Implementation method of transparent encrypted virtual file system based on hardware key
By using a layered architecture design with a built-in SM4 hardware encryption engine in the USB KEY, secure storage and transparent encryption of the master key are achieved, solving the problems of easy key leakage and poor user experience in existing technologies, and providing high security and convenient file-level access control.
Patent Information
- Application Number
- CN202511111808.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-08
- Publication Date
- 2025-11-21
AI Technical Summary
In existing technologies, traditional encryption schemes suffer from problems such as easy key leakage, poor user experience, rudimentary access control, weak hardware dependence, and insufficient transparency, especially in hardware-assisted encryption schemes and software-transparent encryption schemes.
It adopts a layered architecture design, combining a hardware security layer, a key management layer, an encryption engine layer, and a virtual file system layer. Through the built-in SM4 hardware encryption engine in the USB KEY, it achieves transparent encryption. The master key is permanently stored in the hardware, and file metadata is encrypted and processed by the hardware engine, supporting flexible access control at the file level and seamless encryption and decryption.
It achieves high security of the master key, transparent user experience, supports fine-grained access control, requires no complex middleware, and has good compatibility and convenience.
Smart Images

Figure CN120995479A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application belongs to the technical field of computer security, and particularly relates to a transparent encryption virtual file system implementation method based on a hardware key. BACKGROUND
[0002] With the intensification of data security threats, file system encryption technology has become a key means to protect sensitive data. Traditional encryption schemes require users to actively perform encryption and decryption operations, which is poor in experience. Existing transparent encryption schemes mostly rely on software to manage keys, which has security risks such as key being easily dumped from memory, malicious software attacks, and the possibility of data being cracked by various technical means after the device is lost.
[0003] Current similar technical solutions are mainly divided into software transparent encryption solutions, such as BitLocker, EncFS, and LUKS, but have problems such as limited fine-grained control, insecure key storage, and simple key derivation algorithm. Hardware-assisted encryption solutions, such as file systems based on TPM and smart card file systems, have weaknesses such as weak dynamic key management and the need for complex middleware. As for the FUSE technology, its performance, stability, and functionality are mature, but it lacks deep integration with hardware security modules and national encryption algorithms. These technologies generally have the shortcomings of insufficient key security, complex user experience, coarse access control granularity, weak hardware dependency, and lack of transparency. The fundamental reasons are the limitations of design concepts, defects in key management architecture, low hardware integration, and insufficient technology stack integration.
[0004] Therefore, it is necessary to provide a transparent encryption virtual file system implementation method based on a hardware key to solve the above problems. SUMMARY
[0005] In view of the defects in the prior art, the present application aims to provide a transparent encryption virtual file system implementation method based on a hardware key, which adopts a layered architecture design and realizes safe and efficient transparent encryption through a technical solution combining hardware and software.
[0006] The technical solution of the present application includes a layered architecture of a hardware security layer, a key management layer, an encryption engine layer, a virtual file system layer, and a user application layer, and specifically provides the following core technical solutions: Step S1, hardware key management mechanism, integrating an SM4 hardware encryption engine in a USB KEY; Step S2, implementing a transparent encryption file system based on the FUSE technology; Step S3, the system controls the core information of the encrypted file through the metadata management module to support the transparent encryption function, wherein the encryption identifier is used to clearly distinguish whether the file is encrypted, the encryption parameter contains the 16-byte initialization vector (IV) and encryption mode required for SM4 encryption, and the access control information records the access permission and encryption strategy of the file. These metadata are stored in the special security area in an encrypted form, and the reading and writing thereof are processed by the hardware encryption engine and are attached with integrity check to ensure the safe management of the file in cooperation with the transparent encryption process; Step S4, the system implements a complete USB KEY plug-in control mechanism to ensure data security when the hardware is removed.
[0007] Preferably, in step S1, the SM4 hardware encryption engine integrated in the USB KEY realizes the following sub-steps: Step S1.1, generating and permanently storing the master key in the USB KEY, which never leaves the hardware boundary; Step S1.2, after the user inserts the USB KEY, the PIN code needs to be input for identity authentication, and the key usage permission is activated after successful authentication; Step S1.3, based on the master key and file path information, a file-specific key is derived in the hardware.
[0008] Preferably, in step S2, the transparent encryption file system realizes the following sub-steps: Step S2.1, after the USB KEY is inserted and authenticated, the FUSE virtual file system is automatically created and mounted; Step S2.2, the plaintext data written by the application program is stored to the physical hard disk after SM4 encryption; Step S2.3, when reading, the ciphertext data read from the physical hard disk is returned to the application program after SM4 decryption; Step S2.4, the encryption and decryption process is completely transparent to the user and the application program.
[0009] Preferably, in step S4, the complete USB KEY plug-in control mechanism includes the following sub-steps: Step S4.1, after the system detects that the USB KEY is inserted, the legality of the device is verified and the authentication process is started; Step S4.2, after the system detects that the USB KEY is pulled out, the security cleaning operation is immediately performed; Step S4.2, after the USB KEY is pulled out, the virtual file system is forcibly uninstalled and all file handles are closed.
[0010] As a further scheme of the present application: the key algorithm is realized in two ways: one is to realize SM4 key derivation based on PBKDF2 standard combined with file path information, and the related formula is FileKey = PBKDF2 (MasterKey, FilePath || Salt, IterationCount, KeyLength), wherein MasterKey is the hardware master key in the USB KEY, FilePath is the complete path of the file, Salt is the randomly generated salt value, IterationCount is the iteration count, and KeyLength is the SM4 key length; and the other is to realize file content encryption and decryption by using the SM4-CBC mode, wherein a random IV is generated and block encryption is performed during encryption, IV and cipher text data are read from the physical file during decryption, and SM4-CBC decryption is performed by using the same FileKey and IV, the padding data is removed, and the original plaintext is returned.
[0011] As a further scheme of the present application: the performance is optimized by means of key, metadata and data caching, asynchronous I / O, multi-thread encryption and pipeline processing and the like concurrent processing modes; the memory safety is guaranteed by means of sensitive data zeroization, secure memory allocation and anti-debugging protection; and the integrity protection is realized by means of file integrity verification, metadata digital signature and anti-tamper mechanism.
[0012] Compared with the prior art, the present application has the following advantages: 1. In terms of security, the master key is permanently stored in the USB KEY, and the key operation does not deviate from the hardware boundary, so as to eliminate the risk of leakage; 2. In terms of user experience, the FUSE user space file system and the real-time encryption and decryption engine are used to realize transparent encryption without additional operation; 3. In terms of technical architecture, file-level encryption control and flexible policy configuration are supported, good compatibility is achieved, existing software does not need to be modified, and the USB KEY is plug and play and convenient to operate. BRIEF DESCRIPTION OF DRAWINGS
[0013] Figure 1 : Architecture diagram of the transparent encryption virtual file system based on the hardware key; Figure 2 : Timing diagram of the hardware key management mechanism; Figure 3 : Flowchart of the transparent encryption file system read-write process; Figure 4 : Structure diagram of the file metadata management; Figure 5 : Timing diagram of the USB KEY plug-in control mechanism. DETAILED DESCRIPTION
[0014] Embodiments of the present disclosure will be described in more detail below with reference to the accompanying drawings. Although certain embodiments of the present disclosure are shown in the drawings, it is understood that the present disclosure can be implemented in various forms and should not be interpreted as being limited to the embodiments set forth herein, but rather the embodiments are provided to more thoroughly and completely understand the present disclosure. It is understood that the drawings and embodiments of the present disclosure are for exemplary purposes only and are not intended to limit the scope of protection of the present disclosure.
[0015] As shown in Figure 1 The technical scheme of the present application adopts a layered architecture design, mainly including a hardware security layer, a key management layer, an encryption engine layer, a virtual file system layer and a user application layer.
[0016] As shown in Figure 2 The USB KEY adopted by the present application has a built-in SM4 hardware encryption engine in line with the standard of the National Cryptographic Administration, and its key function is implemented as follows: Step S1, the master key is generated and permanently stored inside the USB KEY, and it does not leave the hardware boundary throughout the process, and its life cycle is completely limited to the hardware, and no software-level copy is generated throughout the process from generation, storage to operation, completely eliminating the risk of key derivation; Step S2, after the user inserts the USB KEY into the host USB interface, the file system agent module (FUSE) of the host end detects the USB device access event and immediately sends a device detection request to the key management module. After the key manager starts, it sends a device authentication request to the USB KEY, and the USB KEY returns the encrypted authentication response to the key management module through the USB interface. After receiving the response, the pre-stored device public key is called to decrypt and verify the response. After successful authentication, the FUSE module pops up a PIN code input interface on the host end, and after the user inputs the PIN code, the FUSE module immediately processes the PIN code in the encrypted isolation area of the host memory, and after successful verification, the hardware activates the master key for operation; Step S3, the derivation of the file-specific key is completed inside the hardware. After the system sends the derivation instruction containing the file path through the protocol, it is stored in the temporary register and immediately cleared after the operation is completed, ensuring the closed safety of the derivation process; Step S4, when the user pulls out the USB KEY, the FUSE module is activated and sends a hardware removal event to the key manager. After the key manager is activated, it clears all key handles, and then feeds back to the FUSE that the key cleaning is complete and closes. The FUSE then unloads the virtual file system and closes. At this time, the system enters a locked state, the virtual file system is inaccessible, and the physical storage only remains the SM4 ciphertext, all plaintext information has been cleaned up, ensuring complete data security.
[0017] AsFigure 3 As shown, the present invention provides a transparent encrypted file system based on FUSE technology, and its specific implementation is as follows: Step S1: After the USB KEY is inserted and PIN code authentication is completed, the FUSE driver automatically creates a virtual file system in user space and mounts it to the preset path, while registering file operation callback functions such as read and write. Step S2: For the write operation, the plaintext data output by the application is intercepted by the FUSE framework and sent to the SM4 encryption engine through the hardware interface of the USBKEY. The encrypted ciphertext is written to the physical storage medium by the callback function. Step S3: For the read operation, the callback function reads the encrypted data from the physical storage, decrypts it using the USB KEY, and returns it to the application. In step S4, throughout the entire process, the file creation, editing, and deletion operations performed by the user are completely consistent with accessing a normal file system. The encryption and decryption logic is embedded in the file operation chain and is unknown to the user and application, thus achieving full transparency of the encryption process.
[0018] like Figure 4 As shown, the encrypted file metadata management system of the present invention supports transparent encryption through a layered architecture. Each module collaboratively manages encryption identifiers, encryption parameters, and access control information. The specific implementation method is as follows: Data flow in each functional area follows strict access control rules: Step S1: The encrypted file metadata area provides basic information to the access control area to bind permissions. The basic file information includes encryption identifier, file name, file size, creation time and last access time. The encryption parameter information includes initialization vector, encryption algorithm identifier, key derivation parameters and encryption mode configuration. In step S2, the context management area manages the lifecycle of metadata through a standardized interface, while simultaneously calling the hardware engine area to perform encryption operations. In step S3, the access control area then provides real-time feedback on the current user's permission status to the context management area, forming a closed-loop mechanism of "metadata storage - permission control - context coordination - hardware encryption". Step S4: Through this architecture, the system achieves immutable encryption identifiers, secure isolation of encryption parameters, and dynamic control of access permissions, providing end-to-end metadata security for transparent encryption functions.
[0019] like Figure 5 As shown, the system of this invention constructs a complete USB key insertion and removal control mechanism through the USB device monitoring service integrated into the kernel, ensuring data security when the hardware is removed. The specific implementation is as follows: Step S1, after the user inserts the USB KEY, the system monitoring module detects the USB device insertion event, sends a device discovery notification to the authentication module, the authentication module immediately performs hardware legality verification with the USB KEY, and after verification, pushes the PIN code input interface to the user, the user inputs the PIN code which is encrypted and transmitted to the USB KEY, and the hardware inside completes the verification and returns a success response process; Step S2, after authentication, enter the virtual file system creation phase, the authentication module sends an activation instruction to the key manager, the key manager establishes an encrypted session with the USB KEY (the session key is generated by the hardware random number generator), then calls the FUSE library interface to mount a virtual directory in the preset path, and returns an accessible notification to the user after completion, at this time the user can access the file through the standard file operation interface, and the whole process is free of awareness encryption process; Step S3, in the file access phase, the user's read-write request is intercepted by the FUSE callback function, in the write operation, FUSE requests a special key derived based on the file path from the USB KEY through the key manager, and the hardware encryption engine completes SM4-CBC encryption after the ciphertext is written into the physical storage; in the read operation, FUSE reads the ciphertext and returns the plaintext after decryption by the USB KEY, and the whole process is realized by thread pool to realize parallel processing; Step 4, when the user pulls out the USB KEY, the system monitoring module detects the device removal event, immediately sends an offline notification to FUSE, FUSE triggers the forced uninstallation process, iterates and closes all file handles, calls the key and plaintext cache in memory, calls the virtual mounting point, and the key manager destroys the session information and cleans up the key handle, finally the physical storage only retains the SM4 encrypted ciphertext, and no sensitive information is left.
[0020] The specific embodiments of the application are described above. It should be understood that the application is not limited to the above specific embodiments, and those skilled in the art can make various changes or modifications within the scope of the claims, which does not affect the essential content of the application. In the case of no conflict, the embodiments of the application and the features in the embodiments can be combined with each other arbitrarily.
Claims
1. A method for implementing a transparent encrypted virtual file system based on hardware keys, characterized in that, include: A. It adopts a layered architecture design, including a hardware security layer, a key management layer, an encryption engine layer, a virtual file system layer, and a user application layer; B. The hardware security layer achieves hardware-level key isolation through the USB KEY. The master key is generated and permanently stored inside the USB KEY and never leaves the hardware boundary. All SM4 encryption and decryption operations are completed inside the USB KEY. C. The virtual file system layer is implemented based on FUSE technology. When the USB key is inserted and authenticated, a virtual file system is automatically created and mounted. During write operations, plaintext data is encrypted with SM4 and stored on the physical hard drive. During read operations, ciphertext data in the physical hard drive is decrypted with SM4 and returned to the application. This achieves real-time encryption and decryption and is completely transparent to the user, combining flexibility and security. D. Establish a USB KEY plug-in / plug-out control mechanism so that the virtual file system becomes immediately inaccessible when the KEY is unplugged; E. Based on the file path information and the master key in the USB key, the SM4 key derivation algorithm is used to dynamically derive file-specific keys. Different files use different encryption keys to achieve file-level key isolation and improve overall security.
2. The method according to claim 1, characterized in that, The hardware key management mechanism of the USB KEY specifically includes: A. Master key protection: The master key is generated and permanently stored inside the USB KEY. It only participates in calculations within the hardware and never leaves the hardware boundary. B. Identity authentication: After inserting the USB KEY, the user needs to enter a PIN code for identity authentication. Only after successful authentication can the user activate the key usage rights. C. Key Derivation: Based on the master key and file path information, a file-specific key is derived internally within the USB KEY hardware.
3. The method according to claim 1, characterized in that, The transparent encrypted file system based on FUSE technology includes file metadata management, which includes encryption identifiers, encryption parameters, and access control information. The encryption identifier is used to distinguish whether a file is encrypted. The encryption parameters store the initialization vector and related parameters of SM4 encryption. The access control information records file access permissions and encryption policies.
4. The method according to claim 1, characterized in that, The virtual file system based on FUSE technology is automatically created and mounted after the USB key is inserted and authenticated. Users and applications operate on encrypted files in the same way as on ordinary files, and the encryption and decryption process is imperceptible.
5. The method according to claim 1, characterized in that, The SM4 key derivation algorithm is implemented based on the PBKDF2 standard, and the formula is: FileKey = PBKDF2(MasterKey, FilePath || Salt, IterationCount, KeyLength), where MasterKey is the hardware master key in the USB key, FilePath is the complete path of the file, Salt is a randomly generated salt value, IterationCount is the number of iterations and is not less than 10,000, and KeyLength is the SM4 key length of 128 bits.
6. The method according to claim 1, characterized in that, The real-time encryption and decryption process adopts the SM4-CBC mode. The encryption process includes generating a random IV, dividing the file content into blocks (16-byte aligned), encrypting each data block using the SM4-CBC mode, and storing the IV and ciphertext data in a physical file. The decryption process includes reading the IV and ciphertext data from the physical file, performing SM4-CBC decryption using the same FileKey and IV, removing padding data, and returning the original plaintext.
7. The method according to claim 1, characterized in that, In the USB KEY insertion and removal control mechanism, when the device is inserted, the system verifies the device's legitimacy and initiates the authentication process; when the device is removed, a security cleanup is immediately performed, forcibly unloading the virtual file system and closing all file handles.
8. The method according to claim 1, characterized in that, It also includes performance optimization strategies, such as reducing hardware calls and disk I / O by caching derived file keys, file metadata, and frequently accessed encrypted data during sessions, and improving efficiency by using asynchronous I / O, multi-threaded parallel encryption and decryption, and pipelined processing.
9. The method according to claim 1, characterized in that, It also includes security mechanisms, such as immediately clearing sensitive memory data after processing, using a secure memory allocation mechanism to prevent leakage, performing HMAC integrity verification on encrypted files, protecting file metadata with digital signatures, and detecting whether file content has been tampered with.
Citation Information
Cited By
Data security processing method, client, electronic equipment and storage medium
CN122027356A