Method, device and equipment for deploying network attached storage software based on USB (Universal Serial Bus) flash disk

By using a two-way authentication mechanism between the USB flash drive and the terminal device, the problem of network-attached storage software being easily cracked is solved, achieving high security and flexible data sharing. A dual system of 'physical key' + 'software authentication' is constructed to reduce the risk of data leakage.

CN121543077AActive Publication Date: 2026-02-17SHENZHEN LINGDECHUANG TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202610088004.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-01-22
Publication Date
2026-02-17
Estimated Expiration
2046-01-22

AI Technical Summary

Technical Problem

Existing network-attached storage software relies on software passwords or system accounts for authentication, which are vulnerable to brute-force attacks or tampering, posing a significant risk of data leakage.

Method used

A dual authentication system based on USB flash drive is adopted. By encrypting and transmitting device information and verifying the legitimacy of the USB flash drive, combined with decrypting and splitting identity information and comparing verification codes, two-way authentication between the USB flash drive and the terminal device is achieved, thus constructing a security mechanism of 'physical key' + 'software authentication'.

Benefits of technology

Effectively filter unauthorized terminal devices, reduce the risk of data leakage, improve data security and ease of operation, and ensure the flexibility and security of software deployment.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121543077A_ABST
    Figure CN121543077A_ABST
Patent Text Reader

Abstract

The embodiment of the invention provides a network additional storage software deployment method, device and equipment based on a USB flash disk, and the method comprises the steps: collecting equipment information of terminal equipment under the condition that the USB flash disk is detected to be accessed and network additional storage software is installed, encrypting the equipment information to obtain encrypted equipment information, and storing the encrypted equipment information in the USB flash disk; transmitting the encrypted equipment information to the USB flash disk; and under the condition that the encrypted identity identification information is received, decrypting the encrypted identity identification information to obtain the identity identification information, splitting the identity identification information into sequence information and a first check code, performing check calculation on the sequence information to obtain a second check code, and under the condition that the first check code is the same as the second check code, performing verification calculation on the second check code to obtain the encrypted identity identification information. Determining that the verification is passed; and under the condition that the activation information is received, the client use right of the network attachment storage software is activated based on the activation information. According to the scheme, the special USB flash disk is taken as a unique activation certificate on the physical level, and the bidirectional authentication of the USB flash disk and the terminal equipment is realized.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of computer technology, and in particular to a method, apparatus, and device for deploying network attached storage software based on a USB flash drive. Background Technology

[0002] In the digital age, multimedia data (photos, videos, documents, etc.) across various application scenarios is experiencing explosive growth, while problems such as fragmented data storage, inconvenient sharing, and difficulties in remote access are becoming increasingly prominent. Traditional local storage methods (such as hard drive partitioning) suffer from severe data fragmentation, weak cross-device collaboration capabilities, and a lack of security protection mechanisms; while public cloud storage faces issues such as privacy leakage risks, limited transmission bandwidth, and high long-term subscription costs, making it difficult to meet users' core needs for centralized data management, secure and controllable data, and efficient sharing. Therefore, network-attached storage technology has become a key technological link in the field of data storage and sharing. Its core objective is to achieve centralized management of distributed data, cross-terminal interconnection, and convenient remote access while ensuring data security and reliability, thereby reducing storage and maintenance costs, improving data sharing and access efficiency, and laying the foundation for efficient data management in personal, family, and small office scenarios.

[0003] In related technologies, to eliminate the hardware-binding limitations of finished network-attached storage (NAT) products, NAT software can be deployed using pure software installation or system integration methods. However, these methods rely on software passwords or system accounts for authentication, which are vulnerable to brute-force attacks or tampering, posing a significant risk of data leakage and requiring improvement. Summary of the Invention

[0004] This application provides a method, apparatus, and device for deploying network attached storage software based on a USB flash drive. It solves the problem in related technologies that the deployment of network attached storage software relies on software passwords or system accounts for authentication, which is vulnerable to brute-force attacks or tampering and poses a significant risk of data leakage. It constructs a dual system of "physical key" + "software authentication", using a dedicated USB flash drive as the unique activation credential at the physical level to achieve two-way authentication between the USB flash drive and the terminal device, reducing the risk of data leakage, improving data security, and providing high flexibility in software deployment.

[0005] In a first aspect, embodiments of this application provide a method for deploying network-attached storage software based on a USB flash drive, the method comprising: When a USB flash drive is detected and network attached storage software is installed, the device information of the terminal device is collected, the device information is encrypted to obtain encrypted device information, and the encrypted device information is transmitted to the USB flash drive so that the USB flash drive can decrypt the encrypted device information to obtain the device information. If the device information meets the legal conditions, the pre-generated identity information is encrypted to obtain encrypted identity information, and the encrypted identity information is fed back to the terminal device. Upon receiving the encrypted identity information, the encrypted identity information is decrypted to obtain the identity information, which is then split into sequence information and a first verification code. The sequence information is then verified to obtain a second verification code. If the first verification code and the second verification code are the same, the verification is confirmed to be successful, so that the USB flash drive can send activation information to the terminal device. Upon receiving the activation information, the client access rights of the network attachment storage software are activated based on the activation information for data sharing and transmission.

[0006] Secondly, embodiments of this application also provide a network-attached storage device based on a USB flash drive, comprising: The first USB flash drive authentication module is configured to, upon detecting a USB flash drive connection and having network attached storage software installed, collect device information of the terminal device, encrypt the device information to obtain encrypted device information, and transmit the encrypted device information to the USB flash drive, so that the USB flash drive can decrypt the encrypted device information to obtain the device information. If the device information is valid, the module will encrypt pre-generated identity information to obtain encrypted identity information and feed the encrypted identity information back to the terminal device. The first device authentication module is configured to, upon receiving the encrypted identity information, decrypt the encrypted identity information to obtain the identity information, split the identity information into sequence information and a first verification code, perform verification calculation on the sequence information to obtain a second verification code, and determine that the verification is successful if the first verification code and the second verification code are the same, so that the USB flash drive can send activation information to the terminal device. The first software activation module is configured to, upon receiving the activation information, activate the client access rights of the network attachment storage software based on the activation information for data sharing and transmission.

[0007] Thirdly, embodiments of this application also provide an electronic device, the device comprising: One or more processors; Storage device, configured to store one or more programs, When the one or more programs are executed by the one or more processors, the one or more processors implement the network attached storage software deployment method based on USB flash drive as described in the embodiments of this application.

[0008] Fourthly, embodiments of this application also provide a non-volatile storage medium for storing computer-executable instructions, which, when executed by a computer processor, are configured to execute the network-attached storage software deployment method based on a USB flash drive as described in embodiments of this application.

[0009] In this embodiment, by encrypting device information transmission and verifying the legitimacy of the USB flash drive, illegal terminal devices can be effectively filtered, avoiding the risk of unauthorized devices activating the network attachment storage software. The integrity and authenticity of identity credentials are ensured through decryption and splitting of identity information and verification code comparison. The automated linkage between USB flash drive access and network attachment storage software activation enhances operational convenience and security. The above solution constructs a dual system of "physical key" + "software authentication." At the physical level, a dedicated USB flash drive serves as the sole activation credential, enabling two-way authentication between the USB flash drive and the terminal device, reducing the risk of data leakage, improving data security, and offering high flexibility in software deployment. Attached Figure Description

[0010] Figure 1 A flowchart illustrating a method for deploying network attached storage software based on a USB flash drive, as provided in this application embodiment; Figure 2 A flowchart illustrating the process of calculating a second check code is provided in an embodiment of this application; Figure 3 A flowchart of a network-attached storage software deployment method, including the process of installing network-attached storage software, is provided for embodiments of this application. Figure 4 A flowchart of a network-attached storage software deployment method, including a process for enabling file sharing functionality, is provided as an embodiment of this application. Figure 5 A flowchart illustrating a network attached storage software deployment method, including a process for ejecting a USB flash drive, is provided as an embodiment of this application. Figure 6 A flowchart illustrating another method for deploying network-attached storage software provided in this application embodiment; Figure 7 A flowchart illustrating a process for generating identity information is provided in this application embodiment; Figure 8 A structural block diagram of a network attached storage device based on a USB flash drive is provided for embodiments of this application; Figure 9This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application. Detailed Implementation

[0011] The embodiments of this application will be further described in detail below with reference to the accompanying drawings and examples. It should be understood that the specific embodiments described herein are merely illustrative of the embodiments of this application and are not intended to limit the scope of the embodiments. Furthermore, it should be noted that, for ease of description, only the parts relevant to the embodiments of this application are shown in the accompanying drawings, not the entire structure.

[0012] The terms "first," "second," etc., used in the specification and claims of this application are used to distinguish similar objects and not to describe a specific order or sequence. It should be understood that such use of data can be interchanged where appropriate so that embodiments of this application can be implemented in orders other than those illustrated or described herein, and the objects distinguished by "first," "second," etc., are generally of the same class and the number of objects is not limited; for example, a first object can be one or more. Furthermore, in the specification and claims, "and / or" indicates at least one of the connected objects, and the character " / " generally indicates that the preceding and following objects are in an "or" relationship.

[0013] The network attached storage software deployment method based on USB flash drive provided in this application embodiment can be executed by a computer device. The computer device refers to any electronic device with data computing, processing and storage capabilities, such as mobile phones, PCs (Personal Computers), tablet computers and other terminal devices. This application embodiment does not limit this.

[0014] Figure 1 A flowchart illustrating a method for deploying network attached storage software based on a USB flash drive, provided in this application embodiment, is shown. This method is applied to terminal devices, such as... Figure 1 As shown, the deployment method for network attached storage software based on a USB flash drive specifically includes the following steps: Step S101: When a USB flash drive is detected to be connected and network attached storage software has been installed, the device information of the terminal device is collected, the device information is encrypted to obtain encrypted device information, and the encrypted device information is transmitted to the USB flash drive so that the USB flash drive can decrypt the encrypted device information to obtain the device information. If the device information meets the legal conditions, the pre-generated identity information is encrypted to obtain encrypted identity information, and the encrypted identity information is fed back to the terminal device.

[0015] The core functions of the network attached storage software include file sharing, data backup, remote access, and access control, and it can be applied to various storage scenarios such as home and office. This embodiment does not rely on dedicated NAS hardware; instead, it directly utilizes idle terminal devices (such as desktop computers and laptops) in home or office settings to deploy the network attached storage software. Users only need a dedicated USB flash drive to complete the authentication process in steps S101-S102 to use the relevant services, thus lowering the barrier to entry for network attached storage technology. Furthermore, the USB flash drive can be bound to multiple terminal devices, allowing users to switch the hardware carrier of the network attached storage software according to their needs. The portability of the USB flash drive also facilitates the temporary deployment of the network attached storage software on remote terminal devices, enabling temporary data sharing and management.

[0016] Specifically, after detecting the USB flash drive connection, the terminal device can first check whether network attachment storage software is installed. The terminal device can determine whether network attachment storage software is installed through system service queries, software installation directory checks, or registry key verification. If the network attachment storage software is installed, it is launched and begins collecting its own device information. This device information may include computer motherboard information, system version, device name, disk capacity, etc., which are not limited in this application. It is understood that this device information can be considered the unique identifier of the terminal device and serves as the core basis for determining the device's legitimacy. To improve data security, the terminal device can encrypt the collected device information. Specific encryption methods can include symmetric encryption (e.g., AES-256) or asymmetric encryption (e.g., RSA-2048). In one embodiment, an AES key can be pre-written into the secure storage area of ​​the terminal device, and the same AES key can be written into the firmware encryption storage area of ​​the USB flash drive. During interaction, the terminal device and the USB flash drive can directly call the pre-stored symmetric key for encryption or decryption. In one embodiment, when the USB flash drive leaves the factory, the authorized party can generate an RSA key pair using dedicated equipment. The private key is written into the firmware secure storage area of ​​the USB flash drive, while the public key is exported and stored in the secure storage area of ​​the terminal device. Alternatively, a hybrid encryption method of AES and RSA can be used. The terminal device generates a temporary AES session key, encrypts it using the public key provided by the USB flash drive, and transmits it to the USB flash drive. The USB flash drive uses its private key to obtain the session key, and both the terminal device and the USB flash drive can use the session key for encrypted data transmission. Therefore, this application does not limit the specific encryption method and can adapt it according to the specific application scenario.

[0017] After encrypting the device information, the terminal device can transfer it to a USB drive for device authentication. Specifically, after decrypting the encrypted device information, the USB drive can verify it by comparing it to a preset device list. If the device information is recorded in the preset device list, it is considered authentic; otherwise, it is considered illegitimate. This preset device list can be understood as an authorized device whitelist, allowing the USB drive to be bound to multiple terminal devices. After the USB drive confirms the device information is authentic, it can read pre-generated identity information, encrypt it to obtain encrypted identity information, and then send this encrypted identity information back to the terminal device for authentication.

[0018] Step S102: Upon receiving the encrypted identity information, the encrypted identity information is decrypted to obtain the identity information. The identity information is then split into sequence information and a first verification code. The sequence information is verified and calculated to obtain a second verification code. If the first verification code and the second verification code are the same, the verification is confirmed to be successful, so that the USB flash drive can send activation information to the terminal device.

[0019] The identity information can be a unique authorization identifier built into the USB flash drive, used by terminal devices to identify the legitimate identity of the USB flash drive. To prevent interception and forgery during transmission, the USB flash drive can encrypt the identity information to be transmitted, thus improving security. Therefore, after receiving the encrypted identity information, the terminal device can first decrypt the encrypted identity information to obtain the original identity information, and then parse the identity information. It should be noted that the identity information can consist of two parts: sequence information and a first checksum. The sequence information can be the subject to be verified, while the first checksum can be a check value pre-calculated and generated by the USB flash drive, transmitted along with the sequence information. Therefore, the terminal device can split the identity information according to the pre-negotiated combination rules of the sequence information and the first checksum to obtain the sequence information and the first checksum. After obtaining the sequence information, a second checksum can be calculated to obtain the second checksum. This verification calculation can be a hash algorithm, a cyclic redundancy check algorithm, etc., which are not limited in this application. If the first and second verification codes match, the terminal device can confirm that the USB flash drive has passed authentication and receive the activation information sent by the USB flash drive. Thus, through steps S101 and S102, the terminal device and the USB flash drive can complete two-way authentication and proceed to the subsequent software usage process.

[0020] Optional, Figure 2 A flowchart of a process for calculating a second check code is provided for an embodiment of this application, as follows: Figure 2 As shown, the specific implementation process of calculating the second check code by verifying the sequence information includes the following steps: Step S1021: Concatenate the sequence information with the preset string to obtain the target string, and convert the target string into a byte array.

[0021] The sequence information can be the core valid data extracted from the plaintext identity information decrypted by the terminal device. It is the core component of this verification calculation and the original core data used by the USB flash drive to generate the first verification code. The preset string can be a fixed, confidential, and unmodifiable character content jointly pre-stored by the terminal device and the USB flash drive during the authorization phase. It can be called a salt string or a fixed verification factor, and serves as fixed supplementary data for this concatenation operation. Concatenating the sequence information with the preset string can be a string processing operation performed in a pre-agreed fixed order. After obtaining the target string, it can be converted into a byte array. Specifically, the target string can be converted into an ordered data set composed of several bytes as basic units according to a unified character encoding format agreed upon by the terminal and the USB flash drive (such as UTF-8 encoding, ASCII encoding, etc.). This byte data can be used as input data for subsequent cyclic redundancy check calculations.

[0022] Step S1022: Perform cyclic redundancy check calculation on the byte array to obtain the second check code.

[0023] The cyclic redundancy check (CRC) calculation involves performing a specific binary modulo-2 division operation on the input byte array and using the remainder as the final verification result, i.e., the second checksum. This second checksum is a fixed-length check value and serves as the core basis for consistency comparison with the first checksum. It should be noted that only legally paired terminal devices and USB flash drives can generate two identical checksums, thus effectively verifying the integrity of the USB flash drive's identity credentials.

[0024] Step S103: Upon receiving activation information, activate the client access rights of the network attachment storage software based on the activation information for data sharing and transmission.

[0025] The activation information can be an authorization credential for the network attachment storage software, specifically including one-time or time-limited authorization codes. Upon receiving the activation information, the client-side usage rights of the network attachment storage software can be activated directly based on this information. For example, the authorization credential from the activation information can be entered into the network attachment storage software to enable its full client functionality. The network attachment storage software can mount local storage media, which may include an internal computer disk, an external hard drive, or an additional USB storage card slot; this application does not impose any limitations on this. It should be noted that when it is necessary to increase the storage capacity or computing performance of the network attachment storage software, users do not need to replace the entire system; they only need to upgrade the hard drive, memory, and other hardware of the relevant terminal devices, making the upgrade cost controllable. If the current terminal device malfunctions, it can be directly replaced with another terminal device, and the service can be restored by inserting a USB flash drive. It is understandable that this embodiment constructs a triple security protection system of "physical key + two-way authentication + data encryption": the USB flash drive serves as the physical activation key, and its plugging and unplugging enables the start and stop control of the network attachment storage software, thus cutting off the possibility of unauthorized access at the physical level; the two-way authentication mechanism between the USB flash drive and the terminal device ensures that only authorized devices can run the network attachment storage service; and the algorithm encryption and permission management of the data further protect the privacy of the data.

[0026] The above-mentioned approach effectively filters out unauthorized terminal devices and mitigates the risk of unauthorized activation of network attachment storage software by encrypting device information transmission and verifying the legitimacy of the USB drive. It ensures the integrity and authenticity of identity credentials through decryption and splitting of identity information and verification code comparison. Furthermore, the automated linkage between USB drive access and network attachment storage software activation enhances operational convenience and security. This solution constructs a dual system of "physical key" + "software authentication." At the physical level, a dedicated USB drive serves as the sole activation credential, enabling two-way authentication between the USB drive and the terminal device, reducing the risk of data leakage, improving data security, and offering high flexibility in software deployment.

[0027] Figure 3 A flowchart of a network-attached storage software deployment method, including the process of installing network-attached storage software, is provided for embodiments of this application. Figure 3 As shown, the deployment method for network attached storage software based on a USB flash drive specifically includes the following steps: Step S301: When a USB flash drive is detected to be connected and network attached storage software has been installed, the device information of the terminal device is collected, the device information is encrypted to obtain encrypted device information, and the encrypted device information is transmitted to the USB flash drive so that the USB flash drive can decrypt the encrypted device information to obtain the device information. If the device information meets the legal conditions, the pre-generated identity information is encrypted to obtain encrypted identity information, and the encrypted identity information is fed back to the terminal device.

[0028] Step S302: Upon receiving the encrypted identity information, the encrypted identity information is decrypted to obtain the identity information. The identity information is then split into sequence information and a first verification code. The sequence information is verified and calculated to obtain a second verification code. If the first verification code and the second verification code are the same, the verification is confirmed to be successful, so that the USB flash drive can send activation information to the terminal device.

[0029] Step S303: Upon receiving activation information, activate the client access rights of the network attachment storage software based on the activation information for data sharing and transmission.

[0030] Step S304: If the USB flash drive is detected to be connected and no network attachment storage software is installed, obtain the installation package of the network attachment storage software from the USB flash drive, or obtain the software download address from the USB flash drive and obtain the installation package of the network attachment storage software based on the software download address.

[0031] If the terminal device is connecting to the USB drive for the first time, it will detect that the network attachment storage software is not installed. In one possible implementation, the USB drive may contain an installation package for the network attachment storage software. This package may be a complete compressed file containing all program files, installation scripts, configuration information, and dependent components of the network attachment storage software, which can be used to install the software. In another possible implementation, the USB drive may provide a software download address, which may be a unique network address pointing to the storage server of the network attachment storage software installation package. The terminal device can download the installation package from the designated server using this download address.

[0032] Step S305: Install the network attachment storage software based on the installation package, and start the network attachment storage software for data sharing and transmission.

[0033] The installation package includes built-in scripts that deploy the network attachment storage software's program files, configuration files, and dependent components to a specified storage directory on the terminal device, register system services, and create a startup entry point. After launching the network attachment storage software, users can select to mount local storage media and use it for data sharing and transfer.

[0034] The software installation resources provided by the USB flash drive can solve the problem of terminal devices without network attachment storage software being unable to enable the function, ensuring that legitimate terminal devices can obtain and install compliant network attachment storage software, and guaranteeing the security of software use and data sharing.

[0035] Figure 4 A flowchart of a network-attached storage software deployment method, including a process for enabling file sharing functionality, is provided for embodiments of this application. Figure 4 As shown, the deployment method for network attached storage software based on a USB flash drive specifically includes the following steps: Step S401: When a USB flash drive is detected to be connected and network attached storage software has been installed, the device information of the terminal device is collected, the device information is encrypted to obtain encrypted device information, and the encrypted device information is transmitted to the USB flash drive so that the USB flash drive can decrypt the encrypted device information to obtain the device information. If the device information meets the legal conditions, the pre-generated identity information is encrypted to obtain encrypted identity information, and the encrypted identity information is fed back to the terminal device.

[0036] Step S402: Upon receiving the encrypted identity information, the encrypted identity information is decrypted to obtain the identity information. The identity information is then split into sequence information and a first verification code. The sequence information is verified to obtain a second verification code. If the first verification code and the second verification code are the same, the verification is confirmed to be successful, so that the USB flash drive can send activation information to the terminal device.

[0037] Step S403: Upon receiving activation information, activate the client access rights of the network attachment storage software based on the activation information for data sharing and transmission.

[0038] Step S404: When the file sharing function of the network attachment storage software is triggered, retrieve the file to be transferred from the mounted local storage medium.

[0039] The mounted local storage medium can be a storage medium that has been recognized and managed by the network attachment storage software, and serves as the storage carrier for the file to be transferred. This file can be target data that the user needs for sharing or backup. The network attachment storage software can read the file to be transferred from this local storage medium through a standardized storage access interface.

[0040] Step S405: Send the file to be transmitted to the target terminal device through a preset network link using network attachment storage software, or back up the file to be transmitted to an external mobile storage medium using network attachment storage software.

[0041] The preset network link can be a pre-configured, encrypted, dedicated data transmission channel between the network attachment storage software and the target terminal device. The specific type of the preset network link can support LAN, VPN, encrypted WAN, and the Internet. The target terminal device can be a legitimately authorized terminal receiving the file to be transferred; it is the recipient of the file sharing. Besides sending the file to be transferred to the target terminal device via the preset network link, in some application scenarios, the file can also be backed up to an external removable storage medium. This external removable storage medium can be an external storage device newly connected to the terminal device after the network attachment storage software starts, used for file backup; it can be other USB flash drives, external hard drives, or memory cards, etc.

[0042] As mentioned above, users can flexibly choose between network sharing or offline backup for file processing based on actual needs. This not only meets the needs of real-time data interaction across multiple terminals but also enables offline disaster recovery backup of data, balancing ease of operation and data security.

[0043] Figure 5 A flowchart illustrating a network attached storage software deployment method, including a process for ejecting a USB flash drive, is provided as an embodiment of this application. Figure 5 As shown, the deployment method for network attached storage software based on a USB flash drive specifically includes the following steps: Step S501: When a USB flash drive is detected to be connected and network attached storage software has been installed, the device information of the terminal device is collected, the device information is encrypted to obtain encrypted device information, and the encrypted device information is transmitted to the USB flash drive so that the USB flash drive can decrypt the encrypted device information to obtain the device information. If the device information meets the legal conditions, the pre-generated identity information is encrypted to obtain encrypted identity information, and the encrypted identity information is fed back to the terminal device.

[0044] Step S502: Upon receiving the encrypted identity information, the encrypted identity information is decrypted to obtain the identity information. The identity information is then split into sequence information and a first verification code. The sequence information is verified and calculated to obtain a second verification code. If the first verification code and the second verification code are the same, the verification is confirmed to be successful, so that the USB flash drive can send activation information to the terminal device.

[0045] Step S503: Upon receiving activation information, activate the client access rights of the network attachment storage software based on the activation information for data sharing and transmission.

[0046] Step S504: If the USB flash drive is detected to be removed, disconnect the network attachment storage software from access permissions and stop the enabled service process.

[0047] If the USB drive is detected as being removed, it can be considered a physical disconnection between the terminal device and the USB drive, requiring subsequent mandatory security operations. First, access permissions to the network attachment storage software need to be revoked to reclaim all data access points provided by the software and prohibit any access control operations for the shared service. Furthermore, any running service processes must be stopped; these can be a collection of background processes that support the core functions of the network attachment storage software.

[0048] Step S505: Clear the cached data in memory.

[0049] During operation, network attachment storage software generates non-persistent data that is temporarily stored in the terminal memory. Therefore, it is necessary to clear the cached data in memory and release the cache space it occupies.

[0050] As described above, promptly disconnecting permissions and terminating the process after detecting that the USB drive has been removed allows the USB drive to function as a physical key for unique activation credentials, eliminating the risk of unauthorized access and data leakage. Furthermore, it promptly clears cached data in memory, optimizing terminal resource usage.

[0051] Figure 6 This is a flowchart illustrating another network-attached storage software deployment method provided in an embodiment of this application. This method is applied to a USB flash drive, such as... Figure 6 As shown, the deployment method for network attached storage software based on a USB flash drive specifically includes the following steps: Step S601: Upon receiving encrypted device information sent by the terminal device, the encrypted device information is decrypted to obtain device information. The device information is then compared with a preset device list to determine whether the device information meets the legality requirements.

[0052] When the USB flash drive is inserted into the terminal device, it receives encrypted device information from the terminal device. This encrypted device information may include information such as the terminal device's computer motherboard information, system version, device name, and disk capacity. The USB flash drive decrypts the encrypted device information using either symmetric or asymmetric decryption methods to obtain the device information. The specific decryption method corresponds to the encryption method in the aforementioned embodiments and will not be elaborated upon here. Specifically, after decrypting the encrypted device information, the USB flash drive compares the device information with a preset device list. If the device information is recorded in the preset device list, it can be determined that the device information meets the legality conditions; if the device information is not recorded in the preset device list, it can be determined that the device information does not meet the legality conditions.

[0053] Step S602: If the device information meets the legal conditions, the pre-generated identity information is encrypted to obtain encrypted identity information, and the encrypted identity information is fed back to the terminal device so that the terminal device can decrypt the encrypted identity information to obtain the identity information. The identity information is then split into sequence information and a first check code. The sequence information is verified and calculated to obtain a second check code. If the first check code and the second check code are the same, the verification is confirmed to be successful.

[0054] If the device information meets the legal requirements, the USB flash drive can transmit its identity information to the terminal device for authentication. The identity information can be a unique authorization identifier built into the USB flash drive, used by the terminal device to identify the USB flash drive's legitimate identity. After receiving the encrypted identity information, the terminal device can first decrypt the encrypted identity information to obtain the original identity information, and then parse it. It should be noted that the identity information can consist of two parts: sequence information and a first checksum. The sequence information can be the subject to be verified, while the first checksum can be a check value pre-calculated and generated by the USB flash drive, transmitted along with the sequence information. Therefore, the terminal device can split the identity information according to a pre-negotiated combination rule for the sequence information and the first checksum to obtain the sequence information and the first checksum. After obtaining the sequence information, a second checksum can be calculated to obtain it. This calculation can be a hash algorithm, a cyclic redundancy check algorithm, etc., which are not limited in this application. If the first checksum and the second checksum are the same, the terminal device can confirm that the USB flash drive has passed authentication and determine that the verification is successful.

[0055] Optional, Figure 7 A flowchart illustrating a process for generating identity information is provided in this application embodiment, such as... Figure 7 As shown, the process of generating this identity information includes the following steps: Step S701: Encode the sequence information based on the product attributes, time information and serial number, and concatenate the sequence information with a preset string to obtain the target string.

[0056] The product attributes can be unique hardware parameters of the USB flash drive, such as the main control chip model, firmware version number, storage media type, and batch number. The time information can be the timestamp data used to generate the serial information corresponding to this USB flash drive. The serial number can be an incrementing sequence number maintained by the manufacturer to ensure the global uniqueness of the serial information. These product attributes, time information, and serial number can be converted into a unified format of serial information according to preset rules to uniquely identify the current USB flash drive. The preset string can be a fixed, confidential, and unmodifiable string content jointly pre-stored by the terminal device and the USB flash drive during the authorization phase; it can be called a salt string or a fixed checksum, and serves as fixed supplementary data for this concatenation operation. Concatenating the serial information with the preset string can be a string processing operation performed in a pre-agreed fixed order. Step S702: Convert the target string into a byte array, and perform cyclic redundancy check calculation on the byte array to obtain the first check code.

[0057] After obtaining the target string, it can be converted into a byte array. Specifically, the target string can be converted into an ordered data set composed of several bytes as basic units, according to a unified character encoding format agreed upon by the terminal and the USB flash drive (such as UTF-8 encoding, ASCII encoding, etc.). This byte data can be used as input data for subsequent cyclic redundancy check (CRC) calculations. The CRC calculation can be performed on the input byte array using a specific binary modulo-2 division operation, and the remainder obtained is used as the final verification result, i.e., the first checksum. This first checksum is a fixed-length check value and can serve as the core basis for consistency comparison with the second checksum. It should be noted that only legally paired terminal devices and USB flash drives can generate two consistent checksums, thereby effectively verifying the integrity of the USB flash drive's identity credentials.

[0058] Step S703: Concatenate the sequence information and the first check code to obtain the identity information.

[0059] The sequence information and the first check code are concatenated to obtain the identity information, which can be a unique authorization identifier built into the USB flash drive, used by terminal devices to identify the legitimate identity of the USB flash drive.

[0060] refer to Figure 6 The aforementioned implementation process also includes: Step S603: Feed back activation information to the terminal device so that the terminal device can activate the client usage right of the network attachment storage software based on the activation information upon receiving the activation information.

[0061] After the terminal device completes the verification, the USB flash drive can send activation information back to the terminal device. This activation information can be an authorization credential for the network attachment storage software, specifically including one-time or time-limited authorization codes. If the terminal device has already installed the network attachment storage software, it can directly activate the client-side usage rights of the network attachment storage software based on this activation information. For example, the authorization credential from the activation information can be entered into the network attachment storage software to enable its functions normally.

[0062] The above-mentioned approach effectively filters out unauthorized terminal devices and mitigates the risk of unauthorized activation of network attachment storage software by encrypting device information transmission and verifying the legitimacy of the USB drive. It ensures the integrity and authenticity of identity credentials through decryption and splitting of identity information and verification code comparison. Furthermore, the automated linkage between USB drive access and network attachment storage software activation enhances operational convenience and security. This solution constructs a dual system of "physical key" + "software authentication." At the physical level, a dedicated USB drive serves as the sole activation credential, enabling two-way authentication between the USB drive and the terminal device, reducing the risk of data leakage, improving data security, and offering high flexibility in software deployment.

[0063] Figure 8 This application provides a structural block diagram of a USB flash drive-based network attached storage device. This device is configured to execute the USB flash drive-based network attached storage software deployment method provided in the above embodiments, and possesses the corresponding functional modules and beneficial effects of the method. Figure 8 As shown, the device specifically includes: The first USB flash drive authentication module 801 is configured to, when a USB flash drive is detected to be connected and network attached storage software has been installed, collect device information of the terminal device, encrypt the device information to obtain encrypted device information, and transmit the encrypted device information to the USB flash drive so that the USB flash drive can decrypt the encrypted device information to obtain device information. If the device information is valid, the pre-generated identity information is encrypted to obtain encrypted identity information, and the encrypted identity information is fed back to the terminal device. The first device authentication module 802 is configured to, upon receiving encrypted identity information, decrypt the encrypted identity information to obtain identity information, split the identity information into sequence information and a first verification code, perform verification calculation on the sequence information to obtain a second verification code, and determine that the verification is successful if the first verification code and the second verification code are the same, so that the USB flash drive can send activation information to the terminal device. The first software activation module 803 is configured to activate the client access rights of the network attachment storage software based on the activation information received, for data sharing and transmission.

[0064] The above-mentioned approach effectively filters out unauthorized terminal devices and mitigates the risk of unauthorized activation of network attachment storage software by encrypting device information transmission and verifying the legitimacy of the USB drive. It ensures the integrity and authenticity of identity credentials through decryption and splitting of identity information and verification code comparison. Furthermore, the automated linkage between USB drive access and network attachment storage software activation enhances operational convenience and security. This solution constructs a dual system of "physical key" + "software authentication." At the physical level, a dedicated USB drive serves as the sole activation credential, enabling two-way authentication between the USB drive and the terminal device, reducing the risk of data leakage, improving data security, and offering high flexibility in software deployment.

[0065] In one possible embodiment, the first device authentication module 802 is further configured to: The sequence information is concatenated with a preset string to obtain the target string, and the target string is then converted into a byte array. The second check code is obtained by performing a cyclic redundancy check on the byte array.

[0066] In one possible embodiment, a second software enabling module is also included, configured to: If a USB flash drive is detected and no network attachment storage software is installed, obtain the installation package of the network attachment storage software from the USB flash drive, or obtain the software download address from the USB flash drive and obtain the installation package of the network attachment storage software based on the software download address; Install the network attachment storage software using the installation package, and then start the network attachment storage software for data sharing and transmission.

[0067] In one possible embodiment, a file sharing module is also included, configured as follows: When the file sharing function of the network attachment storage software is triggered, the file to be transferred is retrieved from the mounted local storage medium; The file to be transferred can be sent to the target terminal device via a preset network link using network attachment storage software, or the file to be transferred can be backed up to an external removable storage medium using network attachment storage software.

[0068] In one possible embodiment, a software deactivation module is also included, configured to: If the USB drive is detected to have been removed, disconnect the network attachment storage software from access and stop any enabled service processes. Clear cached data in memory.

[0069] This application also provides another network attached storage device based on a USB flash drive, configured to execute the network attached storage software deployment method based on a USB flash drive provided in the above embodiments, and possessing the corresponding functional modules and beneficial effects of the method. Specifically, the device includes: The second USB flash drive authentication module is configured to, upon receiving encrypted device information sent by the terminal device, decrypt the encrypted device information to obtain the device information, compare the device information with a preset device list, and determine whether the device information meets the legal conditions. The second device authentication module is configured to, when the device information meets the legal conditions, encrypt the pre-generated identity information to obtain encrypted identity information, and feed the encrypted identity information back to the terminal device so that the terminal device can decrypt the encrypted identity information to obtain the identity information, and split the identity information into sequence information and a first check code, perform verification calculation on the sequence information to obtain a second check code, and determine that the verification is successful if the first check code and the second check code are the same. The third software activation module is configured to send activation information back to the terminal device, so that the terminal device can activate the client access rights of the network attachment storage software based on the activation information upon receiving the activation information.

[0070] In one possible embodiment, the process of generating identity information is as follows: The sequence information is obtained by encoding based on product attributes, time information and serial number, and then the sequence information and a preset string are concatenated to obtain the target string; The target string is converted into a byte array, and a cyclic redundancy check is performed on the byte array to obtain the first checksum. The identity information is obtained by concatenating the sequence information and the first check code.

[0071] Figure 9 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application, such as... Figure 9 As shown, the device includes a processor 901, a memory 902, an input device 903, and an output device 904; the number of processors 901 in the device can be one or more. Figure 9 Taking a processor 901 as an example; the processor 901, memory 902, input device 903, and output device 904 in the device can be connected via a bus or other means. Figure 9Taking a bus connection as an example, the memory 902, as a computer-readable storage medium, can be configured to store software programs, computer-executable programs, and modules, such as the program instructions / modules corresponding to the USB flash drive-based network attached storage software deployment method in this embodiment. The processor 901 executes various functional applications and data processing of the device by running the software programs, instructions, and modules stored in the memory 902, thereby implementing the aforementioned USB flash drive-based network attached storage software deployment method. The input device 903 can be configured to receive input digital or character information and generate key signal inputs related to user settings and function control of the device. The output device 904 may include a display screen or other display device.

[0072] The electronic device provided above can be used to execute the network-attached storage software deployment method based on a USB flash drive provided in any of the above embodiments, and has corresponding functions and beneficial effects.

[0073] This application also provides a non-volatile storage medium containing computer-executable instructions. When executed by a computer processor, the computer-executable instructions are configured to execute a USB flash drive-based network attached storage software deployment method described in the above embodiments. The method includes: upon detecting a USB flash drive connection and that network attached storage software has been installed, collecting device information from a terminal device, encrypting the device information to obtain encrypted device information, and transmitting the encrypted device information to the USB flash drive, so that the USB flash drive decrypts the encrypted device information to obtain the device information; if the device information meets legal conditions, encrypting pre-generated identity information to obtain encrypted identity information, and feeding back the encrypted identity information to the terminal device; upon receiving the encrypted identity information, decrypting the encrypted identity information to obtain identity information, splitting the identity information into sequence information and a first checksum, performing verification calculation on the sequence information to obtain a second checksum, and determining that the verification is successful if the first checksum and the second checksum are the same, so that the USB flash drive feeds back activation information to the terminal device; upon receiving the activation information, activating the client's access rights to the network attached storage software based on the activation information for data sharing and transmission.

[0074] Storage medium – any type of memory device or storage device. The term “storage medium” is intended to include: mounting media, such as CD-ROM, floppy disk, or magnetic tape devices; computer system memory or random access memory, such as DRAM, DDR RAM, SRAM, EDO RAM, Rambus RAM, etc.; non-volatile memory, such as flash memory, magnetic media, or optical storage; registers or other similar types of memory elements, etc. Storage medium may also include other types of memory or combinations thereof. Furthermore, storage medium may reside in a first computer system in which the program is executed, or it may reside in a different second computer system connected to the first computer system via a network (such as the Internet). The second computer system can provide program instructions to the first computer for execution. The term “storage medium” may include two or more storage media residing in different locations (e.g., in different computer systems connected via a network). Storage medium may store program instructions (e.g., specifically implemented as a computer program) executable by one or more processors.

[0075] Of course, the computer-executable instructions provided in the embodiments of this application are not limited to the above-mentioned USB flash drive-based network attached storage software deployment method, but can also perform related operations in the USB flash drive-based network attached storage software deployment method provided in any embodiment of this application.

[0076] It is worth noting that in the above embodiments of the network attached storage device based on USB flash drive, the various units and modules included are only divided according to functional logic, but are not limited to the above division, as long as the corresponding functions can be achieved; in addition, the specific names of each functional unit are only for easy differentiation and are not configured to limit the protection scope of the embodiments of this application.

[0077] It should be noted that the numbering of each step in this solution is only used to describe the overall design framework of this solution and does not indicate a necessary sequential relationship between the steps. As long as the overall implementation process conforms to the overall design framework of this solution, it falls within the protection scope of this solution. The order of the text in the description is not an exclusive limitation on the specific implementation process of this solution. Those skilled in the art should understand that the embodiments of this application can be provided as methods, systems, or computer program products. In a typical configuration, a computing device includes one or more processors (CPUs), input / output interfaces, network interfaces, and memory. Memory may include non-persistent memory in computer-readable media, random access memory (RAM), and / or non-volatile memory, such as read-only memory (ROM) or flash RAM. Memory is an example of computer-readable media.

[0078] It should also be noted that the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such process, method, article, or apparatus. Unless otherwise specified, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes that element.

[0079] Note that the above description is merely a preferred embodiment of the present invention and the technical principles employed. Those skilled in the art will understand that the present invention is not limited to the specific embodiments described herein, and various obvious changes, readjustments, and substitutions can be made without departing from the scope of protection of the present invention. Therefore, although the present invention has been described in detail through the above embodiments, the present invention is not limited to the above embodiments, and may include many other equivalent embodiments without departing from the concept of the present invention, the scope of which is determined by the scope of the appended claims.

Claims

1. A method for deploying network attached storage software based on a USB flash drive, characterized in that, Applied to a terminal device, the method includes: When a USB flash drive is detected and network attached storage software is installed, the device information of the terminal device is collected, the device information is encrypted to obtain encrypted device information, and the encrypted device information is transmitted to the USB flash drive so that the USB flash drive can decrypt the encrypted device information to obtain the device information. If the device information meets the legal conditions, the pre-generated identity information is encrypted to obtain encrypted identity information, and the encrypted identity information is fed back to the terminal device. Upon receiving the encrypted identity information, the encrypted identity information is decrypted to obtain the identity information, which is then split into sequence information and a first verification code. The sequence information is then verified to obtain a second verification code. If the first verification code and the second verification code are the same, the verification is confirmed to be successful, so that the USB flash drive can send activation information to the terminal device. Upon receiving the activation information, the client access rights of the network attachment storage software are activated based on the activation information for data sharing and transmission.

2. The method for deploying network attached storage software based on a USB flash drive according to claim 1, characterized in that, The step of verifying the sequence information to obtain the second check code includes: The sequence information is concatenated with a preset string to obtain the target string, and the target string is converted into a byte array; The second check code is obtained by performing a cyclic redundancy check on the byte array.

3. The method for deploying network attached storage software based on a USB flash drive according to claim 1, characterized in that, Also includes: If a USB flash drive is detected and no network attachment storage software is installed, the installation package of the network attachment storage software is obtained from the USB flash drive, or the software download address is obtained from the USB flash drive, and the installation package of the network attachment storage software is obtained based on the software download address. Install the network attachment storage software based on the installation package, and start the network attachment storage software for data sharing and transmission.

4. The method for deploying network attached storage software based on a USB flash drive according to claim 1, characterized in that, After activating the client's access to the network attachment storage software based on the activation information, the method further includes: When the file sharing function of the network attachment storage software is triggered, the file to be transferred is obtained from the mounted local storage medium; The file to be transmitted can be sent to the target terminal device via a preset network link using the network attachment storage software, or the file to be transmitted can be backed up to an external mobile storage medium using the network attachment storage software.

5. The method for deploying network-attached storage software based on a USB flash drive according to claim 1, characterized in that, After activating the client's access to the network attachment storage software based on the activation information, the method further includes: If the USB flash drive is detected to have been removed, disconnect the network attachment storage software from access and stop any enabled service processes. Clear cached data in memory.

6. A method for deploying network attached storage software based on a USB flash drive, characterized in that, Applied to USB flash drives, the method includes: Upon receiving encrypted device information sent by a terminal device, the encrypted device information is decrypted to obtain the device information. The device information is then compared with a preset device list to determine whether the device information meets the legality requirements. If the device information meets the legal conditions, the pre-generated identity information is encrypted to obtain encrypted identity information, and the encrypted identity information is fed back to the terminal device so that the terminal device can decrypt the encrypted identity information to obtain the identity information, and split the identity information into sequence information and a first check code. The sequence information is verified and calculated to obtain a second check code. If the first check code and the second check code are the same, the verification is determined to be successful. The system sends activation information back to the terminal device, so that upon receiving the activation information, the terminal device can activate the client-side usage rights of the network attachment storage software based on the activation information.

7. The method for deploying network attached storage software based on a USB flash drive according to claim 6, characterized in that, The process of generating the identity information is as follows: The sequence information is obtained by encoding based on product attributes, time information and serial number, and the sequence information is concatenated with a preset string to obtain the target string; The target string is converted into a byte array, and a cyclic redundancy check is performed on the byte array to obtain the first check code; The sequence information and the first check code are concatenated to obtain the identity information.

8. A network attached storage device based on a USB flash drive, characterized in that, include: The first USB flash drive authentication module is configured to, upon detecting a USB flash drive connection and having network attached storage software installed, collect device information of the terminal device, encrypt the device information to obtain encrypted device information, and transmit the encrypted device information to the USB flash drive, so that the USB flash drive can decrypt the encrypted device information to obtain the device information. If the device information is valid, the module will encrypt pre-generated identity information to obtain encrypted identity information and feed the encrypted identity information back to the terminal device. The first device authentication module is configured to, upon receiving the encrypted identity information, decrypt the encrypted identity information to obtain the identity information, split the identity information into sequence information and a first verification code, perform verification calculation on the sequence information to obtain a second verification code, and determine that the verification is successful if the first verification code and the second verification code are the same, so that the USB flash drive can send activation information to the terminal device. The first software activation module is configured to, upon receiving the activation information, activate the client access rights of the network attachment storage software based on the activation information for data sharing and transmission.

9. An electronic device, characterized in that, The electronic device includes: one or more processors; and a memory configured to store one or more programs, which, when executed by the one or more processors, cause the one or more processors to implement the network-attached storage software deployment method based on a USB flash drive as described in any one of claims 1-7.

10. A non-volatile storage medium for storing computer-executable instructions, characterized in that, The computer-executable instructions, when executed by a computer processor, are configured to perform the network-attached storage software deployment method based on a USB flash drive as described in any one of claims 1-7.

Citation Information

Patent Citations

  • Method and device for starting program by utilizing USB flash disk based on DES encryption algorithm, and medium

    CN112486590A

  • USB flash disk system authentication method and device, electronic equipment and storage medium

    CN112613011A