Multi-protection method and system for storage medium destroying machine

By reading unique identification information, generating a one-time pass code, creating a dynamic security zone, and linking electromagnetic shielding and physical interlocking in the storage medium destruction machine, triple authentication and multi-source sensor data acquisition are implemented, solving the problems of incomplete trust chain and untrusted auditing in the storage medium destruction process, and achieving higher security and reliability.

CN121145274AActive Publication Date: 2025-12-16JUNENG XINAN (TIANJIN) TECHNOLOGY CO LTD

Patent Information

Application Number
CN202511620706.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-11-07
Publication Date
2025-12-16
Estimated Expiration
2045-11-07

AI Technical Summary

Technical Problem

In existing technologies, the storage media destruction process suffers from an incomplete trust chain and a black box approach to process verification, leading to leakage risks and unreliable audit results, which affects the security of the destruction operation.

Method used

By comparing the unique identification information of the storage medium with the preset authorized database, a one-time destruction pass code is generated, a dynamic security zone is created and electromagnetic shielding and physical locking structures are linked, triple authentication is implemented and multi-source sensors are activated to collect data, a destruction encryption digest is generated, and multiple protections are provided by combining the one-time destruction pass code and multi-modal sensor data.

Benefits of technology

Ensuring complete and tamper-proof records of each destruction operation enhances the security and reliability of the destruction process and reduces the risk of data leakage.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121145274A_ABST
    Figure CN121145274A_ABST
Patent Text Reader

Abstract

The invention provides a multi-protection method and system for a storage medium destroying machine, and relates to the technical field of data security, the method comprises the following steps: a storage medium enters a destroying cabin, the unique identification information of the storage medium is read, and the unique identification information is compared with a preset authorization database for verification; creating a dynamic safety area; operator identity confirmation, external authorization confirmation and storage medium state confirmation are executed, and when the triple authentication is passed, destruction operation is executed; activating a multi-source sensor to perform data acquisition; sending the multi-modal sensing data to an abnormity authentication channel; the multi-protection of destruction is carried out according to the destruction encryption abstract, the one-time destruction pass code and the multi-mode sensing data. According to the method and the device, the technical problem that in the prior art, due to incomplete trust chains and black boxed process verification, leakage risks exist before and after the storage medium is destroyed, auditing results are incredible, and the safety of destroying operation is affected is solved, and the safety of destroying operation is improved through multiple protections.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of data security, in particular to a multi-protection method and system for a storage medium destruction machine. BACKGROUND

[0002] The security guarantee of storage media in the scrapping disposal link is the last line of defense of data life cycle management, and its reliability is crucial. At present, the industry generally adopts physical crushing, demagnetization or logical erasure and other technologies to destroy storage media. However, in the face of storage media such as solid state disks, the existing solutions generally rely on the integrity and credibility of the destruction equipment itself, and the internal operation process is a black box that cannot be seen by the user, so that the destruction operation has trust blind spots in the authorization, execution and verification links. Before the destruction execution, there is a lack of strong correlation verification of the medium identity, operation permission and destruction instruction, which cannot effectively prevent unauthorized or incorrect destruction behavior; during the destruction process, there is a lack of a secure execution environment, making it difficult to prevent sensitive data from being leaked through potential backdoors of the device at the moment before destruction. Since the existing method completely relies on the sensor data reported by the device for the verification of the destruction process, the data itself may be tampered with or forged, resulting in insufficient credibility of the generated audit log and destruction certificate, which further affects the security of the destruction operation.

[0003] In summary, the existing technology has the technical problem that due to incomplete trust chain and process verification black box, there is a risk of leakage of storage media before and after destruction, and the audit result is not reliable, which further affects the security of the destruction operation. SUMMARY

[0004] The purpose of the present application is to provide a multi-protection method and system for a storage medium destruction machine, to solve the technical problem in the prior art that due to incomplete trust chain and process verification black box, there is a risk of leakage of storage media before and after destruction, and the audit result is not reliable, which further affects the security of the destruction operation.

[0005] In order to achieve the above purpose, the present application provides a multi-protection method and system for a storage medium destruction machine.

[0006] In a first aspect, the application provides a multiple protection method for a storage medium destruction machine, which is implemented by a multiple protection system for a storage medium destruction machine, wherein the multiple protection method for the storage medium destruction machine comprises: after a storage medium enters a destruction cabin, reading unique identification information of the storage medium, verifying the unique identification information against a preset authorization database to generate a one-time destruction passcode; creating a dynamic safety zone in the destruction cabin according to the one-time destruction passcode, wherein a boundary of the dynamic safety zone is a dynamically adjusted boundary, and the dynamic safety zone is linked to start electromagnetic shielding and physical locking structures; performing operator identity confirmation, external authorization confirmation and storage medium state confirmation, and when the three confirmations are all passed, controlling the storage medium destruction machine to perform a destruction operation; activating a multi-source sensor to collect data of a storage medium destruction machine execution process, establishing multi-modal sensing data, wherein the multi-modal sensing data includes residual fragment granularity data, electromagnetic erasure depth data, energy consumption data and running state data of the storage medium destruction machine; sending the multi-modal sensing data to an abnormality authentication channel to perform abnormality authentication of the destruction process, and establishing a destruction encryption digest; and performing multiple protection of the destruction according to the destruction encryption digest, the one-time destruction passcode and the multi-modal sensing data.

[0007] Optionally, a digital potentiometer array coupled with the electromagnetic erasing device is arranged in the destruction cabin, and the digital potentiometer array is used to dynamically adjust a current intensity of electromagnetic erasing based on a security parameter generation result of the one-time destruction passcode, wherein each digital potentiometer corresponds to an independent erasing channel, and the dynamic adjustment of the current intensity of electromagnetic erasing includes digital programmable control of a rising slope, a peak amplitude and a maintenance time of the erasing current.

[0008] Optionally, the boundary adjustment of the dynamic safety zone is driven by multi-dimensional sensing input, including temperature gradient, electromagnetic field intensity and mechanical vibration signal, and the boundary dynamic reconstruction is performed according to real-time changes of the multi-dimensional sensing input to adjust the electromagnetic shielding intensity and the locking delay, so as to perform dynamic isolation control of an internal space of the destruction cabin.

[0009] Optionally, a joint confidence calculation unit is configured, and the joint confidence calculation unit is used to dynamically calculate a comprehensive confidence score based on historical credibility, verification time interval and communication delay of each authentication source; when the comprehensive confidence score is lower than a preset score threshold, a safety interruption is triggered, and the one-time destruction passcode is frozen.

[0010] Optionally, the multi-modal sensing data is subjected to timing synchronization, denoising and frame processing in a trusted execution environment within the abnormal authentication channel, a granularity distribution spectrum is extracted from the residual fragment granularity data, a frequency spectrum energy density curve is extracted from the electromagnetic erasing depth data, a potential power pulse feature is extracted from the energy consumption data, a mechanical vibration mode and a motor driving current feature are extracted from the running state data, and the extracted results are subjected to normalization and dimensionless processing; the processed extracted results are synchronized to three-layer verification sub-channels in the abnormal authentication channel, single-modal abnormal scores of each layer of the verification sub-channels are weighted and fused to establish an overall abnormal score; and the abnormal authentication is completed according to the overall abnormal score.

[0011] Optionally, the processed extracted results are synchronized to a first layer of verification sub-channels, the first layer of verification sub-channels is a rule sub-channel based on residual and threshold statistics, and a first single-modal abnormal score is output; the processed extracted results are synchronized to a second layer of verification sub-channels, the second layer of verification sub-channels is a time series anomaly detection sub-channel based on a sliding window, and a second single-modal abnormal score is output; the processed extracted results are synchronized to a third layer of verification sub-channels, the third layer of verification sub-channels is a multi-modal reconstruction sub-channel based on deep learning, and a third single-modal abnormal score is output; and the first single-modal abnormal score, the second single-modal abnormal score and the third single-modal abnormal score are weighted and fused to establish an overall abnormal score.

[0012] Optionally, a multi-modal feature vector set in a normal destruction state of the same type of medium is subjected to offline statistical modeling, and a baseline mean value is constructed for each modal vector; an element-by-element difference operation is performed on the baseline mean value and the extracted results by the rule sub-channel to calculate a residual vector, the residual vector is subjected to Mahalanobis distance normalization processing according to a covariance matrix, and a Mahalanobis residual value is output as a unified residual quantity; and a threshold determination is performed according to the unified residual quantity, and a first single-modal abnormal score is output.

[0013] Optionally, at least two window lengths of sliding windows are established, and the processed extracted results are subjected to overlapping sliding processing of the sliding windows; a group of time series statistics and frequency domain features are calculated in each sliding window, the time series statistics include mean, variance, kurtosis and skewness, and the frequency domain features include main frequency power density, frequency spectrum energy concentration degree and bandwidth expansion coefficient; a dual-domain joint change model is established according to the time series statistics and the frequency domain features, change point detection is performed through a difference matrix and a correlation coefficient matrix of adjacent frames between the windows, and an initial drift area is established; the initial drift area is subjected to dynamic threshold correction and confidence interval determination, and a drift recognition result is output; the drift recognition result is subjected to time series mapping of a corresponding window index, a time series drift spectrum is established, and a second single-modal abnormal score is output according to the time series drift spectrum.

[0014] Optionally, the third layer verification sub-channel comprises a self-supervised reconstruction neural network, the reconstruction neural network is composed of a multi-channel modal encoder, a fusion bottleneck layer and a joint decoder, each channel of the multi-channel modal encoder corresponds to a sensor stream, the encoder is constructed based on a one-dimensional / two-dimensional convolution network, the fusion bottleneck layer performs feature interaction fusion based on a cross-modal attention mechanism, and the joint decoder is used to perform reconstruction of the modal data.

[0015] In a second aspect, the present application also provides a multiple protection system for a storage medium destruction machine, for executing the multiple protection method for a storage medium destruction machine as described in the first aspect, wherein the multiple protection system for the storage medium destruction machine comprises: a comparison verification module, configured to read unique identification information of a storage medium after the storage medium enters a destruction cabin, to perform comparison verification of the unique identification information with a preset authorization database, and to generate a one-time destruction password; a safety zone determination module, configured to create a dynamic safety zone in the destruction cabin according to the one-time destruction password, wherein the boundary of the dynamic safety zone is a dynamically adjusted boundary, and the electromagnetic shielding and the physical locking structure are started in linkage; a three-way authentication module, configured to perform operator identity confirmation, external authorization confirmation and storage medium state confirmation, and to control the storage medium destruction machine to perform a destruction operation when the three-way authentication passes; a data acquisition module, configured to activate a multi-source sensor to perform data acquisition of a storage medium destruction machine execution process, to establish multi-modal sensing data, and to perform storage medium destruction machine operation state data, wherein the multi-modal sensing data comprises residual fragment granularity data, electromagnetic erasure depth data, energy consumption data, and the like; an anomaly authentication module, configured to send the multi-modal sensing data to an anomaly authentication channel, to perform anomaly authentication of a destruction process, and to establish a destruction encryption digest; and a multiple protection module, configured to perform multiple protection of the destruction according to the destruction encryption digest, the one-time destruction password and the multi-modal sensing data.

[0016] One or more technical solutions provided in the present application have at least the following technical effects or advantages: By reading the unique identification information of the storage medium after the storage medium enters the destruction cabin, the one-time destruction password is generated by comparing and verifying the unique identification information with the preset authorization database; a dynamic security zone is created in the destruction cabin according to the one-time destruction password, the boundary of the dynamic security zone is a dynamically adjusted boundary, and the electromagnetic shielding and the physical locking structure are started in linkage; the operator identity confirmation, the external authorization confirmation and the storage medium state confirmation are performed, and when the three authentications are passed, the storage medium destruction machine is controlled to perform the destruction operation; the multi-source sensor is activated to collect data of the execution process of the storage medium destruction machine, multi-modal sensing data is established, the multi-modal sensing data includes residual fragment granularity data, electromagnetic erasing depth data, energy consumption data and running state data of the storage medium destruction machine; the multi-modal sensing data is sent to an abnormality authentication channel to perform abnormality authentication of the destruction process, and a destruction encryption digest is established; and the destruction is protected in multiple ways according to the destruction encryption digest, the one-time destruction password and the multi-modal sensing data. That is, by reading the unique identification information of the storage medium and comparing it with the preset authorization database, a one-time destruction password is generated, a dynamic security zone is created, and the electromagnetic shielding and the physical locking structure are started in linkage to strengthen the protection of the storage medium. By implementing three authentications and activating the multi-source sensor to collect data of the destruction process, a destruction encryption digest is generated, and the destruction is protected in multiple ways in combination with the one-time destruction password and the multi-modal sensing data, ensuring complete records and non-tamperability of each destruction operation and further improving the security and reliability of the destruction process.

[0017] The above description is only a summary of the technical solutions of the present application. In order to more clearly understand the technical means of the present application, the specific embodiments of the present application can be implemented in accordance with the content of the specification, and in order to make the above and other purposes, features and advantages of the present application more obvious and easy to understand, the following specific embodiments of the present application are described. It should be understood that the content described in this part is not intended to identify the key or important features of the embodiments of the present application, nor is it intended to limit the scope of the present application. Other features of the present application will become apparent from the following description. BRIEF DESCRIPTION OF DRAWINGS

[0018] In order to more clearly illustrate the technical solutions in the present application or the prior art, the following will briefly introduce the drawings needed to be used in the embodiments or the prior art description. Obviously, the drawings in the following description are only exemplary, and other drawings can be obtained by the provided drawings without creative labor for those skilled in the art.

[0019] Figure 1 The flowchart of the multiple protection method for the storage medium destruction machine of the present application.

[0020] Figure 2Structure diagram of the multiple protection system for the storage medium destruction machine.

[0021] Legend: comparison verification module 11, security zone determination module 12, three-factor authentication module 13, data acquisition module 14, abnormal authentication module 15, multiple protection module 16. DETAILED DESCRIPTION

[0022] The present application provides a multiple protection method and system for a storage medium destruction machine, which solves the technical problem in the prior art that due to incomplete trust chain and black-box process verification, there is a risk of leakage of the storage medium before and after destruction, and the audit result is not trustworthy, which further affects the safety of the destruction operation. By reading the unique identification information of the storage medium and comparing it with the preset authorized database, a one-time destruction password is generated, a dynamic security zone is created and the electromagnetic shielding and physical locking structure are started in linkage, the protection of the storage medium is strengthened, three-factor authentication is implemented and multiple source sensors are activated to collect data during the destruction process, a destruction encryption digest is generated, and the multiple protection of the destruction is performed in combination with the one-time destruction password and multi-modal sensing data, which ensures complete recording and tamper-proof of each destruction operation, and further improves the safety and reliability of the destruction process.

[0023] Hereinafter, the technical solutions in the present application will be described clearly and completely with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments of the present application. It should be understood that the present application is not limited by the example embodiments described herein. Based on the embodiments of the present application, all other embodiments obtained by a person of ordinary skill in the art without creative work fall within the scope of protection of the present application. In addition, it should be noted that, for convenience of description, only parts related to the present application are shown in the drawings, rather than all parts.

[0024] Embodiment one, please refer to the accompanying Figure 1 The present application provides a multiple protection method for a storage medium destruction machine, wherein the multiple protection method for the storage medium destruction machine is implemented by a multiple protection system for the storage medium destruction machine, and the multiple protection method for the storage medium destruction machine specifically includes the following steps: After the storage medium enters the destruction cabin, the unique identification information of the storage medium is read, the unique identification information is compared with a preset authorized database for verification, and a one-time destruction password is generated.

[0025] Further, the application also includes the following steps: the destruction cabin is provided with a digital potentiometer array coupled with the electromagnetic erasing device, the digital potentiometer array is used for dynamically adjusting the current intensity of electromagnetic erasing based on the security parameter generation result of one-time destruction of the pass code, wherein each digital potentiometer corresponds to an independent erasing channel, and the dynamically adjusting the current intensity of electromagnetic erasing includes digitally programmable control of the rising slope, peak amplitude and maintenance time of the erasing current.

[0026] Specifically, the storage medium destruction machine is an industrial-grade physical destruction equipment specially designed for scenarios that require high security processing of scrap storage media. The main function is to completely destroy various storage media to a physical state that cannot be recovered through powerful mechanical crushing capacity, ensuring that sensitive data stored therein will not be leaked. The storage medium destruction machine is equipped with a high-power reduction motor with super crushing capacity; has a cutter made of special alloy steel to ensure firm grip on the objects to be crushed, doubling the crushing capacity of the machine and improving work efficiency. The crushed debris falls directly into the oversized waste bucket from the cutter group, and the waste bucket is equipped with rollers that can be easily pushed to the waste storage area to empty the waste bucket, facilitating handling and reducing the labor intensity of operators. Mechanical and electrical equipment have multiple intelligent protection, including main motor start protection, motor stuck overload, automatic reverse, emergency stop, door opening stop and other protections to ensure stable operation of the equipment itself and prevent fault expansion. The storage medium destruction machine is equipped with an emergency stop button and a door opening stop function. Once the hopper cover is opened, the equipment will immediately stop working, effectively preventing personal injury accidents. The power supply is well grounded, and the electrical control cabinet maintenance needs to be operated by professional personnel with power off, and is equipped with overload protection.

[0027] The storage medium destruction machine can handle a wide range of storage media, including mechanical hard drives, video tapes, magnetic tapes, magnetic cards, solid state drives, USB drives, memory cards, chips, mobile phones, tablets, circuit boards, optical discs and other types of magnetic, semiconductor and optical media. The hard drive crushing blade of the storage medium destruction machine is 25-30mm wide, and the crushing capacity is: hard drive 90kg / h, other storage media 50-70kg / h, power 2.5-3kW, voltage 220V / 380V.

[0028] The storage medium destruction machine includes a power and transmission system, a crushing system, a feeding and collecting system, a support and appearance structure, a control and safety system, etc. Among them, the power and transmission system is responsible for providing and transmitting the huge torque required for crushing, including motor, speed reducer, belt pulley and belt, etc.; the crushing system is the execution mechanism, including knife box, driving knife shaft and driven knife shaft, crushing blade (hard disk crushing blade and U disk crushing blade), comb tooth, isolation sleeve (hard disk isolation sleeve and U disk isolation sleeve), wallboard and end cover; the feeding and collecting system includes a flip hopper and a 65L waste collecting box. The flip hopper is equipped with a safety interlock switch. When the cover is opened, the equipment will stop running immediately. The waste collecting box is provided with a roller for easy pulling out after crushing.

[0029] When the storage medium is sent into the destruction cabin, it is scanned and verified. The storage medium is a physical device for storing data that needs to be destroyed, such as mechanical hard disk, video tape, magnetic tape, magnetic card, solid state disk, U disk, memory card, chip, mobile phone, PAD, circuit board, optical disc and other types of magnetic medium, semiconductor medium and optical medium, etc. The scanner in the destruction cabin will start immediately to read the unique identification information of the storage medium, for example, the serial number of a hard disk WDC-WX12A1234567. The unique identification information is unique identification data of each storage medium, including device serial number, manufacturer information, model, production date, MAC address, electronic tag, etc.

[0030] The preset authorization database is a pre-established and maintained database, which records the list of all authorized storage media to be destroyed. Each record contains at least the unique identification information of the storage medium, the destruction task metadata associated with it, such as the destruction reason, the authorized person, the required security level, etc. The destruction cabin initiates a query request containing unique identification information to the preset authorization database. After receiving the request, the preset authorization database searches the unique identification information in its to-be-destroyed task list. If the preset authorization database finds a matching record and the status of the record is authorized, the preset authorization database returns a verification passed signal to the destruction cabin, and attaches the security parameters of the task, such as the required destruction standard. At the same time, a one-time destruction passcode is generated, including timestamp, task ID and digital signature. The one-time destruction passcode is a digital token generated, which has the characteristics of uniqueness, timeliness and one-time use. For example, the one-time destruction passcode is ABC12345XYZ, which is only valid for the current destruction process and cannot be reused.

[0031] If the unique identification information is not found in the preset authorization database, or the task state corresponding to the unique identification information is canceled / completed, the process will be terminated immediately, an alarm will be issued, and the destruction cabin will be kept closed, and the unauthorized attempt will be recorded in the security log, ensuring that only the medium that has passed strict approval can enter the subsequent physical destruction link.

[0032] The destruction cabin is the core working cavity of the storage medium destruction machine, which is a closed space with physical isolation and electromagnetic shielding functions. The digital potentiometer array coupled with the electromagnetic erasing device is arranged in the destruction cabin. The electromagnetic erasing device is a device that generates a high-strength alternating magnetic field to cause the magnetic domain orientation of the magnetic storage medium to be chaotic, thereby irreversibly erasing data, achieving interference and erasing effect on medium data; the digital potentiometer array is a set of electronic components whose resistance values are accurately controlled by digital signals. Each independent erasing channel corresponds to a digital potentiometer, and according to the security parameter generation result of the one-time destruction password, the resistance value of the digital potentiometer is changed to accurately control the current intensity of the electromagnetic erasing. The rising slope, peak amplitude and maintenance time of the current are programmed and controlled, wherein the rising slope is the rate at which the current intensity increases within a certain time to avoid damage to the equipment caused by current impact; the peak amplitude is the maximum value of the current to ensure that the magnetic field strength is sufficient to completely demagnetize; the maintenance time is the duration for which the current is maintained at the peak amplitude to ensure that the magnetic domain has sufficient time to fully randomize. According to the security parameters provided by the one-time destruction password, the digital potentiometer array dynamically adjusts the three key parameters of the current, i.e. the rising slope, the peak amplitude and the maintenance time. Through digital programmable control, the digital potentiometer array can dynamically adjust the above parameters in real time, accurately control the current intensity of each channel, and ensure optimal electromagnetic erasing according to the type of storage medium and specific destruction requirements.

[0033] By comparing the unique identification information of the storage medium with the preset authorization database, it is ensured that only authorized storage media can enter the destruction process, avoiding the destruction of illegal or unauthorized media. The one-time destruction password ensures that the destruction process of each storage medium is unique and cannot be reused, reducing the risk of data leakage and ensuring the safety of the destruction operation.

[0034] According to the one-time destruction password, a dynamic security zone is created in the destruction cabin, the boundary of the dynamic security zone is a dynamically adjusted boundary, and the electromagnetic shielding and the physical locking structure are started in linkage.

[0035] Further, the application further includes the following steps: the boundary adjustment of the dynamic security zone is driven by multi-dimensional sensing input, including temperature gradient, electromagnetic field strength and mechanical vibration signal, and the boundary is dynamically reconstructed according to the real-time change of the multi-dimensional sensing input, the electromagnetic shielding strength and the locking delay are adjusted, and the dynamic isolation control of the internal space of the destruction cabin is performed.

[0036] Specifically, according to the security level of one-time destruction of the access code, a dynamic security zone is created in the destruction cabin, that is, a virtual security protection area established inside the destruction cabin with a flexible changing boundary, and the protection strength and security parameters can be dynamically adjusted according to real-time risks. During the destruction process, the boundary of the dynamic security zone is not fixed, but is adjusted in real time according to multi-dimensional data from different sensors. According to the temperature gradient, electromagnetic field strength and mechanical vibration signal, the safety isolation in the destruction cabin is dynamically controlled by adjusting the electromagnetic shielding strength and the lock delay. For example, when the external vibration signal is too strong, the lock delay can be set to 10 seconds to ensure that the inside of the device is not affected by external impact, further strengthening the non-interference of the destruction process. Real-time monitoring of multi-dimensional data will drive the boundary adjustment of the dynamic security zone. If the external electromagnetic interference increases, the range of the electromagnetic shielding zone will be automatically expanded according to the electromagnetic field strength to ensure effective isolation between the inside and outside of the destruction cabin.

[0037] The multi-dimensional sensing input includes temperature gradient, electromagnetic field strength and mechanical vibration signal. According to the real-time changes of the multi-dimensional sensing input, the boundary is dynamically reconstructed, and the range, shielding strength and other parameters of the security zone are recalculated and set. For example, when it is detected that the temperature at the upper right corner of the destruction cabin rises sharply by 40°C within 3 seconds, indicating that the device is short-circuited and on fire, boundary reconstruction is immediately performed: the high-temperature area is marked as a high-risk core area, the electromagnetic shielding strength around it within a range of 20 cm is increased from the basic 60 dB to 90 dB, and the delay of all physical locks is extended from the standard 30 seconds to 300 seconds, so that even if someone presses the emergency door button at this time, it will not be unlocked, thereby achieving heat source isolation. Similarly, if an abnormal 1.2 GHz high-intensity pulse signal is detected inside the cabin, which may come from an implanted wireless transmission device, the electromagnetic shielding strength of the entire cabin is immediately increased to the highest 120 dB, and a safety event alarm is generated.

[0038] The electromagnetic shielding and physical locking structure are started in linkage. The electromagnetic shielding is a closed body made of conductive or magnetically conductive material, which is used to block the leakage of electromagnetic signals inside the destruction cabin to prevent data from being remotely stolen before destruction. The physical locking structure is a mechanical locking device such as the destruction cabin door and internal isolation baffle, which ensures that it cannot be opened unauthorized during critical operations. By creating a dynamic security zone driven by multi-dimensional sensing, the security protection is upgraded from a static mode of one-size-fits-all to a dynamic mode of precise response based on real-time risk situation, greatly improving the intelligent level of the security boundary.

[0039] The operator identity confirmation, external authorization confirmation and storage medium state confirmation are performed, and when the three confirmations are passed, the storage medium destruction machine is controlled to perform the destruction operation.

[0040] Further, the application also includes the following steps: configuring a joint confidence calculation unit, using the joint confidence calculation unit to dynamically calculate a comprehensive confidence score based on the historical credibility of each authentication source, the verification time interval, and the communication delay; when the comprehensive confidence score is lower than a preset score threshold, triggering a security interruption and freezing the one-time destruction of the passcode.

[0041] Specifically, in the destruction operation, triple authentication is required, including operator identity confirmation, external authorization confirmation, and storage medium state confirmation. Operator identity confirmation refers to the verification process of the operator's identity before the storage medium destruction operation is performed, which is completed through login credentials, fingerprint recognition, facial recognition, or other identity verification technologies, ensuring that only authorized personnel can perform the destruction operation. For example, the operator enters a password or confirms identity through a biometric identification device. If identity confirmation fails, the destruction operation will not be performed. External authorization confirmation refers to the confirmation of external authorization for the storage medium destruction operation, such as interfacing with a company's permission management system or a specialized authentication center to verify whether the destruction operation of the storage medium is authorized. Storage medium state confirmation is the verification of the state of the storage medium itself, ensuring that it is physically in place, the model matches the task, and ensuring that the medium is in an appropriate state before the destruction operation, such as no faults, meets the destruction conditions, etc.

[0042] When the operator selects to perform the destruction at the console, three confirmation requests are initiated in parallel: operator identity confirmation, external authorization confirmation, and storage medium state confirmation. Only when all three authentications pass, ensuring that each link of the destruction operation meets the safety and legality requirements, can the storage medium destruction machine perform the destruction operation. If any one of the confirmation processes fails, the destruction operation will not be continued.

[0043] Meanwhile, the joint confidence calculation unit is activated to receive real-time metadata from the three authentication sources, obtain the historical trustworthiness, verification time interval, communication delay, etc. of each authentication source, and dynamically calculate the comprehensive confidence score. The historical trustworthiness is based on the success and failure records of a certain authentication source in the past period of time, and the reliability weight assigned to it. The verification time interval is the time interval of the authentication process. The communication delay is the time from sending a request to receiving a response in authentication that requires external communication. For example, assuming that a potential attack is detected through an abnormally long verification time, a simulated attack scenario, an operator uses a highly simulated fingerprint film for identity verification, and at the same time, a delay is injected on the network link to simulate a man-in-the-middle attack. It is recorded that the total verification time of the operator's fingerprint is 4.8 seconds, and the normal baseline is 1.2±0.3 seconds. Based on this abnormally long verification time interval, the joint confidence unit reduces the weight of the operator's identity confirmation from the base 0.95 to 0.55; an external authorization request is sent, but due to the simulated network attack, the communication delay reaches 18 seconds, which is normally <3 seconds, and the weight of the external authorization confirmation is reduced from 0.98 to 0.2; the storage medium state confirmation is normal, the time consumption is 0.9 seconds, and the weight is 1.0; assuming that the weights of the operator identity confirmation, external authorization confirmation and storage medium state confirmation are 0.3, 0.5 and 0.2 respectively, then the joint confidence calculation unit performs operation to obtain the comprehensive confidence score as 0.55*0.3+0.2*0.5+1*0.2=0.465, i.e. 46.5 points.

[0044] When the comprehensive confidence score is lower than the preset score threshold, a security interruption is triggered, and the one-time destruction of the passcode is frozen. The preset score threshold is a predefined trustworthiness score value. Only when the comprehensive confidence score is higher than the preset score threshold, the destruction operation is allowed to continue. If it is lower than the preset score threshold, it is judged that the current authentication result is not trustworthy, thereby triggering a security interruption. For example, assuming that the preset score threshold is 0.85, i.e. 85 points, and the comprehensive confidence score 0.465 in the foregoing is far lower than the preset score threshold, a security interruption is triggered immediately, the passcode is frozen, and an alarm is given. The security team confirms the abnormal time consumption of identity verification and network delay in the log afterwards, successfully prevents this potential security breach, and indicates that the main reason for the low confidence score is the timeout of identity verification and external authorization response. Through triple authentication and comprehensive confidence calculation, it is ensured that each link of verification is fully confirmed, and illegal or unauthorized destruction operation is avoided.

[0045] The multi-source sensors are activated to perform data collection of the storage medium destruction machine execution process, and multi-modal sensor data is established, which includes residual fragment granularity data, electromagnetic erasure depth data, energy consumption data, and running state data of the storage medium destruction machine.

[0046] Specifically, the multi-source sensor is activated, and full-dimensional process monitoring is started. The multi-source sensor is a plurality of different types of sensors capable of simultaneously collecting different types of environmental or operating data during the destruction of the storage medium, obtaining multi-modal sensor data, including residual fragment size data, electromagnetic erasure depth data, energy consumption data, and storage medium destruction machine operating state data. The residual fragment size data is the data of the size distribution of the medium fragments after physical crushing, which is usually obtained through a visual sensor or a laser scanner; the electromagnetic erasure depth data is the data of the residual magnetic field strength of the magnetic medium after demagnetization processing, reflecting the thoroughness of the logical erasure of the data; the energy consumption data is the data of the motor driving power, current and other parameters changing with time during the destruction process, reflecting the load state of the storage medium destruction machine; the operating state data includes vibration spectrum, bearing temperature, rotating speed and other data reflecting the mechanical state of the destruction machine itself.

[0047] For example, a high-frequency industrial camera located at the discharge port analyzes the projection size of the fragments in real time at a sampling rate of 2000 frames / second, generates a residual fragment size distribution curve, and counts that 96% of the fragments pass through a 2mm x 2mm screen at 1.5 seconds after the start of the destruction, and the particle size distribution meets the second level standard; a Hall effect sensor array close to the demagnetization assembly monitors the magnetic field change at a sampling rate of 100kHz, calculates the ratio of the residual magnetic field strength to the initial strength, and outputs the electromagnetic erasure depth percentage; within 0.1 seconds after the demagnetization pulse is applied, the magnetic field strength on the surface of the disc decreases from the initial 120kA / m to 0.45kA / m, and the erasure depth reaches 99.63%; an integrated power quality analyzer accurately captures energy consumption data, including transient power and cumulative energy consumption, at a sampling rate of 10kHz; the power peak of the main shaft motor is 3.8kW at the moment of crushing, and the total energy consumption is 48kJ during the entire 15-second destruction period; vibration sensors and infrared temperature sensors installed on the main shaft and bearing seat collect mechanical vibration spectrum and temperature rise data at sampling rates of 50kHz and 10Hz, respectively; the main shaft appears a characteristic vibration at 1850Hz, and the amplitude is within the safe range <5m / s 2 ; the temperature sensor shows that the maximum bearing temperature is 67℃, which is lower than the alarm threshold of 85℃. All sensor data are synchronized at the microsecond level through the PTP precise clock protocol. Analysis shows that the peak of energy consumption is completely consistent in time with the most intensive crushing stage, and the appearance of the vibration characteristic peak accurately corresponds to the moment when a particularly solid disc assembly is crushed, proving that there is good causal correlation between multi-modal data.

[0048] The originally black-box destruction process is converted into a series of measurable and analyzable objective physical parameters, providing accurate data support for destruction effect evaluation. The synchronization of multi-modal data in the time dimension and the complementarity in the physical dimension constitute a complete evidence package describing a destruction event, greatly enhancing the credibility and non-repudiation of the audit results.

[0049] sending the multi-modal sensor data to an anomaly authentication channel, performing anomaly authentication of the destruction process, and establishing a destruction encryption digest.

[0050] Further, the present application further comprises the following steps: performing timing synchronization, denoising and frame processing on the multi-modal sensor data in the trusted execution environment in the anomaly authentication channel, extracting granularity distribution spectrum from the residual granularity data, extracting frequency spectrum energy density curve from the electromagnetic erasing depth data, extracting potential power pulse features from the energy consumption data, extracting mechanical vibration mode and motor driving current features from the running state data, normalizing and dimensionless processing the extracted results; synchronizing the processed extracted results to three-layer verification sub-channels in the anomaly authentication channel, weighting and fusing the single-modal anomaly scores of each layer of the verification sub-channels to establish an overall anomaly score; and completing anomaly authentication according to the overall anomaly score.

[0051] Specifically, the multi-modal sensor data is sent to the anomaly authentication channel for anomaly authentication. The data of different types of sensors may have a time deviation when collected. In order to ensure data consistency, these data need to be first timing synchronized. The electromagnetic erasing depth data, energy consumption data, residual granularity and other data can be accurately corresponded on the same time axis. In the data collection process, the original data often contains noise or outliers, which must be removed by denoising to remove irrelevant interference signals and ensure the reliability of the data. After denoising, the data will be frame processed, and each frame of data will become the basic unit of analysis, facilitating subsequent feature extraction and modeling.

[0052] The size distribution spectrum of the fragments, i.e. a continuous curve describing the distribution of the fragment sizes, with the abscissa representing the fragment size and the ordinate representing the percentage of fragments of the corresponding size, shows the size distribution of the fragments after destruction, ensuring that the destruction meets the predetermined particle size standard, i.e. the fragments after shredding should be in the range of 25-30 mm. If the particle size is larger, it means that the shredding process is not fully completed and the efficiency of the shredding equipment needs to be improved. The frequency spectrum energy density curve is extracted from the electromagnetic erasing depth data, the electromagnetic erasing depth data is subjected to fast Fourier transform, and the frequency spectrum energy density curve of the 0-10 kHz frequency band is extracted to analyze the effect of electromagnetic erasing and confirm whether the standard of complete data elimination is met. Generally, an electromagnetic field intensity of 40 V / m and above is considered sufficient to eliminate data in storage media. The characteristic of the inductive power pulse is extracted from the energy consumption data. The characteristic of the inductive power pulse is the transient characteristic of the power change with time, including parameters such as rise time, peak value, and fall time. The mechanical vibration mode and the motor driving current characteristic are extracted from the running state data. The mechanical vibration mode is the vibration characteristic during the execution of the destruction operation, and the motor driving current characteristic is a feature extracted from the motor driving current data, including the total harmonic distortion rate and each harmonic component. All the extracted characteristic parameters are normalized to convert them into dimensionless values in the range of [0, 1].

[0053] For example, assume that the visual sampling rate of the fragment size is set to 2000 frames / s, the sampling rate of the electromagnetic sensor is 100 kHz, the sampling rate of the power sensor is 10 kHz, and the sampling rate of the vibration sensor is 50 kHz. The size distribution spectrum shows that D10=1.2 mm, D50=2.1 mm, and D90=3.8 mm, and the distribution curve has a normal distribution characteristic; during the demagnetization process, the 50 Hz power frequency and its harmonics of the frequency spectrum energy density curve have obvious peak values, and the fundamental wave energy density reaches -25 dB / Hz; the inductive power pulse characteristic detects 3 main power pulses with peak values of 3.2 kW, 3.5 kW, and 3.1 kW, and rise times of 45 ms, 52 ms, and 48 ms; the mechanical vibration mode shows that the main vibration component amplitude is 4.8 m / s 2 at 1850 Hz and the secondary component amplitude is 2.1 m / s 2The motor driving current features include a total harmonic distortion of 7.2%, a third harmonic content of 3.8%, and a fifth harmonic content of 2.1%. After normalization and dimensionless processing, the particle size parameters are D10 of 0.12, D50 of 0.21, and D90 of 0.38, the fundamental energy density of the spectral energy density curve is 0.5, the power peak values of the power impulse features are 0.64, 0.70, and 0.62, the rise times are 0.42, 0.52, and 0.48, the main vibration component amplitudes of the mechanical vibration mode are 0.48 and 0.21, and the total harmonic distortion of the motor driving current features is 0.072, the third harmonic content is 0.038, and the fifth harmonic content is 0.021.

[0054] The processed extraction result is synchronously distributed to three layers of verification sub-channels. Each sub-channel independently calculates an abnormal score based on different algorithm principles. Finally, the overall abnormal score is obtained by weighted fusion. The overall abnormal score reflects the abnormality degree in the destruction process and is used to finally determine whether the destruction operation meets the safety and quality standards. According to the result of the overall abnormal score, the abnormality authentication is completed. If the score is higher than the preset threshold, it means that an abnormality occurs in the destruction process, and an alarm is started or the destruction operation is stopped. If the score is qualified, the destruction process continues to be executed.

[0055] Further, the application further includes the following steps: synchronizing the processed extraction result to the first layer verification sub-channel, the first layer verification sub-channel being a rule sub-channel based on residual error and threshold statistics, and outputting a first single-modal abnormal score; synchronizing the processed extraction result to the second layer verification sub-channel, the second layer verification sub-channel being a time series anomaly detection sub-channel based on a sliding window, and outputting a second single-modal abnormal score; synchronizing the processed extraction result to the third layer verification sub-channel, the third layer verification sub-channel being a multi-modal reconstruction sub-channel based on deep learning, and outputting a third single-modal abnormal score; and performing weighted fusion according to the first single-modal abnormal score, the second single-modal abnormal score, and the third single-modal abnormal score to establish an overall abnormal score.

[0056] Further, the application further includes the following steps: performing offline statistical modeling according to the multi-modal feature vector set in the normal destruction state of the same type of medium, and constructing a baseline mean value for each modal vector; performing element-by-element difference operation based on the baseline mean value and the extraction result by using the rule sub-channel, calculating a residual error vector, performing Mahalanobis distance normalization processing on the residual error vector according to a covariance matrix, and outputting a Mahalanobis residual value as a unified residual amount; and performing threshold determination according to the unified residual amount, and outputting a first single-modal abnormal score.

[0057] Further, the application further comprises the following steps: establishing at least two sliding windows of window length, performing overlapping sliding processing of the sliding windows on the processed extraction results; calculating a set of time series statistics and frequency domain features in each sliding window, the time series statistics including mean, variance, kurtosis and skewness, and the frequency domain features including dominant frequency power density, spectral energy concentration and bandwidth expansion coefficient; establishing a dual-domain joint change model according to the time series statistics and the frequency domain features, performing change point detection through a difference matrix and a correlation coefficient matrix of adjacent frames between windows to establish an initial drift region; performing dynamic threshold correction and confidence interval judgment on the initial drift region to output a drift recognition result; performing time series mapping of the drift recognition result corresponding to the window index to establish a time series drift spectrum, and outputting a second single-modal anomaly score according to the time series drift spectrum.

[0058] Further, the application further comprises the following steps: the third layer verification sub-channel comprises a self-supervised reconstruction neural network, the reconstruction neural network is composed of a multi-path modal encoder, a fusion bottleneck layer and a joint decoder, each path of the multi-path modal encoder corresponds to one sensor stream, the encoder is constructed based on a one-dimensional / two-dimensional convolutional network, the fusion bottleneck layer performs feature interaction fusion based on a cross-modal attention mechanism, and the joint decoder is used to perform reconstruction of the modal data.

[0059] Specifically, the processed extraction results are synchronized to the first layer verification sub-channel, the first layer verification sub-channel is the first layer of the three-layer verification sub-channel, a rule-based method is used to output an anomaly score by calculating the residual of real-time data and historical baseline and performing statistical threshold judgment. In the offline stage, a large amount of multi-modal feature vector data of the same type of medium in the normal destruction state is collected, such as extracting the features of granularity, power and vibration from 100 normal destructions, and calculating the baseline mean vector and covariance matrix of each feature, such as D50 mean = 0.20, power peak mean = 0.65, and vibration amplitude mean = 0.45.

[0060] The multi-modal feature vector set is a vector composed of multiple features extracted from multi-source sensor data, representing the comprehensive state of the destruction process. Offline statistical modeling is a statistical analysis using historical normal destruction data to establish a baseline model without involving real-time data. In offline modeling, the average value vector of each feature in the normal state is calculated as a baseline reference.

[0061] With the rule sub-channel, element-wise difference operation is performed between the baseline mean and the extracted results, i.e., the difference between the baseline mean and the extracted results of each modal vector is calculated to obtain a residual vector. Each modal vector will produce a residual value, which represents the deviation between the current operation and the normal state. The residual vector is processed by the covariance matrix for Mahalanobis distance normalization to standardize the data and eliminate the scale difference between the modes. Although the data magnitudes of different modes may be different, the normalized data can be directly compared. The normalized Mahalanobis residual value will be integrated into a unified residual quantity, which represents the overall degree of deviation of all modal data from the normal state.

[0062] Threshold determination is performed according to the unified residual quantity. If the unified residual quantity is lower than the threshold, the anomaly score is lower; if it exceeds the threshold, the score is higher. The score is usually normalized to the [0, 1] interval, where 0 represents normal and 1 represents severe anomaly. The first single-modal anomaly score is the anomaly score calculated in the first layer verification sub-channel, which is used to represent whether the input data conforms to the normal destruction process. If the score is higher, it means that there is a larger anomaly in the data. Illustratively, normal destruction data of 500 hard disks of the same model are collected, and multi-modal features are extracted, including normalized particle size D50, power peak, and vibration amplitude; the baseline mean vector μ = [0.20, 0.65, 0.45] is calculated; the covariance matrix [0.001, 0.0005, 0.0002], [0.0005, 0.002, 0.0003], and [0.0002, 0.0003, 0.0015] are calculated; based on the 99% confidence interval of historical data, the Mahalanobis distance threshold is 1.0. In a real-time destruction, the extracted feature vector is x = [0.21, 0.70, 0.48]; the residual vector is calculated as x - μ = [0.01, 0.05, 0.03], the inverse of the covariance matrix is first calculated, and then the Mahalanobis residual value is calculated as 0.85, i.e., the unified residual quantity = 0.85 < threshold 1.0, so the anomaly score is lower. According to linear mapping, the first single-modal anomaly score is 0.85. If the feature vector is [0.30, 0.80, 0.60], the residual vector is [0.10, 0.15, 0.15], the Mahalanobis distance is calculated as 2.5, which exceeds the threshold 1.0, and the anomaly score = 1.0, indicating possible tool wear or medium anomaly.

[0063] The second layer verification sub-channel is the second layer of the three-layer verification sub-channel, and focuses on detecting abnormal behaviors in time series data. At least two sliding windows of different lengths are established on the time series data, such as a 200 ms short window for capturing fast transients and a 1000 ms long window for detecting slow drifts, and the overlap rate is set to 50%. The short window and the long window can capture the local change and the overall trend of the data, respectively. The sliding window slides on the data with overlap, and each slide covers a different time period, ensuring that the characteristics of different time intervals are fully extracted. The sliding window is a fixed length time interval that slides on the time series data; the overlapping sliding processing is an analysis method that has time overlap between adjacent sliding windows, which improves the time resolution of detection.

[0064] In each sliding window, time domain and frequency domain features are calculated in parallel. In the time domain, mean, variance, kurtosis and skewness are calculated; in the frequency domain, main frequency power density, spectral energy concentration and bandwidth expansion coefficient are calculated by FFT transformation. The mean is the average value of the data in the window, the variance is a measure of the degree of data dispersion, the kurtosis is a statistical quantity of the sharpness of data distribution, and the skewness is a measure of the asymmetry of data distribution. The main frequency power density is the energy intensity of the main frequency component, the spectral energy concentration is the concentration degree of energy on a few frequencies, and the bandwidth expansion coefficient is a measure of the frequency distribution range of the signal.

[0065] According to the time series statistics and frequency domain features, a dual-domain joint change model is established, that is, the changes in the time domain and the frequency domain are comprehensively analyzed to capture the abnormalities that may not be identified in one domain. The dual-domain joint change model combines the characteristics of the time domain and the frequency domain to construct a comprehensive model to represent the change of the data, helping to capture the change rule of the data in two dimensions (time and frequency), so as to more accurately identify the abnormality.

[0066] Based on the dual-domain joint change model, change points are detected by calculating the difference matrix and correlation coefficient matrix between adjacent frames in the window. When the Frobenius norm of the difference matrix exceeds twice the baseline and the correlation coefficient changes by more than 0.3, it is marked as an initial drift region. Change point detection refers to identifying time points in the time series where statistical characteristics change significantly. A drift region is defined as a data deviation that occurs continuously over a period of time, usually exhibiting a continuous trend change. Dynamic threshold correction is applied to the initial drift region, adjusting the threshold based on the historical behavior of the current window to prevent the static threshold from being too rigid and unable to adapt to changes in different data. The confidence interval determination method is used to evaluate the confidence of the drift region. If the confidence interval is small, the confidence of the anomaly is considered high. For example, by combining the real-time process confidence to dynamically correct the initial drift region, only drift regions that last for more than 3 windows and have a confidence greater than 80% are retained, and the drift identification result is output. The drift identification result is mapped back to the time series of the corresponding window index to generate a time-series drift spectrum. The second single-modal anomaly score is calculated based on the density, duration, and intensity of the drift region in the spectrum. The second single-mode anomaly score is an anomaly score calculated based on the data processed by the second-layer verification sub-channel, and is used to represent the degree of anomaly in the data in terms of time-series and frequency-domain characteristics.

[0067] For example, a 5-minute hard drive destruction process was analyzed, comprising 30 consecutive destruction operations. The sliding window consisted of a short window of 200ms and a long window of 1000ms, with a 50% overlap. Monitoring characteristics included vibration frequency amplitude, power consumption, and shredding efficiency. During the normal phase (0-3 minutes), the vibration frequency amplitude stabilized at 4.2-4.5 m / s. 2 Power consumption remained between 3.2 and 3.4 kW; spectral energy concentration remained between 0.75 and 0.82; the difference matrix norm was between 0.05 and 0.12; and the correlation coefficient varied between 0.1 and 0.2. An anomaly appeared at 3 minutes and 20 seconds, with the amplitude of the dominant vibration frequency slowly increasing to 4.8 m / s². 2 Power consumption decreased to 2.9kW; spectral energy concentration decreased to 0.68; the difference matrix norm surged to 0.35, and the correlation coefficient changed to 0.45; an initial drift region was detected with a confidence level of 72%. An anomaly was confirmed between 3 minutes 40 seconds and 4 minutes 50 seconds, with the vibration amplitude continuously increasing to 5.5 m / s². 2 The power further decreased to 2.6kW; the spectral characteristics showed the emergence of new harmonic components; the drift region lasted for 8 long windows, with the confidence level increasing to 92%; the time-series drift spectrum showed obvious anomalous patterns. Based on a drift density of 0.35, a duration of 70 seconds, and an intensity index of 0.78, the second single-mode anomaly score was calculated to be 0.82.

[0068] The third verification sub-channel is the last layer of the three-layer verification sub-channel. It is the deep learning analysis layer in the anomaly authentication channel, employing a self-supervised learning approach to detect anomalies through reconstruction errors. A reconstructive neural network is pre-trained on a large amount of normally destroyed data, using an architecture of a multi-modal encoder, a fusion bottleneck layer, and a joint decoder. The multi-modal encoder is part of the reconstructive neural network, containing multiple independent encoding paths, each specifically processing a type of sensor data stream. The fusion bottleneck layer is the key layer in the reconstructive neural network, responsible for deep fusion and interaction of the encoded features from different modalities. The joint decoder is the output part of the reconstructive neural network, reconstructing the original input data of all modalities from the fused features. For example, the reconstructive neural network is configured as follows: the granular encoder includes 5 layers of 1D CNN with a kernel size of 5; the vibration encoder includes 4 layers of 2D CNN with a kernel size of 3×3; the power encoder includes 4 layers of 1D CNN with a kernel size of 7; the fusion bottleneck is 256-dimensional with an 8-head attention mechanism; the training cycle is 100 epochs, and the final reconstruction error is <0.05.

[0069] In a multi-channel modal encoder, each channel is designed for a specific sensor data stream: granular data uses a one-dimensional convolutional network to process the time series, vibration spectrum uses a two-dimensional convolutional network to process the time-frequency graph, and power data uses a one-dimensional convolutional network to process the waveform. Features extracted by each modal encoder enter the fusion bottleneck layer, employing a cross-modal attention mechanism to automatically calculate the correlation weights between features from different modes, achieving intelligent feature fusion. For example, when an abnormal power is detected, the attention mechanism strengthens the weight of vibration features to confirm whether it is a mechanical fault. The joint decoder attempts to accurately reconstruct the original input data of each mode from the fused bottleneck features. During the inference phase, the real-time data reconstruction error is calculated: Reconstruction Error = |Original Data - Reconstructed Data| 2 A larger error indicates a higher degree of anomaly. A dynamic threshold is set based on the statistical distribution of the reconstruction error, mapping the reconstruction error to anomaly scores in the [0,1] interval, where 0 represents perfect reconstruction (normal) and 1 represents severe reconstruction failure (abnormal). For example, with input features including granularity D50=0.21, vibration amplitude=0.48, and peak power=0.68, the reconstruction neural network outputs 0.20, 0.47, and 0.67, resulting in a reconstruction error of 0.003. Therefore, the third single-mode anomaly score is 0.15, within the normal range. With input features including granularity D50=0.35, vibration amplitude=0.62, and peak power=0.45, the network reconstruction outputs 0.22, 0.46, and 0.66. The network tends to reconstruct a normal mode, resulting in a reconstruction error of 0.186. Therefore, the third single-mode anomaly score is min(1,(0.186-0.005) / 0.002 / 100)=0.905.

[0070] The overall anomaly score is obtained by weighted fusion of the first, second, and third single-modal anomaly scores. Weights are assigned to the first, second, and third single-modal anomaly scores based on their importance in the overall detection, such as 0.2, 0.3, and 0.5 respectively. Therefore, the overall anomaly score = (first single-modal anomaly score * 0.2) + (second single-modal anomaly score * 0.3) + (third single-modal anomaly score * 0.5). For example, if the first single-modal anomaly score is 0.85, the second single-modal anomaly score is 0.82, and the third single-modal anomaly score is 0.905, the overall anomaly score is 0.8625, used to ultimately determine whether there is an anomaly in the storage medium destruction process. The overall anomaly score is significantly higher than the normal range threshold of 0.7, therefore, the destruction process is deemed abnormal, and appropriate intervention measures are required.

[0071] By employing a hierarchical structure, data is analyzed from different dimensions, with each layer focusing on different types of anomalies to comprehensively capture potential anomaly patterns. Anomaly scores from different levels are weighted and fused, and detection sensitivity is dynamically adjusted based on the importance of different verification channels to improve anomaly detection accuracy. The overall anomaly score provides a comprehensive assessment, helping to promptly identify anomalies during the data destruction process and ensuring the security and integrity of data destruction.

[0072] The system employs multiple protections for destruction, including the destruction encryption digest, one-time destruction passcode, and multimodal sensor data.

[0073] Specifically, the destruction cryptographic digest is a digital fingerprint generated based on multimodal sensor data and anomaly authentication results. Calculated using a cryptographic hash algorithm, it possesses the characteristics of being tamper-proof and unforgeable. The destruction cryptographic digest plays a crucial role in the data destruction process, ensuring traceability and tamper-proofness. By combining the destruction cryptographic digest, one-time destruction passcode, and multimodal sensor data, even if an attacker gains access to some destroyed data, any attempt to reproduce or tamper with the destruction process will be detected because each destruction process's passcode and cryptographic digest are unique. It is impossible to reconstruct the same cryptographic digest and destruction passcode, and all operations and data can be traced. Multiple protection mechanisms ensure that every step of the entire destruction process is monitored and verified. If an anomaly is detected at any stage, an alarm is immediately triggered and the operation is interrupted.

[0074] Employing a cryptographic hash algorithm, any modification to the destruction record is immediately detected, successfully defending against all attempts to tamper with audit logs in actual testing. Through digital signatures and timestamps, the destruction record possesses legally recognized evidentiary value and has been accepted as valid evidence in multiple compliance audits. By cryptographically binding destruction instructions, process data, and execution results, a complete traceability chain is established, allowing auditors to complete comprehensive verification of a single destruction in the shortest possible time, improving efficiency by 80%.

[0075] In summary, the multi-protection method for a storage medium destruction machine provided in this application has the following technical effects: After the storage medium enters the destruction chamber, its unique identification information is read, and compared with a preset authorization database to generate a one-time destruction pass code; a dynamic security zone is created within the destruction chamber based on the one-time destruction pass code, the boundary of which is dynamically adjustable, and electromagnetic shielding and physical locking structures are activated in conjunction; operator identity verification, external authorization verification, and storage medium status verification are performed, and when all three authentications are successful, the storage medium destruction machine is controlled to perform the destruction operation; multi-source sensors are activated to collect data during the storage medium destruction process, establishing multi-modal sensing data, including fragment granularity data, electromagnetic erasure depth data, energy consumption data, and the operating status data of the storage medium destruction machine; the multi-modal sensing data is sent to an abnormal authentication channel to perform abnormal authentication of the destruction process and establish a destruction encryption digest; and multiple protections for destruction are implemented based on the destruction encryption digest, the one-time destruction pass code, and the multi-modal sensing data. In other words, by reading the unique identification information of the storage medium and comparing it with the preset authorized database, a one-time destruction pass code is generated, a dynamic security zone is created, and electromagnetic shielding and physical locking structures are activated in conjunction, which strengthens the protection of the storage medium. By implementing triple authentication and activating multi-source sensors to collect data on the destruction process, a destruction encryption digest is generated. Combined with the one-time destruction pass code and multi-modal sensor data, multiple protections for destruction are provided to ensure the complete record and immutability of each destruction operation, further improving the security and reliability of the destruction process.

[0076] Example 2: Based on the same inventive concept as the multi-protection method for a storage media destruction machine in Example 1, this application also provides a multi-protection system for a storage media destruction machine. Please refer to the appendix. Figure 2 The multi-protection system for the storage medium destruction machine includes: The comparison and verification module 11 is used to read the unique identification information of the storage medium after it enters the destruction chamber, compare and verify the unique identification information with a preset authorization database, and generate a one-time destruction pass code. The security zone determination module 12 is used to create a dynamic security zone in the destruction chamber based on the one-time destruction pass code. The boundary of the dynamic security zone is a dynamically adjustable boundary, and the electromagnetic shielding and physical locking structure are activated in conjunction with it. The triple authentication module 13 is used to perform operator identity verification, external authorization verification, and storage medium status verification. When all three authentications are successful, the storage medium destruction machine is controlled to execute the operation. The system performs a destruction operation; a data acquisition module 14 is used to activate multi-source sensors to acquire data during the execution process of the storage medium destruction machine, and establish multimodal sensing data, which includes fragment granularity data, electromagnetic erasure depth data, energy consumption data, and the operating status data of the storage medium destruction machine; an anomaly authentication module 15 is used to send the multimodal sensing data to the anomaly authentication channel to perform anomaly authentication during the destruction process and establish a destruction encryption digest; a multi-protection module 16 is used to perform multiple protections for destruction based on the destruction encryption digest, the one-time destruction pass code, and the multimodal sensing data.

[0077] Furthermore, the comparison and verification module 11 in the multi-protection system for the storage medium destruction machine is also used for: the destruction chamber is equipped with a digital potentiometer array coupled to the electromagnetic erasure device, the digital potentiometer array is used to dynamically adjust the current intensity of the electromagnetic erasure based on the security parameter generation result of the one-time destruction pass code, wherein each digital potentiometer corresponds to an independent erasure channel, and dynamically adjusting the current intensity of the electromagnetic erasure includes digitally programmable control of the rise slope, peak amplitude and holding time of the erasure current.

[0078] Furthermore, the security zone determination module 12 in the multi-protection system for the storage medium destruction machine is also used for: the boundary adjustment of the dynamic security zone is driven by multi-dimensional sensor input, including temperature gradient, electromagnetic field strength and mechanical vibration signal, and performs dynamic boundary reconstruction according to the real-time changes of multi-dimensional sensor input, adjusting the electromagnetic shielding strength and locking delay to perform dynamic isolation control of the internal space of the destruction chamber.

[0079] Furthermore, the triple authentication module 13 in the multi-protection system for the storage medium destruction machine is also used to: configure a joint confidence calculation unit, and use the joint confidence calculation unit to dynamically calculate a comprehensive confidence score based on the historical credibility of each authentication source, verification time interval, and communication delay; when the comprehensive confidence score is lower than a preset score threshold, a security interruption is triggered, and the one-time destruction access code is frozen.

[0080] Furthermore, the anomaly authentication module 15 in the multi-protection system for the storage medium destruction machine is also used to: perform time-series synchronization, noise reduction, and frame segmentation processing on the multimodal sensing data within the trusted execution environment of the anomaly authentication channel; extract the granularity distribution spectrum from the fragment granularity data; extract the spectral energy density curve from the electromagnetic erasure depth data; extract the downstream power pulse feature from the energy consumption data; and extract the mechanical vibration mode and motor drive current feature from the operating status data; normalize and dimensionless process the extraction results; synchronize the processed extraction results to the three-layer verification sub-channel within the anomaly authentication channel; weight and fuse the single-modal anomaly scores of each verification sub-channel to establish an overall anomaly score; and complete the anomaly authentication based on the overall anomaly score.

[0081] Furthermore, the anomaly authentication module 15 in the multi-protection system for the storage medium destruction machine is also used to: synchronize the processed extraction results to the first-layer verification sub-channel, which is a rule-based sub-channel based on residual and threshold statistics, and output a first single-modal anomaly score; synchronize the processed extraction results to the second-layer verification sub-channel, which is a time-series anomaly detection sub-channel based on a sliding window, and output a second single-modal anomaly score; synchronize the processed extraction results to the third-layer verification sub-channel, which is a multi-modal reconstruction sub-channel based on deep learning, and output a third single-modal anomaly score; and perform weighted fusion based on the first single-modal anomaly score, the second single-modal anomaly score, and the third single-modal anomaly score to establish an overall anomaly score.

[0082] Furthermore, the anomaly authentication module 15 in the multi-protection system for the storage medium destruction machine is also used for: performing offline statistical modeling based on the multimodal feature vector set under normal destruction conditions of similar media, constructing a baseline mean for each modal vector; using the rule sub-channel to perform element-wise difference calculation based on the baseline mean and extraction results to calculate the residual vector, performing Mahalanobis distance normalization on the residual vector according to the covariance matrix, and outputting the Mahalanobis residual value as a unified residual; and performing threshold determination based on the unified residual to output the first single-modal anomaly score.

[0083] Furthermore, the anomaly authentication module 15 in the multi-protection system for the storage medium destruction machine is also used to: establish sliding windows of at least two window lengths, and perform overlapping sliding processing on the processed extraction results; calculate a set of time-series statistics and frequency domain features within each sliding window, wherein the time-series statistics include mean, variance, kurtosis, and skewness, and the frequency domain features include main frequency power density, spectral energy concentration, and bandwidth expansion coefficient; establish a dual-domain joint change model based on the time-series statistics and the frequency domain features, perform change point detection through the difference matrix and correlation coefficient matrix of adjacent frames between windows, and establish an initial drift region; perform dynamic threshold correction and confidence interval determination on the initial drift region, and output the drift identification result; perform time-series mapping of the drift identification result to the corresponding window index, establish a time-series drift spectrum, and output a second single-mode anomaly score based on the time-series drift spectrum.

[0084] Furthermore, the anomaly authentication module 15 in the multi-protection system for the storage medium destruction machine is also used for: the third-layer verification sub-channel includes a self-supervised reconstructed neural network, the reconstructed neural network is composed of a multi-modal encoder, a fusion bottleneck layer and a joint decoder, each channel of the multi-modal encoder corresponds to a sensor stream, the encoder is constructed based on a one-dimensional / two-dimensional convolutional network, the fusion bottleneck layer performs feature interaction fusion based on a cross-modal attention mechanism, and the joint decoder is used to perform reconstruction of each modality data.

[0085] The various embodiments in this specification are described in a progressive manner, with each embodiment focusing on its differences from other embodiments. Figure 1 The multi-protection method and specific examples for the storage media destroyer in Embodiment 1 are also applicable to the multi-protection system for the storage media destroyer in this embodiment. Through the foregoing detailed description of the multi-protection method for the storage media destroyer, those skilled in the art can clearly understand the multi-protection system for the storage media destroyer in this embodiment. Therefore, for the sake of brevity, it will not be described in detail here.

[0086] The above description of the disclosed embodiments enables those skilled in the art to make or use this application. Various modifications to these embodiments will be readily apparent to those skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of this application. Therefore, this application is not to be limited to the embodiments shown herein, but is to be accorded the widest scope consistent with the principles and novel features disclosed herein.

[0087] Obviously, those skilled in the art can make various modifications and variations to this application without departing from the spirit and scope of this application. Therefore, if such modifications and variations fall within the scope of this application and its equivalents, this application also intends to include such modifications and variations.

Claims

1. A multi-protection method for a storage medium destruction machine, characterized in that, include: After the storage medium enters the destruction chamber, the unique identification information of the storage medium is read, and the unique identification information is compared and verified with a preset authorization database to generate a one-time destruction pass code. A dynamic security zone is created within the destruction chamber based on the one-time destruction access code. The boundary of the dynamic security zone is dynamically adjustable, and the electromagnetic shielding and physical locking structures are activated in conjunction with it. Perform operator identity verification, external authorization verification, and storage medium status verification. When all three authentications are successful, control the storage medium destruction machine to perform the destruction operation. Activate multi-source sensors to collect data during the execution process of the storage medium destruction machine, and establish multimodal sensing data, which includes fragment particle size data, electromagnetic erasure depth data, energy consumption data, and operating status data of the storage medium destruction machine; The multimodal sensing data is sent to the anomaly authentication channel to perform anomaly authentication during the destruction process and to establish a destruction encryption digest. The system employs multiple protections for destruction, including the destruction encryption digest, one-time destruction passcode, and multimodal sensor data.

2. The multi-protection method for a storage medium destruction machine as described in claim 1, characterized in that, The multimodal sensing data is sent to the anomaly authentication channel to perform anomaly authentication during the destruction process, including: Within the trusted execution environment of the abnormal authentication channel, the multimodal sensing data is subjected to time synchronization, denoising and framing processing. The granularity distribution spectrum is extracted from the fragment granularity data, the spectral energy density curve is extracted from the electromagnetic erasure depth data, the power pulse feature is extracted from the energy consumption data, and the mechanical vibration mode and motor drive current feature are extracted from the operating status data. The extraction results are normalized and dimensionless. The processed extraction results are synchronized to the three-layer verification sub-channels within the anomaly authentication channel. The single-modal anomaly scores of each verification sub-channel are weighted and fused to establish an overall anomaly score. Anomaly authentication is completed based on the overall anomaly score.

3. The multi-protection method for a storage medium destruction machine as described in claim 2, characterized in that, The processed extraction results will be synchronized to the three-tiered verification sub-channels within the anomaly authentication channel, including: The processed extraction results are synchronized to the first-level verification sub-channel, which is a rule-based sub-channel based on residual and threshold statistics, and outputs the first single-modal anomaly score. The processed extraction results are synchronized to the second-layer verification sub-channel, which is a time-series anomaly detection sub-channel based on a sliding window, and outputs the second single-modal anomaly score. The processed extraction results are synchronized to the third-layer verification sub-channel, which is a deep learning-based multimodal reconstruction sub-channel that outputs the third single-modal anomaly score. The overall anomaly score is established by weighting and fusing the first, second, and third unimodal anomaly scores.

4. The multi-protection method for a storage medium destruction machine as described in claim 3, characterized in that, The processed extraction results are synchronized to the first-level verification sub-channel, including: Offline statistical modeling is performed based on the multimodal feature vector set of similar media under normal destruction conditions, and a baseline mean is constructed for each modal vector; The rule sub-channel is used to perform element-wise difference calculation based on the baseline mean and extraction results to calculate the residual vector. The residual vector is then normalized by Mahalanobis distance according to the covariance matrix, and the Mahalanobis residual value is output as a unified residual. Threshold determination is performed based on the unified residual, and the first single-mode anomaly score is output.

5. The multi-protection method for a storage medium destruction machine as described in claim 3, characterized in that, The processed extraction results are synchronized to the second-level verification sub-channel, including: Establish sliding windows of at least two window lengths, and perform overlapping sliding processing on the processed extraction results of the sliding windows; Within each sliding window, a set of time-series statistics and frequency domain features are calculated. The time-series statistics include mean, variance, kurtosis, and skewness. The frequency domain features include main frequency power density, spectral energy concentration, and bandwidth spread factor. A dual-domain joint change model is established based on the time-series statistics and the frequency domain features. Change point detection is performed by using the difference matrix and correlation coefficient matrix of adjacent frames between windows to establish an initial drift region. The initial drift region is dynamically thresholded and confidence intervals are determined, and the drift identification result is output. The drift identification results are mapped to the time series of the corresponding window index to establish a time series drift spectrum, and the second single-mode anomaly score is output based on the time series drift spectrum.

6. The multi-protection method for a storage medium destruction machine as described in claim 3, characterized in that, The third-layer verification subchannel includes a self-supervised reconstructed neural network, which consists of a multi-modal encoder, a fusion bottleneck layer, and a joint decoder. Each channel of the multi-modal encoder corresponds to a sensor stream. The encoder is built based on a one-dimensional / two-dimensional convolutional network. The fusion bottleneck layer performs feature interaction fusion based on a cross-modal attention mechanism. The joint decoder is used to perform the reconstruction of data from each modality.

7. The multi-protection method for a storage medium destruction machine as described in claim 1, characterized in that, The destruction chamber is equipped with a digital potentiometer array coupled to the electromagnetic erasure device. The digital potentiometer array is used to dynamically adjust the current intensity of the electromagnetic erasure based on the security parameter generation result of the one-time destruction access code. Each digital potentiometer corresponds to an independent erasure channel. The dynamic adjustment of the current intensity of the electromagnetic erasure includes digitally programmable control of the rise slope, peak amplitude and duration of the erasure current.

8. The multi-protection method for a storage medium destruction machine as described in claim 1, characterized in that, The boundary adjustment of the dynamic safety zone is driven by multi-dimensional sensor inputs, including temperature gradient, electromagnetic field strength and mechanical vibration signals. Based on the real-time changes of the multi-dimensional sensor inputs, the boundary is dynamically reconstructed, and the electromagnetic shielding strength and locking delay are adjusted to perform dynamic isolation control of the internal space of the destruction chamber.

9. The multi-protection method for a storage medium destruction machine as described in claim 1, characterized in that, Perform operator identity verification, external authorization verification, and storage media status verification, including: Configure a joint confidence calculation unit and use it to dynamically calculate the comprehensive confidence score based on the historical credibility of each authentication source, verification time interval, and communication delay. If the overall confidence score is lower than the preset score threshold, a security interruption will be triggered, and the access code will be frozen and destroyed in one go.

10. A multi-protection system for a storage medium destruction machine, characterized in that, The steps for implementing the multi-protection method for a storage media destruction machine according to any one of claims 1 to 9, wherein the multi-protection system for the storage media destruction machine comprises: The comparison and verification module is used to read the unique identification information of the storage medium after the storage medium enters the destruction chamber, compare and verify the unique identification information with the preset authorization database, and generate a one-time destruction pass code. The safe zone determination module is used to create a dynamic safe zone in the destruction chamber based on the one-time destruction access code. The boundary of the dynamic safe zone is a dynamically adjustable boundary, and the electromagnetic shielding and physical locking structure are activated in conjunction with it. The triple authentication module is used to verify the operator's identity, external authorization, and storage media status. When all three authentications are successful, it controls the storage media destruction machine to perform the destruction operation. The data acquisition module is used to activate multi-source sensors to acquire data during the execution process of the storage medium destruction machine and establish multimodal sensing data. The multimodal sensing data includes fragment particle size data, electromagnetic erasure depth data, energy consumption data, and operating status data of the storage medium destruction machine. An anomaly authentication module is used to send the multimodal sensing data to the anomaly authentication channel, perform anomaly authentication during the destruction process, and establish a destruction encryption digest. The multi-protection module is used for multiple protections for destruction based on the destruction encryption digest, one-time destruction pass code, and multimodal sensor data.

Citation Information

Patent Citations

  • Method and device for destroying encrypted hard disk

    CN113568846A

  • Storage medium destruction method based on volume identification

    CN117457032A

  • Automobile part data life cycle safety test system

    CN120781366A

  • KR20250085645A

Cited By

  • A multi-modal self-evolving audit hierarchical system and method

    CN122395107A

  • A multi-modal self-evolving audit hierarchical system and method

    CN122395107B