Virtual device data encryption transmission method integrated with private transmission protocol
By integrating a proprietary transmission protocol into the virtual device data encryption transmission method, the problem of lack of security in existing transmission devices that balance high-speed transmission and low-power design is solved, realizing secure and confidential data transmission and improving user experience and transmission efficiency.
Patent Information
- Application Number
- CN202511527010.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-10-24
- Publication Date
- 2025-11-21
- Estimated Expiration
- 2045-10-24
AI Technical Summary
Existing data storage and transmission equipment struggles to balance high-speed transmission requirements with low-power design, and lacks adaptive security mechanisms for transmission modes, making data transmission vulnerable to illegal theft or tampering.
A virtual device data encryption transmission method integrating a proprietary transmission protocol is adopted. The MCU detects the VBUS signal and automatically switches modes. A bridging chip is used to achieve dual-mode switching. A virtual partition table disk is used for encrypted communication. Combined with two-way authentication and key exchange, an encrypted secure channel is established, and data transmission is disguised through steganography.
It achieves the goals of maintaining transmission mode compatibility while ensuring data transmission security and confidentiality, reducing power consumption, improving user experience and data transmission efficiency, and preventing unauthorized access.
Smart Images

Figure CN121000537A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of communication security management, and particularly relates to a virtual device data encryption transmission method integrated with a private transmission protocol. BACKGROUND
[0002] The current data storage and transmission device generally has a dual application scene, that is, it can be used as a network storage server and can be directly connected to a computer through a USB interface to realize a mobile hard disk mode. However, in the prior art, the interface rate is usually limited and difficult to meet the high-speed transmission demand. At the same time, a power line and a data line need to be connected respectively, which increases the use complexity and brings additional power consumption. In addition, the SOC system needs to be powered on to operate, which leads to high overall energy consumption of the device and is not conducive to low-power design. On the other hand, in the data transmission process between the PC and the device, there is a lack of a transmission mode adaptive security mechanism, which leads to the fact that the transmission process is easily illegally stolen or tampered with.
[0003] In summary, how to realize secret and safe data transmission while maintaining transmission mode compatibility to improve the security and practicality of data transmission is a current technical problem to be solved. SUMMARY
[0004] The present application provides a virtual device data encryption transmission method integrated with a private transmission protocol, which is used to solve the technical problem in the prior art that secret and safe data transmission cannot be ensured while maintaining transmission mode compatibility.
[0005] In view of the above problems, the present application provides a virtual device data encryption transmission method integrated with a private transmission protocol.
[0006] The present application provides a virtual device data encryption transmission method integrated with a private transmission protocol, which comprises the following steps: a PC is accessed through a bus, a MCU is powered on and detects whether a VBUS signal exists, if the VBUS signal is valid, it is judged as a mobile hard disk mode, and mode control is performed according to a deployed dual-mode switching circuit; when entering the mobile hard disk mode, the MCU instructs a bridge chip, the PC sends an encrypted file block, and before responding to the command of the PC, the MCU virtually creates a partition table disk, wherein the partition table disk comprises a first partition and a second partition; a client of the PC and the MCU perform bidirectional authentication and key exchange, an encrypted safe channel is established, the encrypted file block sent by the PC is disguised as a target read-write command through protocol steganography processing, the target read-write command is transmitted through the encrypted safe channel and intercepted by the MCU, the target read-write command is interpreted and detected, if the detection is a safe sending request, the target read-write command is transported to a hardware encryption engine for processing and written into a memory, wherein the authentication parties are the client and the second partition in the partition table disk.
[0007] One or more technical solutions provided in the application have at least the following technical effects or advantages: The virtual device data encryption transmission method integrating a private transmission protocol provided by the embodiment of the application has the following technical effects or advantages. BRIEF DESCRIPTION OF DRAWINGS
[0008] Figure 1 A flowchart of the virtual device data encryption transmission method integrating a private transmission protocol is provided for the application. Figure 2 A connection diagram of mode switching in the virtual device data encryption transmission method integrating a private transmission protocol is provided for the application. Figure 3 A control diagram of mode switching in the virtual device data encryption transmission method integrating a private transmission protocol is provided for the application. DETAILED DESCRIPTION
[0009] The virtual device data encryption transmission method integrating a private transmission protocol provided by the application is used to solve the technical problem that secret and safe data transmission cannot be ensured while transmission mode compatibility is met in the prior art.
[0010] As shown in Figure 1 The application provides a virtual device data encryption transmission method integrating a private transmission protocol, which comprises the following steps: S1: PC accesses through a bus, MCU is powered on and detects whether a VBUS signal exists, if the VBUS signal is valid, it is judged as a mobile hard disk mode, and mode control is performed according to a deployed dual-mode switching circuit.
[0011] In the embodiment of the application, the PC end is connected with the device through a bus, and the bus is preferably a universal serial bus in the embodiment, which has the characteristics of plug and play and high-speed data transmission.
[0012] Specifically, after the PC establishes a physical connection with the device, the MCU inside the device starts to be powered on, wherein the MCU refers to a micro control unit in the application, which is a core control unit of the whole dual-mode switching circuit, used for detecting and logically judging external input signals, so as to realize subsequent mode recognition and switching operation.
[0013] Subsequently, after the MCU completes the power-on self-test, it first detects whether there is a VBUS signal, wherein the VBUS signal is a power supply voltage signal provided by the host end in the USB interface, usually 5V, used to represent the physical connection state of the host and the peripheral device.
[0014] Through detection of the VBUS signal, the MCU can confirm whether the device is correctly recognized and powered by the PC end. For example, when the PC supplies power to the peripheral device through the USB port, the VBUS pin will output a stable voltage, and the MCU can determine it as a valid signal after capturing the signal.
[0015] Subsequently, when the MCU detects that the VBUS signal is valid, the current device working mode is determined as the mobile hard disk mode.
[0016] Among them, the mobile hard disk mode in the embodiment refers to that the device is recognized by the PC end as a large-capacity storage device, so that it can interact with file reading and writing in the form of a disk. In this mode, the device does not need to be powered on by the NAS master system, but can directly map the storage medium to the PC end through the bridge chip, which has the characteristics of simple operation and low power consumption.
[0017] Further, after confirming the entry into the mobile hard disk mode, the MCU executes mode control according to the pre-deployed dual-mode switching circuit. The dual-mode switching circuit proposed in the application refers to a circuit structure composed of a switching chip, a bridge chip and related peripheral devices, which functions to switch the path between the network mode and the mobile hard disk mode.
[0018] For example, in the mobile hard disk mode, the MCU controls the switching chip to connect the SATA path of the SSD to the USB bridge chip, so as to realize the direct connection of the PC and the storage medium; and in another network mode, it is switched to the NAS master chip, which takes over the control of the storage medium.
[0019] Through the above process, the device can automatically enter the mobile hard disk mode when detecting the VBUS signal, ensuring that the user can complete the recognition and use of the storage device in the case of inserting only one USB data line, which has good user experience and system compatibility.
[0020] Further, according to the mode control of the deployed dual-mode switching circuit, the step S1 of the application comprises: The VBUS signal is continuously monitored by the MCU. When the VBUS signal is valid, the mobile hard disk mode is entered, wherein the MCU is disconnected from the NAS SOC, and all communications are taken over by the MCU and the bridge chip. When the VBUS signal is invalid, the network mode is entered, wherein the MCU starts the NAS SOC, and the SSD control is transferred to the NAS SOC through the switch chip.
[0021] Further comprising: when there is a mode switching operation based on the dual-mode switching circuit, the security context information is determined and encrypted and packaged, and temporarily stored in the dedicated memory; the MCU transmits and loads the encrypted and packaged security context information through the security message.
[0022] In the embodiment, the MCU is the core control unit of the device, which is in a continuous working state and monitors the VBUS signal in real time.
[0023] The VBUS signal is a power voltage signal provided by the PC USB interface, which is used to represent the connection state between the host and the peripheral. When the MCU detects that the VBUS signal is valid, it means that the PC has powered the device through the USB interface and established a communication link. At this time, the MCU immediately determines that the current device should enter the mobile hard disk mode.
[0024] In one specific embodiment of the application, the VBUS signal can be detected and stabilized at 5V to be determined as valid.
[0025] Subsequently, after entering the mobile hard disk mode, the MCU will actively disconnect the logical connection with the NAS master chip, i.e. the SOC, thereby avoiding the high power consumption caused by the power-on operation of the SOC system, and at the same time, the MCU takes over all communications between the SSD and the PC through the control of the bridge chip.
[0026] Preferably, in the mobile hard disk mode, the PC can directly recognize the storage medium as a large-capacity disk, realize the same read-write operation as the mobile hard disk, and ensure the dual advantages of high speed and low power consumption.
[0027] On the other hand, when the MCU detects that the VBUS signal is invalid during continuous monitoring, i.e. the USB interface fails to obtain a valid power signal from the PC, which is specifically manifested as the inability to detect the VBUS signal or the inability to maintain the stability of the VBUS signal, the MCU determines that the current device should enter the network mode.
[0028] Subsequently, the MCU starts the NAS SOC, so that the SOC system is powered on and runs, and the control of the SSD is switched from the channel of the bridge chip to the NAS SOC through the control of the switch chip, so that the NAS SOC takes over the access and management of the memory.
[0029] In the network mode, the device has complete network storage function, can provide data service externally through the Ethernet interface, and realizes remote access and centralized storage management.
[0030] In summary, through the above automatic mode determination and switching mechanism, the device can flexibly adapt to different application scenarios according to the external power supply and communication state, avoids manual operation of the user, and improves the use convenience and system stability.
[0031] Further, when there is a mode switching operation based on the dual-mode switching circuit, the MCU not only performs channel switching, but also processes the security context information of the current communication. The security context information proposed in the application refers to the security session parameters, key data and authentication state that have been established in the previous mode, which is used to maintain communication continuity and security.
[0032] Specifically, when the MCU detects that the mode switching occurs, it will immediately encrypt and package the security context information, and temporarily store it in a special memory to prevent information leakage or loss during the switching process.
[0033] For example, when switching from the mobile hard disk mode to the network mode, the established encrypted session parameters are packaged into ciphertext by the hardware encryption module, and then written into the isolated storage unit for safe storage.
[0034] Subsequently, after completing the encryption and temporary storage of the security context information, the MCU transmits and loads the above-mentioned encrypted and packaged information through a security message mechanism.
[0035] Specifically, the security message refers to the encrypted communication format used when sensitive data is transmitted between different functional modules in the device, which has the characteristics of integrity verification and confidentiality protection. The MCU transmits the encrypted and packaged context information to the service module corresponding to the new working mode through the security message mechanism, for example, to the encryption service engine of the NAS SOC, so that it can restore the previous security communication state when loaded.
[0036] In summary, even if the device frequently switches between the two modes, the continuity of the encrypted communication session and the security of the data interaction can be ensured, and the user is prevented from performing redundant authentication or key negotiation operations again, thereby improving the security and reliability of the system and the user experience.
[0037] S2: When entering the mobile hard disk mode, the MCU instructs the bridge chip to send the encrypted file block to the PC, and a partition table disk is virtually generated before responding to the command of the PC, wherein the partition table disk comprises a first partition and a second partition.
[0038] In the embodiment, when the device is determined to enter the mobile hard disk mode via the MCU, the MCU first issues a control instruction to the bridge chip, so that the bridge chip establishes a communication path with the PC end.
[0039] In the mode switching circuit provided by the application, the bridge chip is additionally arranged to perform protocol conversion, so as to map the USB data request sent by the PC end into a SATA or PCIe command recognizable by the memory, thereby ensuring that the PC can access the device in the standard mobile hard disk mode.
[0040] In this state, the PC end can send an encrypted file block to the device, wherein the encrypted file block refers to a file data unit processed by the client end, and the file block is always in a ciphertext state as a basic unit of data transmission in the transmission process, so as to ensure the confidentiality and integrity of the data.
[0041] Subsequently, before responding to the access command of the PC end, the MCU virtually generates a partition table disk. The virtual partition table disk provided by the application refers to a disk partition structure simulated by the MCU through firmware logic, which does not exist in the physical storage medium, but is externally presented as a standard disk in the form of memory mapping and software definition. The purpose of generating the partition table disk is to establish a logically isolated and secure channel for subsequent data transmission, and the partition table disk is divided into two functionally different partitions.
[0042] The first partition serves as a public communication partition and is in a display state, which is recognized and mounted by the PC operating system, so that the user can see the normal file structure in the partition, thereby maintaining consistency with the conventional mobile hard disk mode.
[0043] The second partition is an encrypted communication partition and is in a hidden state, which is invisible in the conventional operating system environment and cannot be automatically mounted or recognized. The second partition mainly undertakes the functions of secure communication and key interaction.
[0044] In the application, the public partition and the hidden partition coexist in the virtual partition table, which not only ensures the compatibility and intuitive experience of the user side, but also provides an independent and concealed logical channel for the encrypted communication between the MCU and the PC client, thereby achieving the balance between security and convenience.
[0045] Further, the step S2 comprises: The first partition is a public communication partition, and the second partition is an encrypted communication partition; wherein the first partition in the virtual partition table disk of the MCU is in a display state, and the second partition is in a hidden state, wherein the hidden state represents that it is invisible at the operation level and cannot be recognized and mounted by mainstream operating systems, and cooperates with the MCU to transmit encrypted private protocol data packets.
[0046] In the embodiment, the first partition is defined as a public communication partition, which corresponds to the visible space of a common storage device in logic. When the MCU virtually creates a partition table disk, the first partition is set to a display state, that is, it can be directly recognized and mounted in the PC operating system, and the user can access and operate it like using a common mobile hard disk. Through the existence of the partition, the interaction experience consistent with the conventional USB mass storage device can be maintained, thereby ensuring the compatibility with mainstream operations and the usability at the user level.
[0047] Correspondingly, the second partition is defined as an encrypted communication partition, and the design purpose of the partition is to establish a secure and hidden transmission channel between the MCU and the PC client. When the MCU virtually creates a partition table disk, the second partition is set to a hidden state, that is, the partition is invisible at the operation level, that is, it does not appear in the disk management tool or file manager of the mainstream operating system, and cannot be accessed through the conventional mounting mechanism.
[0048] Preferably, the hidden state of the second partition is characterized by: on the one hand, it is completely exposed at the external use level, avoiding direct interference of user misoperation or malicious programs; on the other hand, it reserves a dedicated data interaction area for the MCU, for carrying private protocol data packets processed by encryption.
[0049] In the specific application process, when the PC client and the MCU establish an encrypted channel, the encrypted file block is encapsulated into a private protocol data packet, and interacts through the second partition. Then, the MCU internally intercepts and analyzes the data read-write request of the partition, realizes the transmission and verification of encrypted data.
[0050] Therefore, the public communication partition is responsible for maintaining the ordinary data interaction experience externally, and the encrypted communication partition cooperates with the MCU to perform hidden data transmission and security protocol operation, and the two together constitute the complete functional framework of the virtual partition table disk, ensuring the security and concealment of data transmission without affecting the user experience.
[0051] S3: The client of the PC performs mutual authentication and key exchange with the MCU, establishes an encrypted secure channel, and disguises the encrypted file block sent by the PC as a target read-write command through protocol steganography processing. The target read-write command is transmitted through the encrypted secure channel and intercepted by the MCU. The target read-write command is interpreted and verified. If it is a secure transmission request, it is sent to the hardware encryption engine for processing and written into the memory. The authentication parties are the client and the second partition in the partition table disk.
[0052] In this embodiment, when the client application of the PC is started, it first initiates a mutual authentication process with the MCU inside the device. That is, both the client and the MCU need to complete identity verification to ensure the compliance and trustworthiness of the communication parties.
[0053] The MCU is pre-installed with a device private key and a matching public key certificate, while the client is built-in with the public key certificate as the basis for verification. During the authentication process, the client encrypts a randomly generated verification code using the public key certificate and sends it to the MCU. The MCU decrypts the verification code using its own private key and returns the result, thereby completing the mutual identity confirmation. Through this process, it is ensured that unauthorized terminals cannot access the communication channel.
[0054] Subsequently, after mutual authentication is completed, the client and the MCU enter the key exchange phase, that is, both parties negotiate to generate a shared key through a secure protocol mechanism, and derive a session key pair based on the shared key and the random number of both parties, including but not limited to a symmetric encryption key for data encryption and decryption and an authentication key for integrity verification. Through the derivation of the session key, an encrypted secure channel is established between the client and the MCU, ensuring the confidentiality and integrity of the subsequent transmitted data.
[0055] Subsequently, the PC client will encrypt the file block and further disguise the encrypted file block through protocol steganography, that is, embed the encrypted file block into the data payload area of the standard read-write command format, so that it appears as a compliant target read-write command, thereby avoiding regular detection mechanisms during transmission.
[0056] For example, the client will encapsulate the file block as the data stage content of the standard write instruction, so that the seemingly ordinary data write operation actually carries encrypted file data inside.
[0057] Further, when the disguised target read-write command is transmitted to the device end through the encrypted secure channel, the MCU will intercept it when it passes through the second partition of the virtual partition table disk. The MCU uses the interpretation rules defined by the pre-set instruction set to interpret and verify the target read-write command to determine whether it is a secure transmission request.
[0058] If the test passes, indicating that the command is compliant and the data source is trustworthy, the MCU extracts the encrypted file block of the data payload area from the target read-write instruction and sends it to the hardware encryption engine for decryption verification. After successful decryption verification, the file data is finally written into the memory, completing the entire secure transmission process.
[0059] In summary, the embodiment forms logical isolation and secure binding by taking the second partition in the partition table disk as the interactive object for authentication and transmission, ensuring that the public partition is not affected, and that the encrypted communication is completely dependent on the hidden partition in cooperation with the MCU, thereby significantly improving the security and concealment of data transmission.
[0060] Further, the PC client and the MCU perform mutual authentication and key exchange to establish an encrypted secure channel. The step S3 of the present application includes: The client inputs a file block and performs first encryption processing to determine an encrypted file block. The first encryption processing includes mutual authentication and key exchange encryption. When mutual authentication fails, the file block transmission is terminated. When mutual authentication succeeds, a secure encryption channel is established and key exchange encryption processing is performed.
[0061] In the embodiment, the client first inputs a file block to be transmitted, which is the original data unit that the user needs to write or transmit to the device on the PC side. To ensure data security during transmission, the client performs first encryption processing on the file block before transmission. The first encryption processing refers to encrypting the data through mutual authentication and key exchange mechanism before the file block enters the transmission link, to ensure that the data can only flow between trusted communication parties.
[0062] In the specific execution process of the first encryption processing, mutual authentication is the basic link. The client and the device-side MCU perform mutual identity verification through pre-set public key certificates and device private keys, to ensure that both communication parties are compliant entities.
[0063] Specifically, if either party fails to pass the identity verification during the authentication process, for example, the client cannot correctly decrypt the verification information returned by the MCU, it is immediately determined that the authentication fails. In the case of authentication failure, the transmission operation of the current file block is terminated, avoiding the possibility of illegal access to data from the source, thereby ensuring the integrity and security of the transmission channel.
[0064] When the mutual authentication is successfully completed, the client and the MCU continue to perform a key exchange encryption process. The key exchange refers to that both parties generate a shared key through a secure negotiation mechanism, and derive a session key pair, including a symmetric encryption key and an authentication key, in combination with respective random numbers. At this time, both parties formally establish a secure encryption channel, and all data transmitted in the channel is encrypted and protected by the session key. The client encrypts the input file block using the session key in this stage to generate an encrypted file block.
[0065] Thus, the file block is protected as ciphertext before transmission, and even if intercepted during transmission, it cannot be illegally parsed or tampered with. Through the above steps, the confidentiality, integrity and attack resistance of the file block transmission are ensured, laying a foundation for subsequent secure transmission.
[0066] Further, the step S3 of the application comprises: The mutual authentication comprises that the MCU pre-stores a device private key and a public key certificate, the public key certificate is hard-coded in the client of the PC, the client encrypts a random verification code through the public key certificate and sends it to the MCU, the MCU decrypts based on the device private key and replies, and the mutual authentication is completed.
[0067] The key exchange encryption comprises that when the mutual authentication is passed, the client and the MCU generate a shared key through exchange; a session key pair is derived in combination with random numbers of both parties according to the shared key, wherein the session key pair includes a symmetric encryption key and an authentication key; and the file block is encrypted and processed according to the session key to generate an encrypted file block.
[0068] In the embodiment, the mutual authentication process specifically comprises the following steps. The MCU pre-stores a pair of device private key and public key certificate in the device, wherein the private key is securely stored in the hardware security module of the MCU for subsequent decryption and signature operation; and the corresponding public key certificate is hard-coded in the client application of the PC to ensure that the client can directly call the public key certificate for encryption operation when establishing a connection.
[0069] Specifically, the client generates a random verification code when initiating authentication, which is used as one-time challenge data to verify the authenticity of the MCU in the technical solution of the application.
[0070] Subsequently, the client encrypts the random verification code using the public key certificate of the MCU and sends the encrypted result to the MCU. Further, the MCU decrypts the ciphertext by calling the internally stored device private key after receiving the ciphertext.
[0071] If the decrypted verification code is consistent with the one generated by the client, it indicates that the identity verification of both parties is successful. At this time, the MCU will reply the decryption result to the client, completing the two-way authentication process. Through this mechanism, not only does the client confirm the identity of the MCU, but the MCU also proves that it has the corresponding private key, ensuring the compliance of both parties in communication.
[0072] In further embodiments, on the basis of successful two-way authentication, both parties enter the key exchange encryption phase.
[0073] Specifically, the client and the MCU exchange necessary parameters through a secure negotiation process, thereby generating a shared key. The shared key serves as the basis for subsequent derivation. In one feasible implementation, a pair of session keys is derived via a key derivation function in combination with the random numbers generated by the client and the MCU.
[0074] The session key pair includes a symmetric encryption key for file data encryption and decryption, and an authentication key for data integrity verification and identity authentication. Through the key pair, both parties can not only protect the confidentiality of transmitted data, but also ensure that the data has not been tampered with or forged.
[0075] Subsequently, after obtaining the session key pair, the client immediately uses the symmetric encryption key to encrypt the input file block, thereby generating an encrypted file block. The encrypted file block is always in ciphertext state during subsequent transmission, ensuring that even in an untrusted network environment, the data content cannot be illegally parsed or utilized, thereby significantly improving the security and reliability of file transmission.
[0076] Further, the encrypted file block sent by the PC is disguised as a target read-write command through protocol steganography processing. Step S3 of the present application includes: Setting a private protocol steganography mode, performing protocol steganography on the encrypted file block according to the private protocol steganography mode to generate a read-write command, wherein the encrypted file block is taken as the data stage content of the read-write command. The setting method of the private protocol steganography mode is as follows: for a private protocol, a standard field-byte is determined; an instruction set definition is determined, wherein the instruction set definition is a redefinition based on the meaning of the private protocol, and at least includes an instruction code and a sequence number; and the private protocol steganography mode is set according to the standard field-byte and the instruction set definition.
[0077] In the embodiment, in order to ensure the concealment and anti-detection of the encrypted file block in the transmission process, a private protocol steganographic mode is proposed. The private protocol steganographic mode refers to the secondary definition and embedding processing of the existing transmission protocol, so that the encrypted file block can be disguised as normal read-write command data payload, thereby realizing the effect of transmitting ciphertext in the form of ordinary operation.
[0078] Specifically, after the MCU and the client establish an encrypted channel, the encrypted file block will be embedded in the specified area of the protocol data frame according to the agreed steganographic mode, so as to appear as a regular storage operation request.
[0079] In the execution process, first, the standard field-bytes of the private protocol need to be determined. The standard field-bytes refer to the fixed format area reserved or defined in the protocol message, such as the command header, the length field, the check field, etc. The above fields are indispensable in normal protocol interaction, and have stable byte structure and fixed semantics.
[0080] In the steganographic mode, the MCU will use these standard fields to constrain the data encapsulation process to ensure that the generated message still conforms to the regular protocol format when observed externally, and will not cause exceptions.
[0081] Secondly, instruction set definition is needed. The instruction set definition refers to the redefinition of the necessary identifiers such as operation codes under the standard fields of the private transmission protocol based on the specific semantics of the private protocol. For example, a one-byte length operation code is repositioned as a main instruction code, and a four-byte length LBA is redefined as a 32-bit sequence number, while embedding the information of the data segment order in the sequence number to ensure that the encrypted file block can be correctly recombined.
[0082] In summary, the redefined instruction set at least contains two core fields of instruction code and sequence number, thereby ensuring that the steganographic command not only conforms to the form, but also has complete execution logic.
[0083] Finally, according to the standard field-bytes and the redefined instruction set definition, a complete private protocol steganographic mode is formed.
[0084] In the above mode, the encrypted file block is directly embedded as the data stage content of the read-write command, that is, a standard data write request is generated on the surface, while the actual payload part stores the encrypted file block. In this way, any external monitoring system can only identify it as a regular write operation, and cannot judge that it contains sensitive encrypted data, thereby greatly improving the concealment and security of the transmission.
[0085] Furthermore, step S3 of this application includes: performing protocol steganography processing on the encrypted file block according to the private protocol steganography mode to generate the target read / write command; wherein, the first steganography step is a conversion based on the instruction set definition, and the second steganography step is the generation of the read / write command and the writing of the converted encrypted file block command, and the encrypted file block is stored in the data payload area of the read / write command.
[0086] In this embodiment, after setting the private protocol steganography mode, protocol steganography processing is then performed on the encrypted file block to generate target read / write commands. These target read / write commands appear externally as standardized read / write instructions conforming to the storage protocol specification, but internally actually carry encrypted file data. In this way, the encrypted file block is naturally embedded into the regular data stream of protocol interaction, achieving steganographic transmission.
[0087] In the specific processing, the first step of steganography is performed, which is a conversion based on the instruction set definition. In a specific implementation, the ordinary protocol opcodes and sequence numbers are replaced or expanded into the instruction structure required by the steganography protocol using the previously reset instruction set definition, that is, the conversion of the encrypted file block based on the private protocol steganography mode.
[0088] Subsequently, the second steganography step is performed, namely, the generation of read / write commands and the writing of encrypted file block commands. In this step, a standardized read / write command is first generated, and the converted encrypted file block is embedded into the generated read / write command as a data payload.
[0089] Specifically, the data phase portion of the generated read / write command is reused as the payload area, and the encrypted file block is completely written into it, thereby forming a complete command message with steganographic features and generating the target read / write command.
[0090] In the preferred processing method, the generated standardized read and write commands are also converted according to the instruction set definition, so that the MCU can verify whether they are the original commands by decoding after subsequent interception.
[0091] At this point, the target read / write command appears to external monitoring or analysis tools as a routine write operation, as its structure is completely identical to the standard read / write command and will not trigger any anomalies. However, its actual data payload area stores real encrypted file blocks, providing a hidden transmission channel for subsequent decryption and processing.
[0092] Therefore, the generated target read / write commands not only have good camouflage properties, but also ensure the integrity and security of the encrypted file blocks during transmission.
[0093] Furthermore, by transmitting through an encrypted secure channel and intercepting the data with the MCU, the target read / write commands are decoded and verified. Step S3 of this application includes: The target read-write command is transmitted to the second partition of the partition table disk, and the MCU intercepts the target read-write command; the target read-write command is interpreted based on the instruction set definition to determine whether it is a secure transmission request; if it is a secure transmission request, the MCU extracts the data stage content of the target read-write command, receives the encrypted file block, and sends the encrypted file block to the hardware encryption engine for decryption verification.
[0094] In this embodiment, when the target read-write command is transmitted to the device end via the encrypted secure channel, the command is first introduced into the second partition of the virtual partition table disk. The second partition is in an invisible state to the operating system and is mainly used for encrypted communication and private protocol data transmission in cooperation with the MCU.
[0095] Further, after entering the second partition, the target read-write command is not directly recognized by the operating system as a normal storage request, but is intercepted and taken over by the MCU internally. In this way, the MCU can obtain the command packet in the first time and perform special analysis and security verification to prevent unauthorized data from entering the memory.
[0096] Specifically, after intercepting the target read-write command, the MCU interprets it based on the previously defined instruction set definition of the private transmission protocol, that is, the operation code, sequence number and additional fields in the target read-write command are parsed according to the rules of the instruction set definition to determine whether the command is a compliant and secure transmission request.
[0097] For example, if the instruction code and sequence number in the command meet the format and order required by the steganography protocol, it is determined to be a valid request; if it does not meet or there are abnormal fields, it is immediately rejected and the processing is aborted. Through the interpretation process, the MCU can effectively prevent fake commands or malicious instructions from being mixed into the secure channel, thereby ensuring the integrity and reliability of the transmission process.
[0098] If the determination result shows that the target read-write command is a secure transmission request, the MCU will further extract the encrypted file block from the data stage of the target read-write command. The data stage content, i.e. the payload area in the target read-write command protocol packet carrying the actual file block, has been filled with the encrypted file block in the steganography step.
[0099] Subsequently, after extracting the content, the MCU hands it over to the hardware encryption engine inside the device for decryption and verification. The hardware encryption engine, as a device-specific security processing module, can complete symmetric decryption operations and integrity checks at high speed to ensure that the encrypted file block has not been tampered with and is trustworthy during transmission. After decryption and verification, the file block is written into the memory, thus completing a complete and secure data transmission process.
[0100] In summary, the secure file transmission in the virtual partition environment is realized, which not only guarantees the concealment and anti-detection of the encrypted file block, but also ensures the confidentiality and integrity of the data.
[0101] The virtual device data encryption transmission method integrating the private transmission protocol provided by the application has the following technical effects: 1. The dual-mode switching circuit is used to realize automatic switching between the mobile hard disk mode and the network mode, the mobile hard disk mode does not need to power on the NAS SOC, the power consumption is reduced, and only one data line is needed for connection, thereby improving the user convenience; the security context information is encrypted, encapsulated and transmitted during mode switching, the continuity of the security state during the switching process is ensured, information leakage or authentication failure is avoided; the high-speed bridge chip and the high-speed storage device are supported, the data encryption transmission is ensured, the transmission rate is taken into account, and the efficient data interaction demand is met.
[0102] 2. The private transmission protocol and the protocol steganography processing are introduced, the encrypted file block is disguised as a target read-write command, the data transmission concealment is enhanced, and the risk of malicious interception and cracking is reduced; the client and the MCU are authenticated and the key exchange mechanism is used, the device public and private key certificate and the shared key are used to derive the session key, the identity compliance and the key security are ensured, the encryption basis for data transmission is provided; the hardware encryption engine is used for data processing, the encryption and decryption efficiency and security are improved, and the whole process safety of data from transmission to storage is ensured; the second partition hidden in the virtual partition table disk is only used for encryption communication and is not recognized by the mainstream system, the encrypted data is further isolated, and the unauthorized access risk is reduced.
[0103] In further embodiments, the application provides a connection diagram for mode switching, in the technical scheme of the application, the switching in the mobile hard disk mode and the network mode is performed, thereby providing a basic condition for the encryption transmission scheme of the application.
[0104] As shown in Figure 2 , it is a connection diagram for mode switching of the application. Specifically, it includes: a power type-c interface (J1), a type-c interface (J2) connected to a PC in a mobile hard disk mode, a J3 connected to an SSD, a type-C 10Gbps to SATA3.0 bridge chip (U3), a SATA3.0 1 to 2port switch 10G chip VL163 (U4), an MCU controller (U2), and a NAS SOC controller (U1).
[0105] As shown in Figure 2 , Figure 3 , the specific implementation mode of the mode switching performed on the basis of the above circuit is: When the user only uses the mobile hard disk mode, the switch selection pin SEL of U4 has a default pull-down resistor R319, and the SATA channel is by default switched from C to 2, that is, the user connects the data line from the PC to J2, then through the bridge chip U3, and then access the switch chip U4, that is, can connect J3, realize the PC on disk of SSD, the user only needs a data line to realize the connection with the hard disk, at the same time, without the power on of SOC and MCU, the power consumption is reduced.
[0106] When the user uses the network mode, the user power is inserted into J1, and the MCU (U2) of the device is powered on first. The MCU first detects whether there is 5V voltage on the VBUS of J2, that is, whether the user connects through J2 in the mobile hard disk mode. If it is detected that there is 5V on the VBUS of J2, the switch chip will not perform switching operation, that is, the mobile hard disk mode is preferentially guaranteed; if it is detected that there is no 5V on the VBUS of J2, then the power supply of U1 is turned on, and then the switch chip will switch the C end to 1, and safely enter the network mode.
[0107] Through the foregoing detailed description of the virtual device data encryption transmission method integrated with the private transmission protocol, those skilled in the art can clearly understand the virtual device data encryption transmission method integrated with the private transmission protocol in the embodiment. For the device disclosed in the embodiment, since it corresponds to the method disclosed in the embodiment, the description is relatively simple, and the related part is referred to the method part description.
[0108] The foregoing description of the disclosed embodiments enables a person skilled in the art to implement or use the present application. Various modifications to these embodiments will be apparent to those skilled in the art, and the general principles defined herein can be implemented in other embodiments without departing from the spirit or scope of the application. Therefore, the present application will not be limited to the embodiments shown herein, but will conform to the widest scope consistent with the principles and novel features disclosed herein.
Claims
1. A method for encrypted transmission of virtual device data integrating a proprietary transmission protocol, characterized in that, The method includes: The PC is connected via a bus. The MCU is powered on and detects the presence of a VBUS signal. If the VBUS signal is valid, it is determined to be in mobile hard drive mode. Mode control is performed according to the deployed dual-mode switching circuit. When entering external hard drive mode, the MCU instructs the bridge chip, and the PC sends encrypted file blocks. Before responding to the PC's command, the MCU virtualizes a partition table disk, which contains a first partition and a second partition. The PC client and MCU perform two-way authentication and key exchange to establish an encrypted secure channel. The encrypted file block sent by the PC is disguised as the target read / write command through protocol steganography, transmitted through the encrypted secure channel and intercepted by the MCU. The target read / write command is decoded and verified. If the verification is a secure transmission request, it is sent to the hardware encryption engine for processing and written to the memory. The two parties to the authentication are the client and the second partition in the partition table disk.
2. The virtual appliance data encryption transmission method integrating a private transmission protocol of claim 1, wherein, Mode control is performed based on the deployed dual-mode switching circuit, including: The MCU continuously monitors the VBUS signal. When the VBUS signal is valid, it enters the external hard drive mode. In this mode, the MCU is disconnected from the NAS SOC, and the MCU and the bridge chip take over all communication. When the VBUS signal is invalid, the system enters network mode, in which the MCU starts the NAS SOC and transfers control of the SSD to the NAS SOC through a switching chip.
3. The virtual appliance data encryption transmission method integrating a private transmission protocol of claim 2, wherein, When a mode switching operation based on a dual-mode switching circuit exists, the security context information is determined and encrypted, and then temporarily stored in a dedicated memory. The MCU transmits encrypted and encapsulated security context information and loads services through security messages.
4. The virtual appliance data encryption transmission method integrating a private transmission protocol of claim 1, wherein, The PC client and the MCU perform two-way authentication and key exchange to establish an encrypted secure channel, including: The client inputs a file block, performs the first encryption process, and determines the encrypted file block. The first encryption process includes two-way authentication and key exchange encryption. Specifically, if authentication between the two parties fails, the file block transmission is terminated; if authentication between the two parties succeeds, a secure encrypted channel is established and key exchange encryption is performed.
5. The virtual appliance data encryption transmission method integrating a private transmission protocol of claim 4, wherein, The two-way authentication includes: The MCU is pre-configured with a device private key and a public key certificate, and the public key certificate is hard-coded in the PC client. The client encrypts a random verification code using a public key certificate and sends it to the MCU. The MCU decrypts the code based on the device's private key and responds, completing the two-way authentication.
6. The virtual device data encryption transmission method integrating a proprietary transmission protocol as described in claim 5, characterized in that, The key exchange encryption includes: Once mutual authentication is successful, the client and the MCU exchange and generate a shared key. Based on the shared key and combined with random numbers from both parties, a session key pair is derived, wherein the session key pair includes a symmetric encryption key and an authentication key; The file block is encrypted using the session key to generate an encrypted file block.
7. The virtual device data encryption transmission method integrating a proprietary transmission protocol as described in claim 6, characterized in that, Encrypted file blocks sent to the PC are steganized using the protocol to disguise them as target read / write commands, including: A private protocol steganography mode is set, and protocol steganography is performed on the encrypted file block according to the private protocol steganography mode to generate read and write commands, wherein the encrypted file block is used as the data phase content of the read and write commands; The method for setting the private protocol steganography mode is as follows: For proprietary protocols, determine the standard field - bytes; Determine the instruction set definition, wherein the instruction set definition is a redefinition based on the meaning of the private protocol, and includes at least instruction code and sequence number; Based on the standard field-byte and the instruction set definition, the private protocol steganography mode is set.
8. The virtual device data encryption transmission method integrating a proprietary transmission protocol as described in claim 7, characterized in that, According to the private protocol steganography mode, the encrypted file block is subjected to protocol steganography processing to generate the target read / write command; The first steganography step involves converting the code based on the instruction set definition, and the second steganography step involves generating read / write commands and writing the converted encrypted file block commands. The encrypted file block is stored in the data payload area of the read / write commands.
9. The virtual device data encryption transmission method integrating a proprietary transmission protocol as described in claim 8, characterized in that, The target read / write commands are transmitted through an encrypted secure channel and intercepted by the MCU, and then interpreted and verified, including: The target read / write command is transmitted to the second partition of the partition table disk, and the MCU intercepts the target read / write command. By interpreting the target read / write commands based on the instruction set definition, it is determined whether the request is a secure transmission request. If the request is sent securely, the MCU will extract the data phase content of the target read / write instruction, receive the encrypted file block, and send the encrypted file block to the hardware encryption engine for decryption and verification.
10. The virtual device data encryption transmission method integrating a proprietary transmission protocol as described in claim 1, characterized in that, The first partition is a public communication partition, and the second partition is an encrypted communication partition; In this system, the first partition in the virtual partition table disk of the MCU is in a visible state, while the second partition is in a hidden state. The hidden state indicates that it is not visible at the operational level and cannot be recognized and mounted by mainstream operating systems. It is used in conjunction with the MCU to transmit encrypted private protocol data packets.
Citation Information
Patent Citations
Data encryption method and system for solid state disk
CN119150329A
Hard disk data protection and secure transmission system
CN120316839A
Non-inductive implementation method for encrypted hidden partition based on bridging chip
CN120822245A
Method and system for encrypting files and storing the encrypted files in a storage file system
US20190171841A1