Self-encryption storage device and operation method thereof
By introducing a wireless communication module and control unit into the self-encrypting hard drive, and using wireless signals to transmit decryption commands and determine distance, the risk of data leakage and theft when the self-encrypting hard drive is connected to a host is solved, achieving higher security and usage efficiency.
Patent Information
- Application Number
- CN202411038129.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-07-31
- Publication Date
- 2026-02-03
AI Technical Summary
When existing self-encrypting hard drives are connected to the host computer, decryption commands or verification information can be easily recorded, leading to data leakage. Furthermore, the risk of cracking the hard drive after it is stolen is high.
It employs a combination of data storage, control unit, and wireless communication module to transmit decryption commands or authentication information via wireless signals. The control unit determines the distance based on signal strength and issues a security alert to ensure data security.
It effectively prevents data leakage after host recording and hard drive theft, improves the security and efficiency of data storage, and provides dual protection.
Smart Images

Figure CN121456927A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application provides a self-encrypting storage device and its operating method, by a decryption instruction from an external device to obtain the operating permission in the self-encrypting storage device. BACKGROUND
[0002] The storage data security is one of the information security focuses, especially when the valuable data is stolen, the loss can be very serious. Especially the portable data storage, easy to move and forget, and the important information can be leaked.
[0003] The self-encrypting hard disk (Self-encrypting drive), the verification system maintains the security of the internal data, although it can enhance the security of the data storage in the portable data storage, there are still some concerns. The verification system and the host computer connected with the self-encrypting hard disk have no dependence, and some operation schemes still need to pass through the host computer to unlock the self-encrypting hard disk. Thus, the decryption instruction or the verification information can still be sniffed in the host computer, resulting in the data leakage in the portable data storage, and the security is a concern.
[0004] In addition, if the known portable data storage is stolen and the shell is damaged, a person with malicious intent can easily crack the reading through the parts, causing the risk of data leakage, and if it is a company's important confidential file, the loss will be difficult to estimate. SUMMARY
[0005] Regarding the foregoing technical needs, the present application provides a self-encrypting storage device, comprising: a data storage for storing data and providing a self-encrypting function for the data; a control unit connected to the data storage by a first signal; and a wireless communication module connected to the control unit by a second signal, the wireless communication module receives a wireless signal from a first external device and converts the wireless signal into a wired signal transmitted to the control unit, wherein when the wireless signal sends a decryption instruction or an authentication information corresponding to the data storage, the control unit transmits the decryption instruction or the authentication information to the data storage, and the data storage unlocks the self-encrypting function according to the decryption instruction or the authentication information to obtain the operating permission of at least one storage section in the data storage.
[0006] In one embodiment, the data storage performs an authorized operation on at least one storage section according to the operation permission when the wireless signal contains the decryption instruction or the authentication information. Alternatively, the self-encrypting storage device further comprises a connector or a signal bridge, and the control unit forms a signal channel with a second external device through the connector or the signal bridge. When the wireless signal contains the decryption instruction or the authentication information, the second external device performs an authorized operation on at least one storage section of the data storage under the operation permission through the signal channel.
[0007] In one embodiment, the control unit determines the distance between the self-encrypting storage device and the first external device according to the strength of the wireless signal received by the wireless communication module. When the connector is not connected to the second external device and the distance between the unlocked self-encrypting storage device and the first external device is greater than a safety distance, the control unit sends a safety warning. Alternatively, when the control unit does not form a signal channel with the second external device through the signal bridge and the distance between the unlocked self-encrypting storage device and the first external device is greater than a safety distance, the control unit sends a safety warning.
[0008] In one embodiment, the second external device comprises a computer, a peripheral storage device, a tablet computer, a smart phone, a display, or a printer, etc. which has a device capable of sending the decryption instruction or the authentication information corresponding to the data storage in the wireless signal.
[0009] In one embodiment, the data storage is a self-encrypting hard disk (Self-encrypting drive) complying with the TCG Opal 2.0 specification. TCG stands for Trusted Computing Group specification.
[0010] In one embodiment, the operation permission comprises a read permission, a write permission, a modification permission, and an execution permission.
[0011] In one embodiment, the aforementioned data can be digital data or analog data.
[0012] In one embodiment, the second external device comprises a computer, a peripheral storage device, a tablet computer, a smart phone, a display, or a printer.
[0013] In one embodiment, the first and second signal connections are wired connections or wireless connections.
[0014] In one embodiment, the wireless signal comprises NFC, Bluetooth, or other similar communication protocols.
[0015] In one embodiment, the self-encrypting function is based on at least one of the Advanced Encryption Standard (AES) and the RSA encryption standard for encryption and decryption.
[0016] According to another aspect, the present application provides an operation method of a self-encrypting storage device, comprising: providing a data storage device, and providing a self-encrypting function for data stored in the data storage device; providing a first signal connection and a control unit, the control unit being connected to the data storage device through the first signal connection; providing a second signal connection and a wireless communication module, the wireless communication module being connected to the control unit through the second signal connection; and the wireless communication module receiving a wireless signal from a first external device, and converting the wireless signal into a wired signal and transmitting the wired signal to the control unit, wherein when the wireless signal sends a decryption instruction or an authentication information corresponding to the data storage device, the data storage device unlocks the self-encrypting function of the data storage device according to the decryption instruction or the authentication information to obtain an operation permission of at least one storage section in the data storage device.
[0017] Thus, the self-encrypting storage device and the operation method of the self-encrypting storage device provided by the present application can avoid the destruction of the shell and the attempt to crack the stolen encrypted data after the present application is stolen. BRIEF DESCRIPTION OF DRAWINGS
[0018] Figure 1 、 2 FIG. 1 shows a schematic diagram of a self-encrypting storage device according to an embodiment of the present application;
[0019] Figure 3 FIG. 2 shows a schematic diagram of the distance between the self-encrypting storage device and the first external device according to an embodiment of the present application;
[0020] Figure 4 FIG. 3 shows a schematic diagram of the encryption and decryption process in the self-encrypting hard disk according to an embodiment of the present application; and
[0021] Figure 5 FIG. 4 shows a schematic diagram of an operation method of a self-encrypting storage device according to an embodiment of the present application.
[0022] BRIEF DESCRIPTION OF DRAWINGS
[0023] 100, 200: self-encrypting storage device
[0024] 10: data storage device
[0025] 20: control unit
[0026] 30: wireless communication module
[0027] CONN: connector
[0028] D: distance
[0029] KEK: key encryption key
[0030] MEK: Media Encryption Key
[0031] ODE1: First External Device
[0032] ODE2: Second External Device
[0033] S1-S6: Steps
[0034] SBR: Signal Bridge
[0035] SCN1: First Signal Connection
[0036] SCN2: Second Signal Connection
[0037] WLS: Wireless signal Detailed Implementation
[0038] The foregoing and other technical contents, features and effects of the present invention will be clearly presented in the following detailed description of the preferred embodiments with reference to the accompanying drawings.
[0039] Reference Figure 1 Regarding the aforementioned technical needs, the present invention provides a self-encrypting storage device 100, comprising: a data storage device 10 for storing data and providing a self-encryption function for the data; a control unit 20 connected to the data storage device 10 via a first signal connection SCN1; and a wireless communication module 30 connected to the control unit 20 via a second signal connection SCN2, wherein the wireless communication module 30 receives a wireless signal WLS from a first external device ODE1 and converts the wireless signal WLS into a wired signal and transmits it to the control unit 20. When a decryption command or authentication information corresponding to data storage 10 is transmitted in the wireless signal WLS, data storage 10 unlocks its self-encryption function according to the decryption command or authentication information (for example, control unit 20 transmits the decryption command or authentication information to data storage 10; or, control unit 20 generates an unlock command to data storage 10 according to the decryption command or authentication information to obtain operation permission for at least one storage segment in data storage 10). Different users may have different security permissions for different data or segments in data storage 10. Therefore, the decryption command or authentication information (or unlock command) may only correspond to different data or different storage segments, thus unlocking operation permission for at least one storage segment in data storage 10 to perform operations.
[0040] Furthermore, the design of operation permissions for at least one storage segment can also greatly improve the utilization efficiency of the data storage device 10. By having different security settings for different data or different storage segments, the self-encrypting storage device 100 can have a variety of security settings.
[0041] In one embodiment, when the wireless signal WLS contains decryption instructions or authentication information, the data storage 10 performs authorized operations on at least one storage section according to the operation authority (e.g., the data storage 10 performs self-authorization operations, or by operating the first external device ODE1 to perform the authorized operations of the data storage 10).
[0042] In comparison with Figure 1 the self-encryption storage device 100. Figure 2 In one embodiment, the self-encryption storage device 200 further includes a connector CONN or a signal bridge SBR, and the control unit 20 forms a signal channel with a second external device ODE2 through the connector CONN or the signal bridge SBR (e.g., the connector CONN is plugged into the second external device ODE2 to form a signal channel between the self-encryption storage device 100 and the second external device ODE2). When the wireless signal WLS contains decryption instructions or authentication information, the second external device ODE2 performs authorized operations on at least one storage section of the data storage 10 according to the operation authority through the signal channel.
[0043] In one embodiment, if there is a need for enhanced security, the signal connection between the first external device ODE1 and the self-encryption storage device 100, 200 can be supplemented with other signals to assist in transmitting decryption instructions or authentication information, such as optical signals, images, animations, mechanical vibrations, sounds, videos, biometric identification, etc., to reduce the possibility of information being stolen and improve the security strength of the data.
[0044] The aforementioned self-encryption function, for example, is when the connector CONN or the signal bridge SBR is disconnected from the second external device ODE2 (e.g., the connector CONN is unplugged from the second external device ODE2). The self-encryption function automatically encrypts (automatically locks) the data storage 10 when it is static. If the data storage 10 is damaged, it is unlocked by receiving a wireless signal WLS from a first external device ODE1 through the wireless communication module 30, otherwise it cannot perform reading of the data storage 10.
[0045] Referring to Figure 3, based on the need to enhance the security of data, in an embodiment, the control unit 20 determines the distance D between the self-encrypting storage device 100 and the first external device ODE1 according to the strength of the wireless signal WLS received by the wireless communication module 30. When the strength of the received wireless signal WLS decreases, it indicates that the distance D between the self-encrypting storage device 100 and the first external device ODE1 increases. When the strength of the received wireless signal WLS increases, it indicates that the distance D between the self-encrypting storage device 100 and the first external device ODE1 decreases. Thus, the distance D between the self-encrypting storage device 100 and the first external device ODE1 can be determined, and this technique can also be used to prevent the self-encrypting storage device 100 from being stolen. For example, when the distance D between the self-encrypting storage device 100 (or 200) and the first external device ODE1 is greater than a safe distance, the control unit 20 sends a security alert to warn that the self-encrypting storage device 100 may be taken away from the scene. For another example, when the connector CONN is not plugged into the second external device ODE2 and the distance D between the unlocked self-encrypting storage device 100 and the first external device ODE1 is greater than a safe distance, the control unit 20 sends a security alert. Various forms of security alerts, such as vibration, flashing, sound, transmitting signals to the first external device ODE1, etc. are sent. Alternatively, when the control unit 20 does not form a signal channel between the signal bridge SBR and the second external device ODE2 and the distance D between the unlocked self-encrypting storage device 100 and the first external device ODE1 is greater than a safe distance, the control unit 20 sends a security alert. This design can handle the failure of the self-encryption function (system failure, settings changed, etc.), increase the risk of theft, and provide a double protection function to separate after use.
[0046] In an embodiment, the second external device ODE2 includes a computer, a peripheral storage device, a tablet computer, a smart phone, a display, or a printer, etc., mainly including a device that can send decryption instructions or authentication information corresponding to the data storage 10 in the wireless signal WLS.
[0047] In an embodiment, the data storage 10 is a self-encrypting hard drive (Self-encrypting drive) that complies with the TCG Opal 2.0 specification.
[0048] In TCG Opal 2.0, a media encryption key (MEK) in the encryption key is the main key for protecting static data in the data storage 10. Static represents that the data is not in a state of performing operations on the data. The generation of the media encryption key MEK can be performed in many ways, such as a random number generator, etc.
[0049] Reference Figure 4The media encryption key MEK is an important key for protecting the static data in the data storage 10, and the media encryption key MEK itself also needs to be encrypted. The encryption of the media encryption key MEK is performed by a key encryption key (KEK), which is a specific value based on a user password, a command, or a calculation. The key encryption key KEK is generated according to a key derivation function (KDF). The media encryption key MEK is only stored in the self-encrypting storage device 100 in an encrypted form, and any unencrypted media encryption key MEK is only stored in the self-encrypting storage device 100 when it is powered on. When the self-encrypting storage device 100 is powered off, the unencrypted media encryption key MEK is lost. In addition, TCG Opal 2.0 does not store an unencrypted user password or command, thereby reducing the possibility of a breach of the self-encrypting storage device 100.
[0050] In an embodiment, the operation permissions include read permission, write permission, modify permission, and execute permission. The authorized operations are operations performed on at least one storage section of the data storage 10, such as reading, writing, modifying, and executing, which correspond to the operation permissions, respectively. If necessary, the operations are not limited to this, such as multiple encryption.
[0051] In an embodiment, the aforementioned data can be digital data or analog data. The data storage can be performed in an electrical physical manner (voltage, resistance, capacitance, electromagnetism, quantum state), an optical physical manner, a chemical manner, a mechanical manner, and the like.
[0052] In an embodiment, the second external device ODE2 includes a computer, a peripheral storage device, a tablet computer, a smart phone, a display, or a printer, and the like.
[0053] In an embodiment, the data storage 10 is a self-encrypting hard disk (Self-encrypting drive) that complies with the TCG Opal 2.0 specification. For example, a self-encrypting SSD hard disk (SATA hard disk or NVMe hard disk). For example, an NVMe hard disk is based on NAND and can be transmitted between a CPU and a high-speed PCIe slot, and the amount of data transmitted is increased by tens of times compared to a SATA hard disk. The NVMe hard disk can process more than one million input / output data per second (IOPS). Compared to the NVMe hard disk, the SATA hard disk has a more traditional architecture, and many devices still use SATA hard disks.
[0054] In one embodiment, the first and second signal connections SCN1, SCN2 can be wired connections or wireless connections. The selection of the connection mode can be determined according to requirements. For example, in the wired connection mode, the internal design of the self-encrypting storage device is relatively crowded, but the connected content is not easy to be intercepted. In the wireless connection mode, the internal design of the self-encrypting storage device is relatively flexible, but the connected content is relatively easy to be intercepted. In addition, when the first and second signal connections SCN1, SCN2 are wired connections, the communication protocol can also be determined according to requirements, such as I2C, SPI, and other wired transmission modes.
[0055] In one embodiment, the wireless signal WLS includes NFC, Bluetooth, or other similar communication protocols.
[0056] In one embodiment, the self-encryption function is based on at least one of the Advanced Encryption Standard (AES) and the RSA encryption standard for encryption and decryption.
[0057] In one embodiment, if necessary, the first external device ODE1 and the second external device ODE2 can also be the same device. For example, the same device communicates with the wireless communication module 30 through the wireless signal WLS by means of the aforementioned NFC, Bluetooth, or other similar communication protocols. At this time, the signal bridge SBR can be combined with the wireless communication module 30, and the same device connects the signal connection data storage 10 through the wireless signal WLS to perform operations.
[0058] Reference Figure 5 According to another aspect, the present application provides an operation method of a self-encrypting storage device, including: providing a data storage device 10 and providing a self-encryption function for data stored in the data storage device 10 (S1); providing a first signal connection SCN1 and a control unit 20, the control unit 20 being connected to the data storage device 10 through the first signal connection SCN1 (S2); providing a second signal connection SCN2 and a wireless communication module 30, the wireless communication module 30 being connected to the control unit 20 through the second signal connection SCN2 (S3); the wireless communication module 30 receives a wireless signal WLS from a first external device ODE1 and converts the wireless signal WLS into a wired signal and transmits it to the control unit 20 (S4); and when a decryption instruction or authentication information corresponding to the data storage device 10 is sent in the wireless signal WLS (S5), the data storage device 10 unlocks the self-encryption function of the data storage device 10 according to the decryption instruction or the authentication information (S6) to obtain an operation permission of at least one storage section in the data storage device 10.
[0059] For the detailed description of the operation method of the self-encryption storage, please refer to the foregoing description of the related embodiments and components, which will not be repeated here. The main technical means of the present application is that the data storage 10 has a self-encryption function (S1). Even if a person with malicious intent destroys the product shell and separately disassembles the components, he or she cannot read the data in the data storage 10. Neither can he or she achieve this through the control unit 20, the wireless communication module 30, or by separately disassembling the data storage 10.
[0060] The above has described the present application for the preferred embodiments, but the above description is only for those skilled in the art to easily understand the content of the present application, and is not intended to limit the scope of the present application and the disclosed technology. Any person skilled in the art can make equivalent embodiments with the above disclosed technology content without departing from the scope of the technical solutions of the present application, such as combination, slight change or modification.
Claims
1. A self-encrypting storage device, characterized by, The data storage device comprises: a data storage unit for storing data and providing a self-encryption function for the data; a control unit connected to the data storage unit via a first signal connection; and a wireless communication module connected to the control unit via a second signal connection, the wireless communication module receiving a wireless signal from a first external device and converting the wireless signal into a wired signal to be transmitted to the control unit, wherein when the wireless signal contains a decryption instruction or authentication information corresponding to the data storage unit, the data storage unit unlocks the self-encryption function according to the decryption instruction or the authentication information to obtain an operation permission for at least one storage section in the data storage unit. When the wireless signal contains the decryption instruction or the authentication information, the data storage unit performs an authorized operation on the at least one storage section according to the operation permission; or the self-encryption storage device further comprises a connector or a signal bridge for plugging a second external device, the control unit forms a signal channel with the second external device via the connector or the signal bridge, wherein when the wireless signal contains the decryption instruction or the authentication information, the second external device performs the authorized operation on the at least one storage section of the data storage unit under the operation permission via the signal channel.
2. The self-encrypting storage device of claim 1, wherein, The control unit determines the distance between the self-encryption storage device and the first external device according to the strength of the wireless signal received by the wireless communication module, wherein when the distance between the unlocked self-encryption storage device and the first external device is greater than a safety distance, the control unit sends a safety warning.
3. The self-encrypting storage device of claim 1, wherein, The second external device comprises a computer, a peripheral storage device, a tablet computer, a smart phone, a display, or a printer.
4. The self-encrypting storage device of claim 1, wherein, The data storage unit is a self-encrypting hard disk (Self-encrypting drive) complying with TCG Opal 2.0 specification.
5. The self-encrypting storage device of claim 1, wherein, The operation permission comprises a read permission, a write permission, a modification permission, and an execution permission.
6. The self-encrypting storage device of claim 1, wherein, The data is digital data or analog data.
7. The self-encrypting storage device of claim 1, wherein, The first and second signal connections are wired connections or wireless connections.
8. The self-encrypting storage device of claim 1, wherein, The wireless signal comprises NFC, Bluetooth, or other similar communication protocols.
9. The self-encrypting storage device of claim 1, wherein, The self-encryption function is performed according to at least one of the Advanced Encryption Standard (AES) and the RSA encryption standard.
10. The self-encrypting storage device of claim 1, wherein, The data storage device comprises:
11. An operating method of a self-encrypting storage, characterized by, a data storage unit for storing data and providing a self-encryption function for the data; a control unit connected to the data storage unit via a first signal connection; a wireless communication module connected to the control unit via a second signal connection; and The wireless communication module receives a wireless signal from a first external device, and converts the wireless signal into a wired signal and transmits the wired signal to the control unit. When a decryption instruction or an authentication information corresponding to the data storage is sent in the wireless signal, the data storage unlocks the self-encryption function of the data storage according to the decryption instruction or the authentication information, to obtain an operation permission of at least one storage section in the data storage.