027] The access permission validity verification specifically includes determining the user's access level to the encrypted USB flash drive based on the binding relationship between the user ID and the UUID of the encrypted USB flash drive in the cloud permission policy library.
[0028] The mobile APP in step S4 sends the received data information to the encrypted USB drive, which specifically includes the following steps:
[0029] The mobile APP encrypts the received data information using a temporary session key and sends it to the encrypted USB flash drive via BLE; the data information includes an authorization token.
[0030] The encrypted USB flash drive in step S5 generates a USB flash drive dynamic key, verifies it with the received cloud dynamic key, and decrypts its own data based on the verification result, specifically including the following steps:
[0031] The encrypted USB drive decrypts the received data information and verifies the legitimacy of the received authorization token and the validity of the timestamp;
[0032] If the verification is successful, the encrypted USB drive generates a dynamic key based on the synchronous dynamic key change mechanism; the dynamic key of the USB drive is matched with the dynamic key in the cloud for verification: If the verification is successful, the encrypted USB drive uses the dynamic key of the USB drive to decrypt the master key stored in the encryption chip, unlock the data partition, and complete the decryption of its own data;
[0033] After decryption, the encrypted USB flash drive is converted into a standard USB storage device; at the same time, the encrypted USB flash drive will upload the unlocked status to the mobile APP, and the mobile APP will synchronously notify the cloud server to complete the update of the dynamic key.
[0034] The synchronous dynamic key change mechanism specifically includes the following steps:
[0035] The cloud server uses the following formula to generate the cloud dynamic key:
[0036]
[0037] The encrypted USB flash drive uses the following formula to generate the dynamic key for the USB flash drive:
[0038]
[0039] In the formula The generated cloud dynamic key; is the cloud dynamic key generated in the previous round; || is serial splicing; HMAC() is the HMAC-SHA256 algorithm used to generate the cloud dynamic key; UUID is the unique identification ID of the USB flash drive; User_ID is the user ID; is the cloud initial key, is the initial key for the encrypted USB drive, and
[0040] The present invention also provides a system for implementing the U disk dynamic encryption method based on cloud-edge collaboration, comprising a U disk identification module, an information sending module, a multiple verification module, an information return module and a decryption module; the U disk identification module, the information sending module, the multiple verification module, the information return module and the decryption module are connected in series in sequence; the U disk identification module is used to enable the mobile terminal APP to establish a connection with the encrypted U disk when the encrypted U disk is inserted into the computer host, and to identify the encrypted U disk and upload the data information to the information sending module; the information sending module is used to enable the mobile terminal APP to perform user identity authentication according to the received data information, and to transmit the user information and the encrypted U disk to the computer host. The disk information is sent to the cloud server, and the data information is uploaded to the multiple verification module; the multiple verification module is used to enable the cloud server to perform multiple verifications based on the received data information, generate a cloud dynamic key and send it to the mobile APP, and upload the data information to the information return module; the information return module is used to enable the mobile APP to send the received data information to the encrypted U disk based on the received data information, and upload the data information to the decryption module; the decryption module is used to enable the encrypted U disk to generate a U disk dynamic key based on the received data information, verify it with the received cloud dynamic key, and decrypt its own data according to the verification result.
[0041] The U disk dynamic encryption method and system based on cloud-edge collaboration provided by the present invention not only realizes the U disk dynamic encryption based on cloud-edge collaboration through multiple data interactions and multiple verifications between the encrypted U disk, mobile APP and cloud server, but also has higher reliability and better security. BRIEF DESCRIPTION OF THE DRAWINGS
[0042] Figure 1 Schematic diagram of the process of the present invention.
[0043] Figure 2 Schematic diagram of the functional modules of the system of the present invention. DETAILED DESCRIPTION
[0044] like Figure 1 The figure shows a flow chart of the method of the present invention: The method for dynamic encryption of a USB flash drive based on cloud-edge collaboration disclosed by the present invention comprises the following steps:
[0045] S1. When the encrypted USB drive is inserted into the computer host, the mobile app (such as a mobile phone app, a mobile PAD app, etc.) establishes a connection with the encrypted USB drive and identifies the encrypted USB drive. The specific steps include the following:
[0046] When the encrypted USB drive is inserted into the computer host, the encrypted USB drive activates its own Bluetooth;
[0047] The encrypted USB drive starts BLE broadcasting; the broadcast content includes the device UUID, a dynamic HMAC generated based on the timestamp and serial number, and the service identifier;
[0048] The mobile app scans the BLE broadcast, confirms that the encrypted USB drive is legitimate, and then initiates a BLE connection request to the encrypted USB drive;
[0049] The mobile app establishes a connection with the encrypted USB drive;
[0050] The mobile app reads the public key of the encrypted USB drive and generates a temporary session key through ECDH negotiation with the encrypted USB drive;
[0051] S2. The mobile app authenticates the user and sends the user information and encrypted USB flash drive information to the cloud server. This includes the following steps:
[0052] The mobile app calls the WebAuthn interface on the mobile side to perform biometric authentication on the mobile user;
[0053] After the user passes the biometric authentication, the mobile app generates a signature assertion; the signature assertion includes the user ID, timestamp and random factor;
[0054] The mobile app sends the user information and encrypted USB disk information to the cloud server, and sends an authentication request to the cloud at the same time; the user information and encrypted USB disk information include user ID, encrypted USB disk UUID, signature assertion, dynamic HMAC and timestamp;
[0055] S3. After the cloud server performs multiple verifications, it generates a cloud-based dynamic key and sends it to the mobile app. This includes the following steps:
[0056] The cloud server performs multiple verifications, including verification of user identity authenticity, verification of the legitimacy of the encrypted USB drive, and verification of the validity of access rights.
[0057] After the cloud server performs multiple verifications and passes the verification, it generates a cloud dynamic key based on the synchronous dynamic key change mechanism, packages the cloud dynamic key into an authorization token, and sends it to the mobile app;
[0058] When implementing:
[0059] The user identity authenticity verification specifically includes verifying the signature legitimacy and validity period of the signature assertion based on WebAuthn, the signature assertion, and the user ID, and ensuring that the mobile app initiating the request has passed biometric identification;
[0060] The encrypted USB drive legitimacy verification specifically includes verifying whether the UUID and dynamic HMAC broadcast by the encrypted USB drive match the cloud registration record, and checking the device certificate chain and online status to prevent forgery or replay attacks;
[0061] The access rights validity verification specifically includes determining the user's access level to the encrypted USB flash drive (including read-only / read-write, validity period, number of times limit, etc.) based on the binding relationship between the user ID and the encrypted USB flash drive's UUID in the cloud permission policy library;
[0062] S4. The mobile app sends the received data to the encrypted USB drive. This includes the following steps:
[0063] The mobile app encrypts the received data information using a temporary session key and sends it to the encrypted USB drive via BLE; the data information includes an authorization token;
[0064] S5. The encrypted USB drive generates a dynamic key for the USB drive, verifies it with the received dynamic key from the cloud, and decrypts its own data based on the verification result. This specifically includes the following steps:
[0065] The encrypted USB drive decrypts the received data information and verifies the legitimacy of the received authorization token and the validity of the timestamp;
[0066] If the verification is successful, the encrypted USB drive generates a dynamic key based on the synchronous dynamic key change mechanism; the dynamic key of the USB drive is matched with the dynamic key in the cloud for verification: If the verification is successful, the encrypted USB drive uses the dynamic key of the USB drive to decrypt the master key stored in the encryption chip, unlock the data partition, and complete the decryption of its own data;
[0067] After decryption, the encrypted USB flash drive is converted into a standard USB storage device; at the same time, the encrypted USB flash drive will upload the unlocked status to the mobile APP, and the mobile APP will synchronously notify the cloud server to complete the update of the dynamic key.
[0068] In specific implementation, the synchronous dynamic key change mechanism includes the following steps:
[0069] The cloud server uses the following formula to generate the cloud dynamic key:
[0070]
[0071] The encrypted USB flash drive uses the following formula to generate the dynamic key for the USB flash drive:
[0072]
[0073] In the formula The generated cloud dynamic key; is the cloud dynamic key generated in the previous round; || is serial splicing; HMAC() is the HMAC-SHA256 algorithm used to generate the cloud dynamic key; UUID is the unique identification ID of the USB flash drive; User_ID is the user ID; is the cloud initial key, is the initial key for the encrypted USB drive, and This synchronous dynamic change mechanism can ensure the forward security, non-replayability and identity binding of dynamic keys; in addition, after the USB flash drive is successfully decrypted, the cloud server and the encrypted USB flash drive automatically synchronize and update the dynamic key for the next round of unlocking the encrypted USB flash drive; the "identity-bound hash chain" is used for the dynamic key evolution of the encrypted USB flash drive device to achieve secure key synchronization without continuous online status.
[0074] The above steps may also include the following exception handling mechanisms, including automatic restoration of the encrypted USB flash drive status when there is no operation for a timeout or it is physically unplugged, switching to emergency transmission channels such as NFC or USB-HID when BLE communication fails, enabling PIN code authentication multiple times when mobile APP biometric authentication fails, physical tampering of the USB flash drive, triggering a data destruction mechanism, etc.
[0075] The solution of the present invention not only overcomes the limitations of traditional USB flash drive encryption such as reliance on static passwords, local authentication, and extensive permissions, but also provides a set of cloud-edge collaboration, dynamic keys, secure and reliable intelligent encrypted USB flash drive system solutions with significant advantages in security, flexibility, and manageability.
[0076] like Figure 2The figure shows a schematic diagram of the functional modules of the system of the present invention: the system disclosed by the present invention for realizing the said cloud-edge collaboration-based U disk dynamic encryption method comprises a U disk identification module, an information sending module, a multiple verification module, an information return module and a decryption module; the U disk identification module, the information sending module, the multiple verification module, the information return module and the decryption module are connected in series in sequence; the U disk identification module is used to establish a connection between the mobile terminal APP and the encrypted U disk when the encrypted U disk is inserted into the computer host, and to identify the encrypted U disk and upload the data information to the information sending module; the information sending module is used to enable the mobile terminal APP to perform user identity authentication according to the received data information, and to User information and encrypted U disk information are sent to the cloud server, and the data information is uploaded to the multiple verification module; the multiple verification module is used to enable the cloud server to perform multiple verifications based on the received data information, generate a cloud dynamic key and send it to the mobile APP, and upload the data information to the information return module; the information return module is used to enable the mobile APP to send the received data information to the encrypted U disk based on the received data information, and upload the data information to the decryption module; the decryption module is used to enable the encrypted U disk to generate a U disk dynamic key based on the received data information, verify it with the received cloud dynamic key, and decrypt its own data based on the verification result.
Claims
1. A USB flash drive dynamic encryption method based on cloud-edge collaboration, comprising the following steps: S1. When the encrypted USB drive is inserted into the computer host, the mobile app establishes a connection with the encrypted USB drive and identifies the encrypted USB drive; S2. The mobile app authenticates the user and sends the user information and encrypted USB flash drive information to the cloud server. S3. After the cloud server performs multiple verifications, it generates a cloud-based dynamic key and sends it to the mobile app. S4. The mobile app sends the received data to the encrypted USB drive; S5. The encrypted USB drive generates a dynamic key for the USB drive, verifies it with the received dynamic key from the cloud, and decrypts its own data based on the verification result.
2. The U disk dynamic encryption method based on cloud-edge collaboration according to claim 1 is characterized in that When the encrypted USB flash drive is inserted into the computer host, the mobile APP establishes a connection with the encrypted USB flash drive and identifies the encrypted USB flash drive, specifically including the following steps: When the encrypted USB drive is inserted into the computer host, the encrypted USB drive activates its own Bluetooth; The encrypted USB drive starts BLE broadcasting; the broadcast content includes the device UUID, a dynamic HMAC generated based on the timestamp and serial number, and the service identifier; The mobile app scans the BLE broadcast, confirms that the encrypted USB drive is legitimate, and then initiates a BLE connection request to the encrypted USB drive; The mobile app establishes a connection with the encrypted USB drive; The mobile app reads the public key of the encrypted USB drive and generates a temporary session key through ECDH negotiation with the encrypted USB drive.
3. The U disk dynamic encryption method based on cloud-edge collaboration according to claim 2 is characterized in that The mobile APP in step S2 performs user identity authentication and sends the user information and encrypted USB disk information to the cloud server, which specifically includes the following steps: The mobile app calls the WebAuthn interface on the mobile side to perform biometric authentication on the mobile user; After the user passes the biometric authentication, the mobile app generates a signature assertion; the signature assertion includes the user ID, timestamp and random factor; The mobile APP sends the user information and encrypted USB disk information to the cloud server and sends an authentication request to the cloud at the same time; the user information and encrypted USB disk information include user ID, encrypted USB disk UUID, signature assertion, dynamic HMAC and timestamp.
4. The U disk dynamic encryption method based on cloud-edge collaboration according to claim 3 is characterized in that After the cloud server performs multiple verifications in step S3, it generates a cloud dynamic key and sends it to the mobile app, which specifically includes the following steps: The cloud server performs multiple verifications, including verification of user identity authenticity, verification of the legitimacy of the encrypted USB drive, and verification of the validity of access rights. After the cloud server performs multiple verifications and passes the verification, it generates a cloud dynamic key based on the synchronous dynamic key change mechanism, packages the cloud dynamic key into an authorization token, and sends it to the mobile APP.
5. The U disk dynamic encryption method based on cloud-edge collaboration according to claim 4 is characterized in that The user identity authenticity verification specifically includes verifying the signature legitimacy and validity period of the signature assertion based on WebAuthn, the signature assertion, and the user ID, and ensuring that the mobile app initiating the request has passed biometric identification; The encrypted USB drive legitimacy verification specifically includes verifying whether the UUID and dynamic HMAC broadcast by the encrypted USB drive match the cloud registration record, and checking the device certificate chain and online status to prevent forgery or replay attacks; The access permission validity verification specifically includes determining the user's access level to the encrypted USB flash drive based on the binding relationship between the user ID and the UUID of the encrypted USB flash drive in the cloud permission policy library.
6. The method for dynamic encryption of USB flash drives based on cloud-edge collaboration according to claim 5 is characterized in that The mobile APP in step S4 sends the received data information to the encrypted USB drive, which specifically includes the following steps: The mobile APP encrypts the received data information using a temporary session key and sends it to the encrypted USB flash drive via BLE; the data information includes an authorization token.
7. The method for dynamic encryption of USB flash drives based on cloud-edge collaboration according to claim 6 is characterized in that The encrypted USB flash drive in step S5 generates a USB flash drive dynamic key, verifies it with the received cloud dynamic key, and decrypts its own data based on the verification result, specifically including the following steps: The encrypted USB drive decrypts the received data information and verifies the legitimacy of the received authorization token and the validity of the timestamp; If the verification is successful, the encrypted USB drive generates a dynamic key based on the synchronous dynamic key change mechanism; the dynamic key of the USB drive is matched with the dynamic key in the cloud for verification: If the verification is successful, the encrypted USB drive uses the dynamic key of the USB drive to decrypt the master key stored in the encryption chip, unlock the data partition, and complete the decryption of its own data; After decryption, the encrypted USB flash drive is converted into a standard USB storage device; at the same time, the encrypted USB flash drive will upload the unlocked status to the mobile APP, and the mobile APP will synchronously notify the cloud server to complete the update of the dynamic key.
8. The method for dynamic encryption of USB flash drives based on cloud-edge collaboration according to claim 7 is characterized in that The synchronous dynamic key change mechanism specifically includes the following steps: The cloud server uses the following formula to generate the cloud dynamic key: The encrypted USB flash drive uses the following formula to generate the dynamic key for the USB flash drive: In the formula The generated cloud dynamic key; is the cloud dynamic key generated in the previous round; || is serial splicing; HMAC() is the HMAC-SHA256 algorithm used to generate the cloud dynamic key; UUID is the unique identification ID of the USB flash drive; User_ID is the user ID; is the cloud initial key, is the initial key for the encrypted USB drive, and 9. A system for implementing the U disk dynamic encryption method based on cloud-edge collaboration as described in any one of claims 1 to 8, characterized in that It includes a U disk identification module, an information sending module, a multiple verification module, an information return module and a decryption module; the U disk identification module, the information sending module, the multiple verification module, the information return module and the decryption module are connected in series in sequence; the U disk identification module is used to establish a connection between the mobile terminal APP and the encrypted U disk when the encrypted U disk is inserted into the computer host, identify the encrypted U disk, and upload the data information to the information sending module; the information sending module is used to enable the mobile terminal APP to perform user identity authentication based on the received data information, and send the user information and the encrypted U disk information to the cloud server, and upload the data information to the multiple verification module; The multi-verification module is used to generate a cloud dynamic key based on the received data information after the cloud server performs multiple verifications and sends it to the mobile APP, and uploads the data information to the information return module; the information return module is used to enable the mobile APP to send the received data information to the encrypted USB flash drive based on the received data information, and upload the data information to the decryption module; The decryption module is used to generate a dynamic key for the encrypted USB flash drive based on the received data information, verify it with the received cloud dynamic key, and decrypt its own data based on the verification result.