A method and system for realizing U disk device interaction based on flash encryption technology

By using dynamic entropy weights and adaptive key generation sequences based on flash memory encryption technology, the risk of key leakage in USB flash drive device interaction is solved, thereby improving the security and reliability of USB flash drive device interaction and enhancing the protection against side-channel attacks.

CN120974552BActive Publication Date: 2026-06-02SHENZHEN LINGCHUANG IND CO LTD

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
SHENZHEN LINGCHUANG IND CO LTD
Filing Date
2025-08-04
Publication Date
2026-06-02

Smart Images

  • Figure CN120974552B_ABST
    Figure CN120974552B_ABST
Patent Text Reader

Abstract

The application relates to the core technical field and discloses a U disk device interaction method and system based on flash memory encryption technology, which comprises the following steps: dividing an encryptable data block of a flash memory controller, determining a dynamic entropy weight value of the encryptable data block by using a device interaction instruction and a random noise characteristic signal; generating an adaptive key generation sequence of the encryptable data block through an address allocation mode of the flash memory controller and the dynamic entropy weight value; calculating a side channel leakage risk index of the flash memory controller, setting a security level label of the encryptable data block in combination with the adaptive key generation sequence; setting a differentiated security protection mechanism of the encryptable data block by constructing an access control matrix of the encryptable data block and an encryption risk area of the flash memory controller; and generating a security interaction scheme of the U disk device based on the adaptive key generation sequence, in combination with the differentiated security protection mechanism and the access control matrix. The application can improve the security and reliability of U disk device interaction.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to a method and system for realizing USB flash drive device interaction based on flash memory encryption technology, which belongs to the core technology field. Background Technology

[0002] USB flash drive device interaction refers to the process of data transfer, information reading, and command response between a USB flash drive and devices such as computers and mobile terminals through the USB interface protocol and data transfer specifications. This enables operations such as file copying, system identification, and permission verification between the USB flash drive and the device. With the surge in data sharing demands in the digital age, USB flash drives, as portable storage media, are widely used in personal, enterprise, and government scenarios. However, the security protection of privacy data, trade secrets, and sensitive information involved in USB flash drive interaction places extremely high demands on the confidentiality and integrity of data. Therefore, strengthening the application of encryption technology in USB flash drive device interaction has become an important measure to ensure data interaction security.

[0003] Traditional USB flash drive device interaction relies on static encryption and fixed access control policies to achieve connection and data transfer between the USB flash drive and the interactive device. Although this method can meet basic storage and data exchange needs, it relies solely on pre-configured encryption keys, which can easily lead to the continuous accumulation of key leakage risks, affecting the security and reliability of the entire USB flash drive device interaction system. Summary of the Invention

[0004] This invention provides a method and system for USB flash drive device interaction based on flash memory encryption technology, the main purpose of which is to improve the security and reliability of USB flash drive device interaction.

[0005] To achieve the above objectives, the present invention provides a method for USB flash drive device interaction based on flash memory encryption technology, comprising:

[0006] Obtain the flash memory controller of the USB flash drive device, its physical address mapping information, and logical address request sequence; based on the physical address mapping information, divide the flash memory controller into encryptable data blocks.

[0007] Extract the device interaction commands of the USB flash drive and the random noise characteristic signals of the flash memory controller, and determine the dynamic entropy weight of the encryptable data block based on the device interaction commands and the random noise characteristic signals;

[0008] Based on the logical address request sequence, the address allocation mode of the flash memory controller is identified, and an adaptive key generation sequence for the encryptable data block is generated by combining the address allocation mode and the dynamic entropy weight.

[0009] Calculate the side-channel leakage risk index of the flash memory controller, set the security level label of the encryptable data block based on the adaptive key generation sequence and the side-channel leakage risk index, and establish the access control matrix of the encryptable data block based on the security level label.

[0010] Based on the side-channel leakage risk index, the encryption risk area of ​​the flash memory controller is located, and based on the access control matrix and the encryption risk area, a differentiated security protection mechanism for the encryptable data block is set.

[0011] Based on the adaptive key generation sequence, combined with the differentiated security protection mechanism and the access control matrix, a secure interaction scheme for the USB flash drive device is generated.

[0012] Optionally, the step of dividing the encryptable data blocks of the flash memory controller based on the physical address mapping information includes:

[0013] Parse the logical block address and physical block address from the physical address mapping information;

[0014] The topology model of the flash memory controller is reconstructed by the conversion mapping relationship between the logical block address and the physical block address;

[0015] Identify the physical units in the topology model and extract the storage characteristic parameters of the physical units;

[0016] The encryption adaptation threshold of the physical unit is defined by using the read / write count, data retention period and read interference coefficient in the storage characteristic parameters.

[0017] The encrypted data blocks of the flash controller are divided according to the encryption adaptation threshold.

[0018] Optionally, determining the dynamic entropy weight of the encryptable data block based on the device interaction command and the random noise characteristic signal includes:

[0019] Identify the timing feature code and protocol interaction fingerprint corresponding to the device interaction command;

[0020] The noise fluctuation amplitude and random bit stream density of the random noise feature signal are extracted;

[0021] Calculate the correlation strength coefficient and timing synchronization deviation value between the device interaction command and the random noise characteristic signal;

[0022] Based on the time sequence feature code and the noise fluctuation amplitude, establish the key entropy pool matrix of the encryptable data block;

[0023] Based on the protocol interaction fingerprint and the random bit stream density, the entropy iteration degree of the key entropy pool matrix is ​​determined;

[0024] The correction coefficient of the key entropy pool matrix is ​​defined based on the correlation strength coefficient and the timing synchronization deviation value.

[0025] The dynamic entropy weight of the encryptable data block is determined by combining the key entropy pool matrix, the entropy iteration degree, and the correction coefficient.

[0026] Optionally, identifying the address allocation mode of the flash controller based on the logical address request sequence includes:

[0027] Collect the logical block address values ​​and their corresponding timestamps from the logical address request sequence;

[0028] Perform timing alignment processing between the logical block address value and the timestamp to obtain the timing alignment result;

[0029] Based on the timing alignment results, a three-dimensional scatter plot of the logical address request sequence is constructed;

[0030] Extract the address contiguous segment features from the three-dimensional scatter plot and quantify the spatiotemporal features of the three-dimensional scatter plot;

[0031] The address allocation mode of the flash memory controller is identified based on the address contiguous segment characteristics and the spatiotemporal characteristics.

[0032] Optionally, the step of combining the address allocation mode and the dynamic entropy weight to generate the adaptive key generation sequence for the encryptable data block includes:

[0033] Extract the address mapping feature parameters from the address allocation mode, and determine the multi-level key derivation domain corresponding to the address mapping feature parameters;

[0034] Based on the distribution characteristics of the dynamic entropy weights, select the key derivation algorithm type corresponding to the multi-level key derivation domain;

[0035] The derivation path offset of the multi-level key derivation domain is calculated using the fluctuation range of the dynamic entropy weight.

[0036] By combining the key derivation algorithm type and the derivation path offset, a key derivation sequence for the encryptable data block is generated;

[0037] Perform topological sorting of the key derivation sequence and output a dynamic key derivation table.

[0038] Optionally, setting the security level label of the encryptable data block based on the adaptive key generation sequence and the side-channel leakage risk index includes:

[0039] Extract the path depth, cryptographic operation sequence, and entropy source type from the adaptive key generation sequence;

[0040] The security baseline level of the encryptable data block is determined based on the path depth, the sequence of cryptographic operations, and the type of entropy source.

[0041] Based on the side-channel leakage risk index, the label level of the encryptable data block is defined, and the level dynamic adjustment threshold of the security baseline level is set.

[0042] The security level label of the encryptable data block is set according to the label level, the security baseline level and its level dynamically adjusted threshold.

[0043] Optionally, establishing the access control matrix for the encryptable data block based on the security level label includes:

[0044] Identify the access subject of the encrypted data block;

[0045] Divide the permission level ranges corresponding to the security level labels;

[0046] Based on the aforementioned permission level range, the encryption strength parameter of the encryptable data block is defined;

[0047] Based on the encryption strength parameter, construct a tuple mapping table between the permission level range and the access subject;

[0048] Define the assignment rules for matrix elements in the tuple mapping table;

[0049] Configure the distributed matrix monitor corresponding to the matrix element according to the assignment rules;

[0050] The distributed matrix monitor can be used to monitor permission conflict events of matrix elements in real time during the assignment process.

[0051] Based on the aforementioned permission conflict event, a hierarchical arbitration mechanism is set for the matrix elements;

[0052] By combining the tuple mapping table, the distributed matrix monitor, and the hierarchical arbitration mechanism, an access control matrix for the encryptable data blocks is established.

[0053] Optionally, locating the encryption risk area of ​​the flash memory controller based on the side-channel leakage risk index includes:

[0054] Collect side-channel historical attack data of the flash memory controller;

[0055] Based on the historical attack data of the side channel, a security threshold corresponding to the side channel leakage risk index is set;

[0056] Based on the security threshold, identify the potential cryptographic attack surface of the flash memory controller;

[0057] Extract the side-channel feature vector corresponding to the potential encryption attack surface;

[0058] Based on the side-channel feature vector, calculate the risk leakage strength of the potential encryption attack surface;

[0059] Construct a thermal distribution map corresponding to the intensity of the risk leakage;

[0060] The encryption risk areas of the flash memory controller can be located using the heat map.

[0061] Optionally, the differentiated security protection mechanism for the encryptable data block, based on the access control matrix and the encryption risk zone, includes:

[0062] Identify the authorized subjects under the access control matrix and determine the risk level classification criteria for the encrypted risk zone;

[0063] Based on the risk level classification criteria, the risk attribution areas of the encryptable data blocks are determined.

[0064] Establish the association between the authorized entity and the risk attribution region;

[0065] Based on the access control matrix, an access permission determination baseline is established among the permission subjects;

[0066] Based on the access permission determination baseline and the association relationship, a dual security access system is constructed, consisting of the risk attribution area and the permission subject.

[0067] Collect access records of the risk-attributed area and operation feedback information corresponding to the permission subject to form a secure access data set for the encryptable data block;

[0068] Based on the aforementioned dual-security access system, the encryption risk feature points of the secure access data set are extracted;

[0069] Based on the encryption risk feature points, a temporary encryption protection instruction is generated for the encryptable data block;

[0070] By combining the temporary encryption protection command and the dual security access system, a differentiated security protection mechanism is set up for the encryptable data block.

[0071] To address the aforementioned problems, the present invention also provides a USB flash drive device interaction system based on flash memory encryption technology, the system comprising:

[0072] The storage analysis module is used to obtain the flash memory controller of the USB flash drive device and its physical address mapping information and logical address request sequence, and to divide the encrypted data blocks of the flash memory controller based on the physical address mapping information;

[0073] The entropy weight calculation module is used to extract the device interaction instructions of the USB flash drive and the random noise characteristic signal of the flash memory controller, and determine the dynamic entropy weight value of the encryptable data block based on the device interaction instructions and the random noise characteristic signal.

[0074] The key derivation module is used to identify the address allocation mode of the flash controller based on the logical address request sequence, and generate an adaptive key generation sequence for the encryptable data block by combining the address allocation mode and the dynamic entropy weight.

[0075] The security risk assessment module is used to calculate the side-channel leakage risk index of the flash memory controller, set the security level label of the encryptable data block based on the adaptive key generation sequence and the side-channel leakage risk index, and establish the access control matrix of the encryptable data block based on the security level label.

[0076] The differentiated protection module is used to locate the encryption risk area of ​​the flash memory controller based on the side channel leakage risk index, and set a differentiated security protection mechanism for the encryptable data block based on the access control matrix and the encryption risk area.

[0077] The secure interaction execution module is used to generate a secure interaction scheme for the USB flash drive device based on the adaptive key generation sequence, combined with the differentiated security protection mechanism and the access control matrix.

[0078] Compared to the problems described in the background art, the embodiments of the present invention, by dividing the encryptable data blocks of the flash memory controller based on the physical address mapping information, allow encryption operations to accurately anchor to the physical units of the actual stored data in the flash memory controller, avoiding encryption overlay omissions or redundancy caused by mapping offsets between logical addresses and physical addresses. Furthermore, by determining the dynamic entropy weight of the encryptable data blocks based on the device interaction instructions and the random noise characteristic signal, the embodiments of the present invention can achieve deep binding between the key derivation process and the real-time state of the device, improving the dynamism and anti-predictability of the key. Finally, by identifying the address allocation pattern of the flash memory controller based on the logical address request sequence, the embodiments of the present invention can uncover different read / write... The underlying logic of address mapping under the operation improves the precise control over the division of the encrypted flash memory area. Furthermore, by combining the address allocation mode and the dynamic entropy weight, this embodiment of the invention generates an adaptive key generation sequence for the encryptable data block, ensuring that the key derivation path accurately matches the storage characteristics and security requirements of the data block, reducing the performance loss of the USB flash drive due to excessive encryption. This embodiment of the invention also improves the accuracy of the flash memory controller's protection against side-channel attacks and the efficiency of security early warning by calculating the side-channel leakage risk index of the flash memory controller. Simultaneously, it ensures that the protection strategy accurately matches the side-channel leakage characteristics and key derivation process, reducing the redundant performance loss of the controller due to excessive protection. Furthermore, this embodiment of the invention… For example, by setting a security level label for the encryptable data block based on the adaptive key generation sequence and the side-channel leakage risk index, it is possible to ensure that security protection measures are accurately matched with the key derivation characteristics and side-channel leakage risk of the data block, reducing the impact of excessive encryption on device interaction performance. Furthermore, by establishing an access control matrix for the encryptable data block based on the security level label, the permission management logic of flash encryption technology can be transformed into a structured access rule system, providing a clear control framework for data encryption and permission allocation during the interaction process of USB flash drive devices, improving the isolation and protection capabilities and access efficiency of data with different security levels. Further, by adjusting the side-channel leakage risk... The index, which locates the encryption risk area of ​​the flash memory controller, can transform abstract side-channel security threats into specific risk location identifiers, providing a clear target area for optimizing the encryption protection of the flash memory controller, thereby enhancing the data protection capabilities of USB flash drive devices based on flash memory encryption technology. This embodiment of the invention, by setting a differentiated security protection mechanism for the encryptable data blocks based on the access control matrix and the encryption risk area, can integrate a structured permission management framework with precise risk location information into a dynamically adaptable protection strategy system. This provides targeted measures for the security protection of encryptable data blocks under different access scenarios, improving the intensity of key protection for high-risk data areas and the flexibility of access to low-risk data areas.Finally, this embodiment of the invention generates a secure interaction scheme for the USB flash drive device by combining the adaptive key generation sequence, the differentiated security protection mechanism, and the access control matrix. This avoids the continuous accumulation of key leakage risks under static encryption, improves the overall security of the USB flash drive device interaction system, and effectively enhances the resistance to specific risks such as side-channel attacks. It also strengthens the protection accuracy of data blocks with different security levels, optimizes the synergistic adaptability of dynamic keys and access permissions, and ensures the reliability and adaptability of the USB flash drive device during data transmission and storage. Therefore, the USB flash drive device interaction method and system based on flash memory encryption technology provided by this embodiment of the invention can improve the security and reliability of USB flash drive device interaction. Attached Figure Description

[0079] Figure 1 This is a flowchart illustrating a method for implementing USB flash drive device interaction based on flash memory encryption technology, provided in an embodiment of the present invention.

[0080] Figure 2 This is a flowchart of the encryption wheel operation of a method for realizing USB flash drive device interaction based on flash memory encryption technology, provided in an embodiment of the present invention;

[0081] Figure 3 This is a functional module diagram illustrating an embodiment of the present invention for implementing a USB flash drive device interaction system based on flash memory encryption technology.

[0082] The objectives, features, and advantages of this invention will be further explained in conjunction with the embodiments and with reference to the accompanying drawings. Detailed Implementation

[0083] It should be understood that the specific embodiments described herein are merely illustrative of the invention and are not intended to limit the invention.

[0084] This application provides a method for interacting with a USB flash drive based on flash memory encryption technology. The executing entity of this method includes, but is not limited to, at least one electronic device that can be configured to execute the method provided in this application, such as a server or a terminal. In other words, this method can be executed by software or hardware installed on a terminal device or a server device. The server includes, but is not limited to, a single server, a server cluster, a cloud server, or a cloud server cluster.

[0085] Reference Figure 1 The diagram shown is a flowchart illustrating a method for implementing USB flash drive device interaction based on flash memory encryption technology according to an embodiment of the present invention. In this embodiment, the method for implementing USB flash drive device interaction based on flash memory encryption technology includes:

[0086] S1. Obtain the flash memory controller of the USB flash drive device and its physical address mapping information and logical address request sequence. Based on the physical address mapping information, divide the encryptable data blocks of the flash memory controller.

[0087] This invention, by acquiring the flash memory controller of a USB flash drive and its physical address mapping information and logical address request sequence, can track the storage and retrieval trajectory of data in the flash memory controller in real time, thereby improving data security and response efficiency in USB flash drive device interactions from the source. The USB flash drive device refers to a portable storage device that uses a flash memory controller as a storage medium and interacts with devices such as computers via a USB interface. The flash memory controller is a core control chip integrated inside the USB flash drive, responsible for coordinating data transmission between the flash memory controller and external devices, managing flash memory storage space (such as erase and write operations), and performing error verification and correction. The physical address mapping information refers to data used to record the correspondence between the logical address of the USB flash drive (i.e., the address seen by the user during operation) and the actual physical storage unit address of the flash memory controller. The logical address request sequence refers to an ordered set of access requests (such as read and write requests) issued by the user or external device to the logical address during data interaction with the USB flash drive, arranged chronologically.

[0088] Furthermore, by dividing the flash memory controller into encryptable data blocks based on the physical address mapping information, the embodiments of the present invention can accurately anchor the encryption operation to the physical unit in the flash memory controller that actually stores the data, avoiding encryption overlay omissions or redundancies caused by the mapping offset between logical addresses and physical addresses. The encryptable data block refers to an independent data storage unit that the flash memory controller can perform encryption operations on, which is divided based on the physical address mapping information.

[0089] As an embodiment of the present invention, the step of dividing the encryptable data blocks of the flash memory controller based on the physical address mapping information includes:

[0090] Parse the logical block address and physical block address from the physical address mapping information;

[0091] The topology model of the flash memory controller is reconstructed by the conversion mapping relationship between the logical block address and the physical block address;

[0092] Identify the physical units in the topology model and extract the storage characteristic parameters of the physical units;

[0093] The encryption adaptation threshold of the physical unit is defined by using the read / write count, data retention period and read interference coefficient in the storage characteristic parameters.

[0094] Divide the encryptable data blocks of the flash memory controller according to the encryption adaptation threshold.

[0095] Among them, the logical block address refers to the virtual address used to identify the data storage location when the user or external device interacts with the USB flash drive. The physical block address refers to the unique identification address of the physical storage block (composed of multiple storage units) where the data is actually stored in the flash memory controller. The conversion mapping relationship refers to the rule or data used to establish the corresponding association between the logical block address and the physical block address. It can implement the conversion from the logical block address to the physical block address and the reverse mapping from the physical block address to the logical block address, ensuring that the system can accurately find the physical block address where the data is located according to the logical block address. The topology structure model refers to the model that describes the connection relationship, distribution and hierarchical structure between the physical blocks in the flash memory controller in an abstract and structured way. The physical unit refers to the basic hardware unit that constitutes the storage structure of the flash memory controller, which can refer to a single storage block (composed of multiple storage units) or a smaller storage particle. The storage characteristic parameters refer to the parameter set that can reflect the inherent properties and performance indicators shown by the physical unit during the storage and interaction processes. The read / write cycle count refers to the cumulative number of data write and read operations performed on the physical unit from the time it is put into use at the factory until the current moment. The data retention period refers to the longest time that the physical unit can keep the data from being lost and can be correctly read without any refresh or rewrite operations after the data is written into the physical unit. The read interference coefficient refers to the quantitative index of the degree of interference caused by the read operation on a certain physical unit to the data stored in other adjacent or associated physical units, resulting in a decrease in data stability. The higher the coefficient value, the greater the impact of the interference on data stability. The encryption adaptation threshold refers to the critical value set according to the storage characteristic parameters of the physical unit. The encryption adaptation threshold can be the maximum tolerance value of the read / write cycle count, the minimum requirement value of the data retention period, the maximum allowable value of the read interference coefficient, etc. For example, if the number of erase / write cycles of a certain physical unit ≤ 80% of the manufacturer's rated maximum value; the data retention period ≥ 2 times the key update period; the read interference coefficient < 50% of the ECC error correction threshold, this physical unit can be divided into encryptable data blocks.

[0096] Optionally, the conversion mapping relationship between the logical block address and the physical block address can be determined by reading the address mapping table of the flash memory controller. The topology structure model of the flash memory controller can be reconstructed by a storage simulation tool. The specific steps are as follows: obtain the physical architecture parameters through the ID instruction of the flash memory controller; based on the physical architecture parameters, use a flash memory dedicated simulation tool to simulate the mapping rule between the logical address and the physical address; combine the physical architecture parameters and the address mapping rule to generate a topology model including the unit hierarchical relationship and dynamic state.

[0097] S2. Extract the device interaction command of the USB flash drive and the random noise characteristic signal of the flash memory controller, and determine the dynamic entropy weight of the encryptable data block based on the device interaction command and the random noise characteristic signal.

[0098] This invention, by extracting the device interaction commands of the USB flash drive and the random noise characteristic signal of the flash memory controller, enables the corresponding noise entropy source to be invoked as needed to generate encryption parameters for different interaction scenarios, thereby improving the adaptability of the encryption mechanism to the device interaction process. The device interaction commands refer to the set of commands sent and received by both parties during the interaction between the USB flash drive and external devices, such as data transmission, status query, and function configuration. These commands include, but are not limited to, data read / write commands, device identification commands, and encryption mode switching commands, and can be extracted using a USB protocol analyzer. The random noise characteristic signal refers to the unpredictable random signal generated by the flash memory controller during operation due to the physical characteristics of the hardware itself (such as electron thermal motion, microscopic differences in semiconductor materials, etc.). The random noise characteristic signal can be extracted using an adaptive sampling strategy (such as a sampling rate of 1MHz in high-security scenarios and reduced to 100kHz in ordinary scenarios), and the sampling accuracy can be dynamically adjusted according to a preset security level label to balance security and efficiency.

[0099] Furthermore, by determining the dynamic entropy weight of the encryptable data block based on the device interaction command and the random noise feature signal, this embodiment of the invention can achieve a deep binding between the key derivation process and the real-time state of the device, thereby improving the dynamics and anti-predictability of the key. The dynamic entropy weight is a composite index combining cryptography and information entropy, generated based on the device interaction command and the random noise feature signal, used to quantify the randomness quality of the encryptable data block.

[0100] As an embodiment of the present invention, determining the dynamic entropy weight of the encryptable data block based on the device interaction command and the random noise characteristic signal includes:

[0101] Identify the timing feature code and protocol interaction fingerprint corresponding to the device interaction command;

[0102] Extract the noise fluctuation amplitude and random bit stream density corresponding to the random noise feature signal;

[0103] Calculate the correlation strength coefficient and timing synchronization deviation value between the device interaction command and the random noise characteristic signal;

[0104] Based on the time sequence feature code and the noise fluctuation amplitude, establish the key entropy pool matrix of the encryptable data block;

[0105] Based on the protocol interaction fingerprint and the random bit stream density, the entropy iteration degree of the key entropy pool matrix is ​​determined;

[0106] The correction coefficient of the key entropy pool matrix is ​​defined based on the correlation strength coefficient and the timing synchronization deviation value.

[0107] The dynamic entropy weight of the encryptable data block is determined by combining the key entropy pool matrix, the entropy iteration degree, and the correction coefficient.

[0108] The time-series feature code refers to the encoding obtained by extracting features from the time sequence of command interactions during device interaction. Specifically, after extracting the periodic features of device interaction commands using a sliding window fast Fourier transform (SW-FFT), the periodicity of the commands in the time dimension (such as command sending intervals, repetition cycles, etc.) is transformed into a 256-bit fixed-length feature code. The protocol interaction fingerprint refers to a 128-bit feature value generated by using the SM3 cryptographic hash algorithm to perform digest calculation on protocol interaction messages between devices (such as data frames and control packets in USB communication). For example, in the protocol communication between a USB flash drive and a host, the interaction fingerprint is used to generate a digest of the message. The message content transmitted during the process (including instruction type, parameters, verification information, etc.) is used as input. After hashing using the SM3 algorithm, a 128-bit result that uniquely identifies the protocol interaction mode and content characteristics can be obtained. This is the protocol interaction fingerprint. The noise fluctuation amplitude refers to the amplitude variation range of the random noise characteristic signal during the operation of the flash memory controller. Specifically, a 12-bit ADC (analog-to-digital converter) can be used to collect the random noise characteristic signal at a sampling rate of 1MHz. The amplitude variation range is obtained by calculating the difference between the maximum and minimum values ​​of the signal within a 100μs time window. The random bit stream density refers to the binary random number extracted from the random noise characteristic signal. The information density of the machine sequence, i.e., the number of effective random bits generated per unit time, is usually expressed as bit rate (bit / s). The correlation strength coefficient is a metric used to quantify the statistical correlation between device interaction commands and random noise characteristic signals. It is obtained by calculating the joint probability distribution entropy of the two, and its value ranges from [0,1]. The closer the coefficient is to 1, the higher the degree of linear or nonlinear correlation between the two. The timing synchronization deviation value refers to the time offset between the timing characteristics of the device interaction commands and the sampling timing of the random noise characteristic signals. For example, a timestamp is recorded when the command is sent, and another timestamp is recorded when the noise is sampled. The difference between the two can be verified by IEEE... The output after 1588 protocol calibration is a key entropy pool matrix, which is a multi-dimensional matrix structure constructed by feature fusion of timing feature codes and noise fluctuation amplitude. The matrix can be filled with different features in each dimension. For example, the first dimension is filled with 64-bit segments of the timing feature codes; the second dimension is filled with the quantized value of the noise fluctuation amplitude; and the third dimension is encrypted using the SM4 algorithm to encrypt the XOR result of the first two dimensions. The entropy iteration degree refers to the quantization parameter that controls the iterative update process of the key entropy pool matrix. The correction coefficient is a quantization parameter generated by a specific cryptographic algorithm based on the association strength coefficient and the timing synchronization deviation value, used to dynamically adjust the statistical characteristics of the key entropy pool matrix.

[0109] Optionally, the entropy iteration degree of the key entropy pool matrix can be determined by the SM3 algorithm, the correction coefficient of the key entropy pool matrix based on the association strength coefficient and the timing synchronization deviation value can be defined using the key stretching algorithm, and the dynamic entropy weight of the encryptable data block can be determined by the lightweight entropy evaluation model.

[0110] S3. Based on the logical address request sequence, identify the address allocation mode of the flash memory controller, and combine the address allocation mode and the dynamic entropy weight to generate an adaptive key generation sequence for the encryptable data block.

[0111] This invention identifies the address allocation mode of the flash memory controller based on the logical address request sequence, thereby uncovering the inherent logic of address mapping under different read and write operations and improving the ability to accurately control the division of the flash memory encryption area. The address allocation mode refers to the management strategy of the flash memory controller in mapping logical addresses to physical storage units when processing logical address requests issued by the host.

[0112] As an embodiment of the present invention, identifying the address allocation mode of the flash controller based on the logical address request sequence includes:

[0113] Collect the logical block address values ​​and their corresponding timestamps from the logical address request sequence;

[0114] Perform timing alignment processing between the logical block address value and the timestamp to obtain the timing alignment result;

[0115] Based on the timing alignment results, a three-dimensional scatter plot of the logical address request sequence is constructed;

[0116] Extract the address contiguous segment features from the three-dimensional scatter plot and quantify the spatiotemporal features of the three-dimensional scatter plot;

[0117] The address allocation mode of the flash memory controller is identified based on the address contiguous segment characteristics and the spatiotemporal characteristics.

[0118] The logical block address value refers to the numerical number used to identify data blocks in the storage device within the logical address request sequence. For example, in a 16GB USB flash drive, the logical block address value may start from 0 and increment sequentially in a fixed size (e.g., 512 bytes / block). The starting logical block address value of a file might be 1000, with subsequent data blocks being 1001, 1002, and so on. The timestamp refers to the time stamp that records the moment the logical block address request occurs, typically expressed with a certain time precision (e.g., milliseconds or microseconds). The timing alignment result refers to a timing alignment method using hardware clock source synchronization, which normalizes the logical block address value and its corresponding timestamp according to a unified time base. The resulting three-dimensional scatter plot refers to a visualization chart constructed with time series as the X-axis, logical address as the Y-axis, and access frequency as the Z-axis. The address continuum feature refers to the characteristics of regions with continuous logical addresses and coherent access times in the three-dimensional scatter plot, including the start address, end address, length, and access frequency distribution within the continuum. The spatiotemporal feature refers to the characteristics presented by combining the three dimensions of time, logical address, and access frequency in the three-dimensional scatter plot, including the temporal distribution pattern of address access (such as access concentrated in a certain time period), the spatial distribution pattern of logical addresses (such as access concentrated in a certain address range), and the trend of access frequency changes with time and address.

[0119] Optionally, the address contiguous segment features in the three-dimensional scatter plot can be extracted using a sliding window algorithm, the spatiotemporal features in the three-dimensional scatter plot can be quantized using a dynamic time warping (DTW) algorithm, and the address allocation pattern of the flash memory controller can be identified using an LSTM classification model based on the address contiguous segment features and the spatiotemporal features.

[0120] Furthermore, by combining the address allocation mode and the dynamic entropy weight, the embodiments of the present invention generate an adaptive key generation sequence for the encryptable data block, which can ensure that the key derivation path is accurately matched with the storage characteristics and security requirements of the data block, and reduce the performance loss of the USB flash drive due to excessive encryption. The adaptive key generation sequence refers to a key management structure based on the address allocation mode and the dynamic entropy weight, which is used to dynamically generate encryption keys for different data blocks in the flash memory controller.

[0121] As an embodiment of the present invention, the step of generating the adaptive key generation sequence for the encryptable data block by combining the address allocation mode and the dynamic entropy weight includes:

[0122] Extract the address mapping feature parameters from the address allocation mode, and determine the multi-level key derivation domain corresponding to the address mapping feature parameters;

[0123] Based on the distribution characteristics of the dynamic entropy weights, select the key derivation algorithm type corresponding to the multi-level key derivation domain;

[0124] The derivation path offset of the multi-level key derivation domain is calculated using the fluctuation range of the dynamic entropy weight.

[0125] By combining the key derivation algorithm type and the derivation path offset, a key derivation sequence for the encryptable data block is generated;

[0126] Perform topological sorting of the key derivation sequence and output a dynamic key derivation table.

[0127] The address mapping feature parameters refer to a set of quantitative indicators extracted from the address allocation pattern to characterize the mapping relationship between logical addresses and physical addresses, including but not limited to logical address continuity, physical address dispersion coefficient, address jump frequency, and mapping stability index. The multi-level key derivation domain refers to a hierarchical logical region used to carry out the key derivation process, divided according to flash memory storage granularity (block, page, partition) and security level, including block-level derivation domains, page-level derivation domains, and partition-level derivation domains. The distribution characteristics refer to the statistical properties of dynamic entropy weights in the time or spatial dimensions, including numerical distribution (histogram distribution of entropy weights) and spatial correlation (entropy between different derivation domains). The covariance matrix of the weights), time stability (variance of entropy weights within the sliding window), and the key derivation algorithm type refer to the encryption algorithm or derivation function dynamically selected based on the entropy weights, including block encryption algorithms (such as AES-256, suitable for batch data encryption in block-level derivation domains), stream encryption algorithms (such as ChaCha20, suitable for real-time data encryption in page-level derivation domains), and hybrid encryption algorithms (such as a combination of AES and SM4, suitable for high-security scenarios in partition-level derivation domains). The fluctuation range refers to the range or standard deviation of the entropy weights within the derivation domain, and the derivation path offset refers to the adjustment amount of the key derivation path caused by fluctuations, calculated using the following formula: , The domain weight coefficient is represented by the key derivation sequence, which is an ordered set of key derivation operations generated according to the derivation domain level and algorithm type. For example, block-level domain: HKDF → page-level domain: ChaCha20 → partition-level domain: PBKDF2. The topology sorting process refers to the process of sorting the sequence acyclically according to the derivation domain dependency relationship (such as the partition key depending on the block key).

[0128] Optionally, the multi-level key derivation domain corresponding to the address mapping feature parameters can be determined by the K-Means clustering algorithm, and the key derivation algorithm type of the encryptable data block can be selected by a lookup table method.

[0129] For example, when the USB flash drive is first inserted into a Windows host, the device interaction command extracts the bcdUSB field (e.g., 2.1.0) of the USB descriptor as the protocol interaction fingerprint, superimposes the thermal noise of the flash controller (fluctuation amplitude = 0.3mV / μs), generates an entropy weight W = 0.82, and derives the key K1 = HKDF(W∥LBA). When the same USB flash drive is inserted into a Linux host, due to the difference in protocol fingerprint (bcdUSB = 3.0.0) and noise changes (fluctuation amplitude = 0.5mV / μs), a new entropy weight W' = 0.76 will be regenerated, and a completely different key K2 will be derived.

[0130] To clearly explain the generation logic of the adaptive key generation sequence for encryptable data blocks, please refer to [reference needed]. Figure 2 The diagram shows a flowchart of the encryption round operation of a USB flash drive device interaction method based on flash memory encryption technology, as provided in an embodiment of the present invention. The symmetric encryption multi-round transformation process shown in the diagram (such as round key addition, S-box nonlinear substitution, etc.) fully presents the encryption paradigm of "plaintext-key iteration processing-ciphertext". The cooperative logic of the round operation (the confusion characteristics implemented by S-box nonlinear substitution, the diffusion mechanism constructed by shift operation, and the key embedding path formed by round key addition) constitutes the underlying cryptographic support for the design of the derived algorithm of the present invention. Specifically, when the derived algorithm needs to implement the "nonlinear confusion" function, the bidirectional mapping logic of the S-box can be directly used to construct the feature perturbation model; when the "path mutation" mechanism needs to be implemented, the jump algorithm of the derived path can be designed with reference to the dynamic offset rule of row shift. This technical anchoring with mature encryption mechanisms not only provides a clear cryptographic theoretical basis for the "selection of derived algorithm type", but also significantly improves the security and reliability of the dynamic key derivation mechanism of the present invention by inheriting the security genes of classic encryption schemes.

[0131] S4. Calculate the side-channel leakage risk index of the flash memory controller, set the security level label of the encryptable data block based on the adaptive key generation sequence and the side-channel leakage risk index, and establish the access control matrix of the encryptable data block based on the security level label.

[0132] This invention, through calculating the side-channel leakage risk index of the flash memory controller, can dynamically adjust the security level label of encryptable data blocks, thereby improving the accuracy of the flash memory controller's protection against side-channel attacks and the efficiency of security early warning. For example, when abnormal power consumption fluctuations are detected (risk index > 70), the system will automatically upgrade the encryption algorithm of high-risk data blocks from AES-128 to AES-256 and add a noise mask. The side-channel leakage risk index is a quantitative indicator that comprehensively evaluates the risk level of unintentional leakage of sensitive information (such as encryption keys and operation data) by the flash memory controller during operation due to physical characteristics (such as power consumption, electromagnetic radiation, timing, etc.). It includes high risk (side-channel leakage risk index > 70), medium risk (0 < side-channel leakage risk index I ≤ 70), and low risk (side-channel leakage risk index ≤ 30).

[0133] As an embodiment of the present invention, the side-channel leakage risk index of the flash memory controller is calculated as follows:

[0134]

[0135] in, This represents the side-channel leakage risk index of the flash memory controller, where n represents the total number of sampling operations and e represents the index of the number of sampling operations. This represents the instantaneous power consumption of the flash memory controller during the e-th sampling, in mW. The reference power consumption corresponding to the instantaneous power consumption at the e-th sampling time is expressed in mW. This represents the execution time of the e-th sample by the flash memory controller, in ns. This indicates the historical average operating time of the flash memory controller, in ns. This indicates the historical maximum operating time of the flash memory controller, in ns. This indicates the historical minimum operating time of the flash memory controller, in ns. Indicates the sensitivity coefficient to time-series anomalies. This indicates the electromagnetic radiation intensity of the flash memory controller, measured in μV. This indicates the electromagnetic safety threshold of the flash memory controller, in μV.

[0136] It should be explained that in this application, the formula Used to quantify the relative deviation of the current power consumption from a reference value. For example, if the power consumption increases from 100mW to 150mW during encryption, the deviation ratio = 0.5. Used to calculate the operating time volatility of the flash memory controller. Used to quantify the electromagnetic leakage level of the flash memory controller, wherein the instantaneous power consumption The maximum dynamic power consumption of the power pin during encryption operation is obtained by sampling the product of voltage and current using an oscilloscope. The electromagnetic radiation intensity... The electromagnetic safety threshold is the root mean square value of the radiated field strength in the 30MHz-1GHz frequency band, measured by a near-field probe and a spectrum analyzer. Radiation limits are set according to FIPS 140-3 and dynamically calibrated according to ambient noise.

[0137] For example, suppose the power consumption of the flash memory controller is: =150mW, =100mW; Timing: =52ns, =50ns, =30ns; Electromagnetic: =80μV, =50μV; Parameters: α=0.4, n=1, substituting into the formula yields I The risk index was 72.3 (high risk), indicating that electromagnetic shielding needs to be optimized or power consumption noise needs to be increased.

[0138] Furthermore, by setting a security level label for the encryptable data block based on the adaptive key generation sequence and the side-channel leakage risk index, this embodiment of the invention can ensure that security protection measures are accurately matched with the key derivation characteristics and side-channel leakage risk of the data block, thereby reducing the impact of excessive encryption on device interaction performance. The security level label refers to a structured identifier assigned to each encryptable data block based on the dynamic key derivation characteristics and side-channel leakage risk index of the encryptable data block, used to identify its security protection requirement level.

[0139] As an embodiment of the present invention, setting the security level label of the encryptable data block based on the adaptive key generation sequence and the side-channel leakage risk index includes:

[0140] Extract the path depth, cryptographic operation sequence, and entropy source type from the adaptive key generation sequence;

[0141] The security baseline level of the encryptable data block is determined based on the path depth, the sequence of cryptographic operations, and the type of entropy source.

[0142] Based on the side-channel leakage risk index, the label level of the encryptable data block is defined, and the level dynamic adjustment threshold of the security baseline level is set.

[0143] The security level label of the encryptable data block is set according to the label level, the security baseline level and its level dynamically adjusted threshold.

[0144] The path depth refers to the number of derivation steps traversed from the master key to the session key of the encryptable data block in the adaptive key generation sequence, reflecting the complexity of the key generation path. For example, the path depth of master key → subkey A → subkey B → session key is 3; the path depth of master key → session key is 1. The cryptographic operation sequence refers to the ordered set of cryptographic algorithms and operation steps executed during the dynamic key derivation process, such as sequences like "SHA-256 hash → AES-256 encryption → HMAC verification" and "SM3 hash → SM4 encryption". The entropy source type refers to the source type that provides randomness for key derivation, including hardware noise sources (such as circuit thermal noise), software pseudo-random number generators, and physically unclonable functions (PUFs). The security baseline level refers to the security protection baseline level of the encryptable data block determined based on the path depth, cryptographic operation sequence, and entropy source type, and is usually divided into four levels: A, B, C, and D (A being the highest). For example, a path depth ≥ 3, containing a PUF entropy source, and with an operation sequence containing more than two encryption operations, has a security baseline level of A; a path depth = 1, using software pseudo-random numbers, and only a single hash operation, has a security baseline level of C. The label level refers to a sub-level classification of the security baseline level based on the side-channel leakage risk index, including a recommended protection measures field to quantify subtle differences in security levels. For example, security baseline level A can be further subdivided into A+, A, and A-. A+ corresponds to "side-channel leakage risk index ≤ 30," and the recommended protection measures field is "enable basic electromagnetic shielding"; A corresponds to "30 < wind...". For "Risk Index ≤ 70", the recommended protection measures are "enhanced electromagnetic shielding + power consumption mitigation"; for "A-", which corresponds to "70 < Risk Index ≤ 90", the recommended protection measures are "full-coverage electromagnetic shielding + dynamic power consumption adjustment". The recommended protection measures field is included. The dynamic adjustment threshold refers to the critical value of the side-channel leakage risk index that triggers the upgrade or downgrade of the security baseline level. It is used to dynamically adjust the level based on real-time risk. For example, when the side-channel leakage risk index > 70, the security baseline level is downgraded by one sub-level (e.g., A → A-); when the side-channel leakage risk index > 90, the security baseline level is downgraded by two sub-levels (e.g., A → B).

[0145] Optionally, the dynamic adjustment threshold for the security baseline level can be set using an adaptive threshold optimization algorithm.

[0146] This invention establishes an access control matrix for the encryptable data blocks based on the security level labels. This transforms the permission management logic of flash encryption technology into a structured access rule system, providing a clear control framework for data encryption and permission allocation during the interaction process of USB flash drives. This improves the isolation and protection capabilities and access efficiency of data with different security levels. The access control matrix is ​​a structured tool for standardizing access permissions for encryptable data blocks. It is based on security level labels and uses different access subjects (such as users, processes, etc.) and encryptable data blocks as rows and columns of the matrix. The elements in the matrix specify the access permissions (such as read, write, modify, delete, etc.) of the corresponding subject to the corresponding data block.

[0147] As an embodiment of the present invention, establishing the access control matrix for the encryptable data block based on the security level label includes:

[0148] Identify the access subject of the encrypted data block;

[0149] Divide the permission level ranges corresponding to the security level labels;

[0150] Based on the aforementioned permission level range, the encryption strength parameter of the encryptable data block is defined;

[0151] Based on the encryption strength parameter, construct a tuple mapping table between the permission level range and the access subject;

[0152] Define the assignment rules for matrix elements in the tuple mapping table;

[0153] Configure the distributed matrix monitor corresponding to the matrix element according to the assignment rules;

[0154] The distributed matrix monitor can be used to monitor permission conflict events of matrix elements in real time during the assignment process.

[0155] Based on the aforementioned permission conflict event, a hierarchical arbitration mechanism is set for the matrix elements;

[0156] By combining the tuple mapping table, the distributed matrix monitor, and the hierarchical arbitration mechanism, an access control matrix for the encryptable data blocks is established.

[0157] The access subject refers to an entity capable of initiating an access request to an encryptable data block, including but not limited to user accounts, running processes, and connected terminal devices. The permission level range refers to a continuous or discrete range defined by security level labels to delineate different permission scopes. The encryption strength parameter refers to an indicator parameter used to quantify the encryption protection capability of the encryptable data block; its value can be determined based on the permission level range and typically includes encryption algorithm complexity, key length, and number of encryption iterations. The tuple mapping table refers to a data structure that stores the correspondence between permission level ranges and access subjects in tuple form, such as a six-tuple mapping table. The fields of the tuple mapping table include a subject identifier (used to uniquely identify the access subject), a data block fingerprint (a unique feature code of the encryptable data block), and a permission level (corresponding to the security level label). The access control matrix includes the following parameters: access level, effective time (the time range within which permissions are valid), geofence (the physical location range within which access operations are permitted), and authorization credentials (proof of access to the access subject). Each matrix element is a specific value at the intersection of a row (access subject) and column (encryptable data block) in the access control matrix, used to define the access permission type for a specific access subject to a specific encrypted data block. The assignment rules are specifications used to determine the specific values ​​of matrix elements, based on field information in the tuple mapping table (such as permission level, effective time, etc.). The distributed matrix monitor is a system component deployed in a distributed environment for real-time monitoring of the assignment and use of access control matrix elements, including time-series monitoring, spatial monitoring, and logical monitoring. Time-series monitoring uses an LSTM anomaly detection model (F1-score ≥ 0).98) By learning from historical time-series data, abnormal behaviors that do not conform to normal time patterns are identified during the assignment of matrix elements; spatial monitoring is based on Voronoi-Delaunay dual-grid partitioning to perform boundary monitoring of matrix element operations in different physical or logical spaces; logical monitoring is verified through CTL (Computation Tree Logic) formulas to ensure that the assignment of matrix elements and the execution of permissions conform to preset logical rules. The permission conflict event refers to the occurrence of events that violate preset permission rules during the assignment or access of matrix elements, such as the access subject's permissions not matching the security level of the encryptable data block, or the same data block being assigned contradictory permissions. The aforementioned layered arbitration mechanism refers to a multi-level processing system for handling permission conflict events. It achieves efficient conflict resolution through tiered responses, comprising a three-level conflict handling pipeline. At the hardware level, SGXEnclave (Software Protection Extended Enclave) performs rapid adjudication, leveraging hardware isolation to ensure the security of the adjudication process with a latency of <10ms. At the system level, the Byzantine Paxos algorithm is applied, enabling consensus adjudication even in the presence of malicious nodes, with a fault tolerance of ≥1 / 3. At the human level, NLP (Natural Language Processing)-based work order classification automatically categorizes conflict events and generates work orders, with final adjudication by a human.

[0158] Optionally, the permission level intervals corresponding to the security level labels can be divided using a fuzzy C-means clustering algorithm, and the assignment rules for matrix elements in the tuple mapping table can be formulated using a genetic algorithm, such as a decision tree algorithm.

[0159] S5. Based on the side-channel leakage risk index, locate the encryption risk area of ​​the flash memory controller, and set a differentiated security protection mechanism for the encryptable data block based on the access control matrix and the encryption risk area.

[0160] This invention, by locating the encryption risk area of ​​the flash memory controller based on the side-channel leakage risk index, can transform the abstract side-channel security threat into a specific risk location identifier, providing a clear target area for optimizing the encryption protection of the flash memory controller, thereby enhancing the data protection capability of USB flash drive devices based on flash memory encryption technology. The encryption risk area refers to a specific physical or logical area in the flash memory controller that is determined to have a high encryption security risk because the side-channel leakage risk index exceeds a preset security threshold.

[0161] As an embodiment of the present invention, locating the encryption risk area of ​​the flash memory controller based on the side-channel leakage risk index includes:

[0162] Collect side-channel historical attack data of the flash memory controller;

[0163] Based on the historical attack data of the side channel, a security threshold corresponding to the side channel leakage risk index is set;

[0164] Based on the security threshold, identify the potential cryptographic attack surface of the flash memory controller;

[0165] Extract the side-channel feature vector corresponding to the potential encryption attack surface;

[0166] Based on the side-channel feature vector, calculate the risk leakage strength of the potential encryption attack surface;

[0167] Construct a thermal distribution map corresponding to the intensity of the risk leakage;

[0168] The encryption risk areas of the flash memory controller can be located using the heat map.

[0169] The side-channel historical attack data refers to a set of relevant information recorded regarding side-channel attack events that occurred against the flash memory controller within a past period, including the time of the attack, the type of side-channel used, the specific means of the attack, the impact of the attack, and the success or failure of the attack. The security threshold is a critical value or range defined for the side-channel leakage risk index based on the side-channel historical attack data. When the side-channel leakage risk index exceeds the critical value or is outside the critical range, it indicates that the flash memory controller has a high encryption risk and requires close attention and handling. When the side-channel leakage risk index is below the critical value or is within the critical range, it indicates that the encryption status of the flash memory controller is relatively secure. The potential encryption attack surface refers to weak points or potential entry points in the flash memory controller that may be exploited by side-channel attacks. These can be specific circuit modules, signal transmission paths, data processing units, etc., identified through sensitive signal annotation and logic simulation using Hardware Description Language (HDL). The side-channel feature vector refers to the vector extracted from the potential encryption attack surface. A set of numerical values ​​or parameters characterizing the side-channel information leakage features of the attack surface, including the peak value of the power consumption change curve, the intensity distribution of electromagnetic radiation, and the timing differences in data processing, etc. The risk leakage intensity refers to a quantitative indicator used to measure the severity of the potential encryption attack surface side-channel information leakage. The heat map refers to a chart that graphically displays the distribution of the risk leakage intensity of the potential encryption attack surface. Based on the physical structure or logical architecture of the flash memory controller, a two-dimensional or three-dimensional coordinate system is established. The calculated risk leakage intensity values ​​of each potential encryption attack surface are discretized and mapped according to their spatial coordinates to form an initial discrete data point set. The Kriging interpolation method is used to perform spatial interpolation operations on the discrete data point set to generate a continuous risk leakage intensity spatial distribution field. According to the numerical range of the risk leakage intensity, multiple risk level intervals are divided, and a corresponding color gradient is assigned to each interval to generate a heat map. In this map, different colors or hues are usually used to represent the magnitude of the risk leakage intensity. The darker the color or the more vivid the hue, the higher the risk leakage intensity of the area, that is, the more likely it is an encryption risk area.

[0170] Optionally, the risk leakage strength of the potential cryptographic attack surface can be calculated using the Mahalanobis distance formula, and the side-channel feature vector corresponding to the potential cryptographic attack surface can be extracted using the deep differential power analysis method.

[0171] Furthermore, this embodiment of the invention, by setting a differentiated security protection mechanism for the encryptable data block based on the access control matrix and the encrypted risk zone, can integrate a structured permission management framework with precise risk location information into a dynamically adaptable protection strategy system. This provides targeted measures for the security protection of encryptable data blocks under different access scenarios, improving the intensity of key protection for high-risk data and the flexibility of access to low-risk data. The differentiated security protection mechanism refers to a dynamic protection system that configures security protection strategies based on the access permission characteristics of the encryptable data block and its encrypted risk environment. This includes hardware-level protection, logic-level protection, and protocol-level protection. The hardware-level protection mandates PUF (Physically Unclonable Function) authentication, requiring three challenge-response verifications for each access, and integrates an electromagnetic shielding layer to suppress radiation field strength to a minimum. Below 0.3, The electromagnetic safety threshold is primarily for high-risk areas. The logic-level protection employs a zero-knowledge proof verifier, transmitting only hash digests (≥256 bits) during the verification process, and enables a dynamic privilege decay mechanism, such as automatically downgrading privileges to read-only after 30 consecutive minutes of inactivity, primarily for medium-risk areas. The protocol protection is mainly based on the USB-IF specification's anti-replay attack mechanism, attaching a monotonically increasing 32-bit counter to each data packet and using a lightweight encryption algorithm (such as XTEA), rotating the key once per hour, suitable for low-risk areas.

[0172] As an embodiment of the present invention, the step of setting a differentiated security protection mechanism for the encryptable data block based on the access control matrix and the encryption risk zone includes:

[0173] Identify the authorized subjects under the access control matrix and determine the risk level classification criteria for the encrypted risk zone;

[0174] Based on the risk level classification criteria, the risk attribution areas of the encryptable data blocks are determined.

[0175] Establish the association between the authorized entity and the risk attribution region;

[0176] Based on the access control matrix, an access permission determination baseline is established among the permission subjects;

[0177] Based on the access permission determination baseline and the association relationship, a dual security access system is constructed, consisting of the risk attribution area and the permission subject.

[0178] Collect access records of the risk-attributed area and operation feedback information corresponding to the permission subject to form a secure access data set for the encryptable data block;

[0179] Based on the aforementioned dual-security access system, the encryption risk feature points of the secure access data set are extracted;

[0180] Based on the encryption risk feature points, a temporary encryption protection instruction is generated for the encryptable data block;

[0181] By combining the temporary encryption protection command and the dual security access system, a differentiated security protection mechanism is set up for the encryptable data block.

[0182] The term "authorized entity" refers to an entity with the permission to access encryptable data blocks, including user accounts, applications, and hardware devices. The risk level classification standard refers to the criteria for dividing encrypted risk areas into high, medium, and low levels based on factors such as data sensitivity, the scope of leakage impact, and the probability of attack. For example, a high-risk level corresponds to a data block storage area involving core trade secrets or sensitive personal information. The risk attribution area refers to the specific encrypted risk area to which the encryptable data block belongs, determined according to the risk level classification standard. The association relationship refers to the correspondence between authorized entities and risk attribution areas, clarifying which authorized entities can access encryptable data blocks within which risk attribution areas, and the access operations... The access permission determination baseline, based on the access control matrix, is a baseline for access permissions set between authorized subjects. It specifies the minimum permission standards and boundaries that different authorized subjects should follow when accessing encryptable data blocks. The dual-security access system is a security system built by combining the access permission determination baseline and the association between authorized subjects and risk attribution areas. It includes three levels: hardware level (PUF physical authentication module, which achieves unique device identity authentication through physical non-cloning characteristics), logic level (zero-knowledge proof verifier, which completes identity and permission verification without disclosing sensitive information), and protocol level (challenge-response mechanism against replay attacks, preventing attackers from reusing intercepted access requests). Access records refer to detailed records of all access behaviors targeting encryptable data blocks within the risk-attributed area, including access subject identification, access duration, data block operation path, etc. Operation feedback information refers to the operation result information returned by the system after the authorized subject performs an access operation on the encryptable data block, as well as any abnormal situations actively reported by the authorized subject during the operation process, such as operation success / failure prompts, insufficient permissions warnings, etc. The secure access data set refers to a data set composed of access records from the risk-attributed area and operation feedback information from the authorized subject, including access timestamps, operation types (such as read, modify, delete, etc.), environmental fingerprints (such as hardware characteristics of the accessing device, network environment parameters, etc.), etc., and the encryption... Risk feature points refer to key information points extracted from the secure access data set based on a dual-security access system that reflect the encryption risks faced by encryptable data blocks. Examples include abnormal access time patterns, operation types that do not match permissions, and discrepancies between environmental fingerprints and historical records. The temporary encryption protection command refers to a command generated based on the extracted encryption risk feature points, used to temporarily strengthen the security protection of encryptable data blocks. The triggering rules for the temporary encryption protection command can be as follows: High-priority command: When "abnormal environmental fingerprint + mismatch between permission subject and risk area" is detected (such as unauthorized device accessing a high-risk area), "forced key rotation + access log upload to the audit server" is immediately triggered. The rotated key must satisfy an entropy value ≥ 0.95; Medium-priority instructions: When an "operation type and permission level conflict" occurs (e.g., a low-privilege subject attempts to modify data in a medium-risk area), trigger "two-factor authentication (e.g., PIN code + hardware token)." If authentication fails, the subject will be frozen for 10 minutes. Low-priority instructions: When an "access timestamp deviates from historical patterns" is detected (e.g., accessing a low-risk area at 3 AM), only a log marker is generated; normal operation is not affected.

[0183] Optionally, the risk attribution region of the encryptable data block can be divided using a clustering algorithm, such as the DBSCAN algorithm. The encryption risk feature points of the secure access data set can be extracted using wavelet transform, and the temporary encryption protection instructions of the encryptable data block can be generated by a security policy engine.

[0184] S6. Based on the adaptive key generation sequence, combined with the differentiated security protection mechanism and the access control matrix, generate a secure interaction scheme for the USB flash drive device.

[0185] This invention, through its embodiments, generates a secure interaction scheme for the USB flash drive device based on the adaptive key generation sequence, combined with the differentiated security protection mechanism and the access control matrix. This avoids the continuous accumulation of key leakage risks under static encryption, improves the overall security of the USB flash drive device's interaction system, and effectively enhances its resistance to specific risks such as side-channel attacks. It also strengthens the protection accuracy of data blocks with different security levels, optimizes the synergistic adaptability of dynamic keys and access permissions, and ensures the reliability and adaptability of the USB flash drive device during data transmission and storage. The secure interaction scheme is constructed based on the adaptive key generation sequence, the differentiated security protection mechanism, and the access control matrix. This comprehensive solution ensures secure connection and data transmission between USB flash drives and interactive devices. For example, when an employee inserts a USB flash drive into their office computer, the secure interaction solution is activated: First, an adaptive key generation sequence generates three sets of dynamic keys for the current session, each corresponding to a data block with a different security level. Then, based on differentiated security protection mechanisms, the corresponding level of encryption protection and auditing mechanisms are enabled for the data blocks accessed by the employee. Simultaneously, referring to the access control matrix, the employee's identity is verified to ensure they meet the permission requirements for accessing the data block. Data transmission is only allowed if the dynamic key matches, the protection mechanism is effective, and the permission verification passes, thus achieving secure interaction between the USB flash drive and the office computer.

[0186] Compared to the problems described in the background art, the embodiments of the present invention, by dividing the encryptable data blocks of the flash memory controller based on the physical address mapping information, allow encryption operations to accurately anchor to the physical units of the actual stored data in the flash memory controller, avoiding encryption overlay omissions or redundancy caused by mapping offsets between logical addresses and physical addresses. Furthermore, by determining the dynamic entropy weight of the encryptable data blocks based on the device interaction instructions and the random noise characteristic signal, the embodiments of the present invention can achieve deep binding between the key derivation process and the real-time state of the device, improving the dynamism and anti-predictability of the key. Finally, by identifying the address allocation pattern of the flash memory controller based on the logical address request sequence, the embodiments of the present invention can uncover different read / write... The underlying logic of address mapping under the operation improves the precise control over the division of the encrypted flash memory area. Furthermore, by combining the address allocation mode and the dynamic entropy weight, this embodiment of the invention generates an adaptive key generation sequence for the encryptable data block, ensuring that the key derivation path accurately matches the storage characteristics and security requirements of the data block, reducing the performance loss of the USB flash drive due to excessive encryption. This embodiment of the invention also improves the accuracy of the flash memory controller's protection against side-channel attacks and the efficiency of security early warning by calculating the side-channel leakage risk index of the flash memory controller. Simultaneously, it ensures that the protection strategy accurately matches the side-channel leakage characteristics and key derivation process, reducing the redundant performance loss of the controller due to excessive protection. Furthermore, this embodiment of the invention… For example, by setting a security level label for the encryptable data block based on the adaptive key generation sequence and the side-channel leakage risk index, it is possible to ensure that security protection measures are accurately matched with the key derivation characteristics and side-channel leakage risk of the data block, reducing the impact of excessive encryption on device interaction performance. Furthermore, by establishing an access control matrix for the encryptable data block based on the security level label, the permission management logic of flash encryption technology can be transformed into a structured access rule system, providing a clear control framework for data encryption and permission allocation during the interaction process of USB flash drive devices, improving the isolation and protection capabilities and access efficiency of data with different security levels. Further, by adjusting the side-channel leakage risk... The index, which locates the encryption risk area of ​​the flash memory controller, can transform abstract side-channel security threats into specific risk location identifiers, providing a clear target area for optimizing the encryption protection of the flash memory controller, thereby enhancing the data protection capabilities of USB flash drive devices based on flash memory encryption technology. This embodiment of the invention, by setting a differentiated security protection mechanism for the encryptable data blocks based on the access control matrix and the encryption risk area, can integrate a structured permission management framework with precise risk location information into a dynamically adaptable protection strategy system. This provides targeted measures for the security protection of encryptable data blocks under different access scenarios, improving the intensity of key protection for high-risk data areas and the flexibility of access to low-risk data areas.Finally, this embodiment of the invention generates a secure interaction scheme for the USB flash drive device by combining the adaptive key generation sequence, the differentiated security protection mechanism, and the access control matrix. This avoids the continuous accumulation of key leakage risks under static encryption, improves the overall security of the USB flash drive device interaction system, and effectively enhances the resistance to specific risks such as side-channel attacks. It also strengthens the protection accuracy of data blocks with different security levels, optimizes the synergistic adaptability of dynamic keys and access permissions, and ensures the reliability and adaptability of the USB flash drive device during data transmission and storage. Therefore, the USB flash drive device interaction method and system based on flash memory encryption technology provided by this embodiment of the invention can improve the security and reliability of USB flash drive device interaction.

[0187] like Figure 3 The diagram shown is a functional block diagram of a USB flash drive device interaction system based on flash memory encryption technology according to the present invention.

[0188] The USB flash drive device interaction system 200 based on flash memory encryption technology described in this invention can be installed in an electronic device. Depending on the functions implemented, the USB flash drive device interaction system based on flash memory encryption technology may include a storage analysis module 201, an entropy weight calculation module 202, a key derivation module 203, a security risk assessment module 204, a differentiated protection module 205, and a secure interaction execution module 206. The modules described in this invention can also be referred to as units, which are a series of computer program segments that can be executed by the processor of an electronic device and can perform a fixed function, stored in the memory of the electronic device.

[0189] In this embodiment of the invention, the functions of each module / unit are as follows:

[0190] The storage analysis module 201 is used to obtain the flash memory controller of the USB flash drive device and its physical address mapping information and logical address request sequence, and to divide the encrypted data blocks of the flash memory controller based on the physical address mapping information.

[0191] The entropy weight calculation module 202 is used to extract the device interaction command of the USB flash drive and the random noise characteristic signal of the flash memory controller, and determine the dynamic entropy weight value of the encryptable data block based on the device interaction command and the random noise characteristic signal.

[0192] The key derivation module 203 is used to identify the address allocation mode of the flash memory controller based on the logical address request sequence, and generate an adaptive key generation sequence for the encryptable data block by combining the address allocation mode and the dynamic entropy weight.

[0193] The security risk assessment module 204 is used to calculate the side channel leakage risk index of the flash memory controller, set the security level label of the encryptable data block based on the adaptive key generation sequence and the side channel leakage risk index, and establish the access control matrix of the encryptable data block based on the security level label.

[0194] The differentiated protection module 205 is used to locate the encryption risk area of ​​the flash memory controller according to the side channel leakage risk index, and set the differentiated security protection mechanism for the encryptable data block based on the access control matrix and the encryption risk area.

[0195] The secure interaction execution module 206 is used to generate a secure interaction scheme for the USB flash drive device based on the adaptive key generation sequence, combined with the differentiated security protection mechanism and the access control matrix.

[0196] In detail, the modules in the USB flash drive device interaction system 200 based on flash memory encryption technology described in this embodiment of the invention employ the same methods as described above during use. Figure 1 The method described above is the same as the one used in the article for realizing USB flash drive device interaction based on flash memory encryption technology, and can produce the same technical effect. It will not be elaborated here.

[0197] It will be apparent to those skilled in the art that the present invention is not limited to the details of the exemplary embodiments described above, and that the present invention can be implemented in other specific forms without departing from the spirit or essential characteristics of the present invention.

[0198] Finally, it should be noted that in the above embodiments, each embodiment can be combined with each other or independent. Deleting any one of them will not affect the technical implementation of other embodiments. The above embodiments are only used to illustrate the technical solutions of the present invention and not to limit it. Although the present invention has been described in detail with reference to preferred embodiments, those skilled in the art should understand that modifications or equivalent substitutions can be made to the technical solutions of the present invention without departing from the spirit and scope of the technical solutions of the present invention.

Claims

1. A method for realizing USB flash drive device interaction based on flash memory encryption technology, characterized in that, The method includes: Obtain the flash memory controller of the USB flash drive device, its physical address mapping information, and logical address request sequence; based on the physical address mapping information, divide the flash memory controller into encryptable data blocks. Extracting the device interaction commands of the USB flash drive and the random noise characteristic signal of the flash memory controller, and determining the dynamic entropy weight of the encryptable data block based on the device interaction commands and the random noise characteristic signal, including: Identify the timing feature code and protocol interaction fingerprint corresponding to the device interaction command; The noise fluctuation amplitude and random bit stream density of the random noise feature signal are extracted; Calculate the correlation strength coefficient and timing synchronization deviation value between the device interaction command and the random noise characteristic signal; Based on the time sequence feature code and the noise fluctuation amplitude, establish the key entropy pool matrix of the encryptable data block; Based on the protocol interaction fingerprint and the random bit stream density, the entropy iteration degree of the key entropy pool matrix is ​​determined; The correction coefficient of the key entropy pool matrix is ​​defined based on the correlation strength coefficient and the timing synchronization deviation value. The dynamic entropy weight of the encryptable data block is determined by combining the key entropy pool matrix, the entropy value iteration degree, and the correction coefficient. Based on the logical address request sequence, the address allocation mode of the flash controller is identified. Combining the address allocation mode and the dynamic entropy weight, an adaptive key generation sequence for the encryptable data block is generated, including: Extract the address mapping feature parameters from the address allocation mode, and determine the multi-level key derivation domain corresponding to the address mapping feature parameters; Based on the distribution characteristics of the dynamic entropy weights, select the key derivation algorithm type corresponding to the multi-level key derivation domain; The derivation path offset of the multi-level key derivation domain is calculated using the fluctuation range of the dynamic entropy weight. By combining the key derivation algorithm type and the derivation path offset, a key derivation sequence for the encryptable data block is generated; Perform topological sorting of the key derivation sequence and output a dynamic key derivation table; Calculate the side-channel leakage risk index of the flash memory controller, set the security level label of the encryptable data block based on the adaptive key generation sequence and the side-channel leakage risk index, and establish the access control matrix of the encryptable data block based on the security level label. Based on the side-channel leakage risk index, the encryption risk area of ​​the flash memory controller is located, and based on the access control matrix and the encryption risk area, a differentiated security protection mechanism for the encryptable data block is set. Based on the adaptive key generation sequence, combined with the differentiated security protection mechanism and the access control matrix, a secure interaction scheme for the USB flash drive device is generated.

2. The method for realizing USB flash drive device interaction based on flash memory encryption technology as described in claim 1, characterized in that, The step of dividing the flash memory controller into encryptable data blocks based on the physical address mapping information includes: Parse the logical block address and physical block address from the physical address mapping information; The topology model of the flash memory controller is reconstructed by the conversion mapping relationship between the logical block address and the physical block address; Identify the physical units in the topology model and extract the storage characteristic parameters of the physical units; The encryption adaptation threshold of the physical unit is defined by using the read / write count, data retention period and read interference coefficient in the storage characteristic parameters. The encrypted data blocks of the flash controller are divided according to the encryption adaptation threshold.

3. The method for realizing USB flash drive device interaction based on flash memory encryption technology as described in claim 1, characterized in that, The step of identifying the address allocation mode of the flash controller based on the logical address request sequence includes: Collect the logical block address values ​​and their corresponding timestamps from the logical address request sequence; Perform timing alignment processing between the logical block address value and the timestamp to obtain the timing alignment result; Based on the timing alignment results, a three-dimensional scatter plot of the logical address request sequence is constructed; Extract the address contiguous segment features from the three-dimensional scatter plot and quantify the spatiotemporal features of the three-dimensional scatter plot; The address allocation mode of the flash memory controller is identified based on the address contiguous segment characteristics and the spatiotemporal characteristics.

4. The method for realizing USB flash drive device interaction based on flash memory encryption technology as described in claim 1, characterized in that, The step of setting the security level label for the encryptable data block based on the adaptive key generation sequence and the side-channel leakage risk index includes: Extract the path depth, cryptographic operation sequence, and entropy source type from the adaptive key generation sequence; The security baseline level of the encryptable data block is determined based on the path depth, the sequence of cryptographic operations, and the type of entropy source. Based on the side-channel leakage risk index, the label level of the encryptable data block is defined, and the level dynamic adjustment threshold of the security baseline level is set. The security level label of the encryptable data block is set according to the label level, the security baseline level and its level dynamically adjusted threshold.

5. The method for realizing USB flash drive device interaction based on flash memory encryption technology as described in claim 1, characterized in that, The step of establishing the access control matrix for the encryptable data block based on the security level label includes: Identify the access subject of the encrypted data block; Divide the permission level ranges corresponding to the security level labels; Based on the aforementioned permission level range, the encryption strength parameter of the encryptable data block is defined; Based on the encryption strength parameter, construct a tuple mapping table between the permission level range and the access subject; Define the assignment rules for matrix elements in the tuple mapping table; Configure the distributed matrix monitor corresponding to the matrix element according to the assignment rules; The distributed matrix monitor can be used to monitor permission conflict events of matrix elements in real time during the assignment process. Based on the aforementioned permission conflict event, a hierarchical arbitration mechanism is set for the matrix elements; By combining the tuple mapping table, the distributed matrix monitor, and the hierarchical arbitration mechanism, an access control matrix for the encryptable data blocks is established.

6. The method for realizing USB flash drive device interaction based on flash memory encryption technology as described in claim 1, characterized in that, The step of locating the encryption risk area of ​​the flash memory controller based on the side-channel leakage risk index includes: Collect side-channel historical attack data of the flash memory controller; Based on the historical attack data of the side channel, a security threshold corresponding to the side channel leakage risk index is set; Based on the security threshold, identify the potential cryptographic attack surface of the flash memory controller; Extract the side-channel feature vector corresponding to the potential encryption attack surface; Based on the side-channel feature vector, calculate the risk leakage strength of the potential encryption attack surface; Construct a thermal distribution map corresponding to the intensity of the risk leakage; The encryption risk areas of the flash memory controller can be located using the heat map.

7. The method for realizing USB flash drive device interaction based on flash memory encryption technology as described in claim 1, characterized in that, The differentiated security protection mechanism for the encryptable data blocks, based on the access control matrix and the encryption risk zone, includes: Identify the authorized subjects under the access control matrix and determine the risk level classification criteria for the encrypted risk zone; Based on the risk level classification criteria, the risk attribution areas of the encryptable data blocks are determined. Establish the association between the authorized entity and the risk attribution region; Based on the access control matrix, an access permission determination baseline is established among the permission subjects; Based on the access permission determination baseline and the association relationship, a dual security access system is constructed, consisting of the risk attribution area and the permission subject. Collect access records of the risk-attributed area and operation feedback information corresponding to the permission subject to form a secure access data set for the encryptable data block; Based on the aforementioned dual-security access system, the encryption risk feature points of the secure access data set are extracted; Based on the encryption risk feature points, a temporary encryption protection instruction is generated for the encryptable data block; By combining the temporary encryption protection command and the dual security access system, a differentiated security protection mechanism is set up for the encryptable data block.

8. A USB flash drive device interaction system based on flash memory encryption technology, characterized in that, The system includes: The storage analysis module is used to obtain the flash memory controller of the USB flash drive device and its physical address mapping information and logical address request sequence, and to divide the encrypted data blocks of the flash memory controller based on the physical address mapping information; An entropy weight calculation module is used to extract the device interaction commands of the USB flash drive and the random noise characteristic signals of the flash memory controller, and determine the dynamic entropy weight value of the encryptable data block based on the device interaction commands and the random noise characteristic signals, including: Identify the timing feature code and protocol interaction fingerprint corresponding to the device interaction command; The noise fluctuation amplitude and random bit stream density of the random noise feature signal are extracted; Calculate the correlation strength coefficient and timing synchronization deviation value between the device interaction command and the random noise characteristic signal; Based on the time sequence feature code and the noise fluctuation amplitude, establish the key entropy pool matrix of the encryptable data block; Based on the protocol interaction fingerprint and the random bit stream density, the entropy iteration degree of the key entropy pool matrix is ​​determined; The correction coefficient of the key entropy pool matrix is ​​defined based on the correlation strength coefficient and the timing synchronization deviation value. The dynamic entropy weight of the encryptable data block is determined by combining the key entropy pool matrix, the entropy value iteration degree, and the correction coefficient. A key derivation module is used to identify the address allocation mode of the flash controller based on the logical address request sequence, and generate an adaptive key generation sequence for the encryptable data block by combining the address allocation mode and the dynamic entropy weight, including: Extract the address mapping feature parameters from the address allocation mode, and determine the multi-level key derivation domain corresponding to the address mapping feature parameters; Based on the distribution characteristics of the dynamic entropy weights, select the key derivation algorithm type corresponding to the multi-level key derivation domain; The derivation path offset of the multi-level key derivation domain is calculated using the fluctuation range of the dynamic entropy weight. By combining the key derivation algorithm type and the derivation path offset, a key derivation sequence for the encryptable data block is generated; Perform topological sorting of the key derivation sequence and output a dynamic key derivation table; The security risk assessment module is used to calculate the side-channel leakage risk index of the flash memory controller, set the security level label of the encryptable data block based on the adaptive key generation sequence and the side-channel leakage risk index, and establish the access control matrix of the encryptable data block based on the security level label. The differentiated protection module is used to locate the encryption risk area of ​​the flash memory controller based on the side channel leakage risk index, and set a differentiated security protection mechanism for the encryptable data block based on the access control matrix and the encryption risk area. The secure interaction execution module is used to generate a secure interaction scheme for the USB flash drive device based on the adaptive key generation sequence, combined with the differentiated security protection mechanism and the access control matrix.