A solid state disk power-off data protection and rapid recovery method
Patent Information
- Application Number
- CN202610831397.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-06-10
- Publication Date
- 2026-08-28
AI Technical Summary
[0003]然而,传统固态硬盘异常掉电数据保护方法中,缺乏将闪存物理固有特征、设备唯一硬件信任根和元数据差异化保护机制进行融合的体系,使得状态标记生成、合法性验证和恢复进程调度环节相互割裂,导致未完成元数据易被覆盖、状态标记易被伪造篡改以及恢复过程缺乏优先级管控,难以实现从异常状态捕获到元数据完整恢复的全流程高可靠防护
响应于检测到固态硬盘的供电电压异常跌落,获取当前正在进行写入操作的物理区块的数据状态信息;根据所述数据状态信息确定对应物理区块的数据更新特征,并通过所述数据更新特征中的写入完成标记判定当前元数据的写入状态;若当前元数据未完成写入,则基于当前元数据对应的更新映射关系构建更新保护层级后,将当前元数据存储至映像保护区域,并在存储完成后更新对应的状态标记;重新上电时,对所述状态标记进行顺序验证,若验证有效,则根据所述更新保护层级分阶段激活恢复进程队列,并在所述恢复进程队列执行完成后清除所述状态标记。
Smart Images

Figure CN122654040A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of hard disk data protection technology, and more specifically, to a method for power-loss data protection and rapid recovery of solid-state drives. Background Technology
[0002] Hard drive data protection refers to a data integrity assurance technology system adopted to prevent the loss or damage of user data and management data in the storage system due to factors such as abnormal power outages, hardware failures, and software errors. For solid-state drives (SSDs), which use non-volatile flash memory as the storage medium, although user data can be preserved for a long time after a power outage, the interruption of the metadata writing process can lead to the damage of the logical-physical mapping relationship, thereby causing the entire hard drive to become inaccessible. This technology uses power-loss energy reserves, atomic metadata writing, abnormal state recording, and dedicated image area backup to save the critical data state in a timely manner when an abnormal event occurs, ensuring that the data can be completely restored after the system is restored, thus ensuring the reliability of the storage system.
[0003] However, traditional SSD data protection methods for abnormal power loss lack a system that integrates the inherent physical characteristics of flash memory, the device's unique hardware root of trust, and differentiated metadata protection mechanisms. This results in fragmented processes for status marker generation, validity verification, and recovery process scheduling, leading to the easy overwriting of incomplete metadata, the vulnerability of status markers to forgery and tampering, and a lack of priority control during the recovery process. Consequently, achieving high-reliability protection throughout the entire process, from capturing the abnormal state to fully restoring the metadata, is difficult. Therefore, how to construct an unforgeable metadata protection mechanism within the limited power loss window of SSDs to improve the integrity of metadata after abnormal power loss is a key challenge facing the industry. Summary of the Invention
[0004] This application provides a method for protecting and quickly recovering solid-state drive (SSD) data after power failure. It can build an unforgeable metadata protection mechanism within the limited power loss energy window of the SSD to improve the integrity of metadata after abnormal power failure.
[0005] In a first aspect, this application provides a method for power-loss data protection and rapid recovery of a solid-state drive, the data protection and rapid recovery method comprising: In response to the detection of an abnormal drop in the power supply voltage of the solid-state drive, the data status information of the physical block currently being written is obtained; The data update characteristics of the corresponding physical block are determined based on the data status information, and the write status of the current metadata is determined by the write completion flag in the data update characteristics. If the current metadata has not been written, an update protection layer is constructed based on the update mapping relationship corresponding to the current metadata, the current metadata is stored in the image protection area, and the corresponding status flag is updated after storage is completed. Upon power-on, the status flags are sequentially verified. If the verification is valid, the recovery process queue is activated in stages according to the updated protection level, and the status flags are cleared after the recovery process queue has been completed.
[0006] In this embodiment, determining the data update characteristics of the corresponding physical block based on the data status information specifically includes: Based on the data status information, determine the entropy of the erase / write degradation hysteresis loop and data residence time of the corresponding physical block, and construct the block wear state vector; The block wear state vector is injected into the block interconnect failure propagation map to generate a data update tendency entropy spectrum. The data update tendency entropy spectrum is projected using a hot and cold gradient to output the data update characteristics of the corresponding physical block.
[0007] In this embodiment, determining the current metadata write status through the write completion flag in the data update feature specifically includes: Extract the charge trap feature code of the write completion mark and the block erase cycle phase from the data update features to generate a write state question vector; The write status challenge vector and the device circuit breaker signature are synchronously injected into the time-wrap hash chain to generate a write integrity verification code. The atomic write verification code at the end of the metadata page is matched and decrypted to obtain the current metadata write status. The write status includes determining that the metadata write is complete if the decryption matches, otherwise a checkpoint rollback is triggered.
[0008] In this embodiment, extracting the charge trap feature code of the write completion marker and the block erase / write cycle phase from the data update features to generate the write state challenge vector specifically includes: Based on the charge trap feature code of the write completion marker and the associated attractor of the block erase / write cycle phase in the topological phase space, the write state entropy kernel seed is determined. A time-varying nonlinear tensor expansion is performed using the write state entropy kernel seed and the write timestamp extracted from the data update features to generate a write state question vector.
[0009] In this embodiment, if the current metadata has not been completely written, then after constructing an update protection layer based on the update mapping relationship corresponding to the current metadata, storing the current metadata in the image protection area specifically includes: Based on the current metadata and the corresponding update mapping relationship, extract the inverse dependency graph from logical pages to physical blocks, and construct the update rollback seed vector; The update rollback seed vector and the isolation boundary attribute of the image protection region are mutually entangled to generate a protection level derivation factor. The current metadata is wrapped by write-time redirection using the protection layer derivation factor to generate an image protection region storage structure, and the current metadata is stored in the image protection region.
[0010] In this embodiment, the mutual information entanglement of the update rollback seed vector and the isolation boundary attribute of the image protection region to generate the protection level derivation factor specifically includes: An entangled mapping seed is generated by projecting mutual information between the updated rollback seed vector and the isolation boundary properties of the image protection region. The protection level derivation factor is obtained by indexing the entanglement mapping seed in a pre-set protection level derivation function library.
[0011] In this embodiment, updating the corresponding status flag after storage is completed specifically includes: Entanglement projection is performed based on the mapping snapshot from logical pages to physical blocks after storage is completed and the isolation boundary attributes of the image protection region to generate a state completion entropy kernel; The state completes the mutual information diffusion between the entropy kernel and the storage verification certificate generated in the storage process, generating a marker-derived kernel; The image storage identifier is determined by indexing the preset tag attribute library based on the tag-derived kernel, so as to update the corresponding state tag.
[0012] In this embodiment, the generation of the marker-derived kernel involves mutual information diffusion between the entropy kernel and the storage verification certificate generated in the storage process, based on the state completion process. The state completes the nonlinear mutual information projection of the entropy kernel and the storage verification certificate to generate a diffusion seed vector. The label-derived kernel is determined by indexing the pre-set label-derived kernel library based on the diffusion seed vector.
[0013] In this embodiment, upon power-on, the status flags are sequentially verified. If the verification is valid, the recovery process queue is activated in stages according to the updated protection level, specifically including: Based on the atomic write confirmation token and mirror consistency token read during power-on, a temporal sequential interleaving is performed to generate a verification challenge vector; A one-way hash chain consistency check is performed using the verification challenge vector and the circuit breaker signature of the device trust root. If the check passes, a valid verification token is generated. The protection strength coefficient and recovery phase dependency weight are parsed from the updated protection level, and the recovery process queue is activated sequentially by the valid verification token.
[0014] In this embodiment, clearing the status flag after the recovery process queue has been completed specifically includes: Securely bind the recovery completion certificate vector generated after the recovery process queue is completed with the circuit breaker signature of the device trust root to generate a clearing authorization credential; The storage area of the status marker is overwritten and erased using the clear authorization credential, and the mirror consistency token and atomic write confirmation token are reset to their initial state.
[0015] The technical solutions provided by the embodiments disclosed in this application have the following beneficial effects: In response to the detection of an abnormal drop in the power supply voltage of the solid-state drive, the system acquires the data status information of the physical block currently undergoing a write operation; it determines the data update characteristics of the corresponding physical block based on the data status information, and determines the write status of the current metadata through the write completion flag in the data update characteristics; if the current metadata has not been written, it constructs an update protection layer based on the update mapping relationship corresponding to the current metadata, stores the current metadata in the image protection area, and updates the corresponding status flag after storage is completed; upon power-on, it sequentially verifies the status flag, and if the verification is valid, it activates the recovery process queue in stages according to the update protection layer, and clears the status flag after the recovery process queue has been executed.
[0016] Therefore, in this application, the recovery process queue is activated in stages according to the updated protection level, and the status flag is cleared after the recovery process queue is completed. Determining the current metadata write status yields the true completion status of the metadata write operation and the unalterable integrity verification result, thus accurately distinguishing between valid metadata that has been written and metadata that is not yet written and awaits protection. This avoids redundant protection operations on complete metadata, significantly reducing the execution time and energy consumption of the power-down protection process. Based on the flash memory physical charge trap characteristics and the time-wound hash chain determination mechanism, it can effectively resist software flag tampering and replay attacks, ensuring the uniqueness and unforgeability of the write status determination result. By constructing and updating the protection layer, the protection strength level and recovery execution priority parameters of the metadata can be obtained. This allows for the implementation of differentiated storage and encapsulation strategies based on the importance and impact of the metadata. Within a limited power outage energy window, the safe storage of core metadata is prioritized, preventing the loss of critical metadata due to energy depletion. Based on the protection layer derivation factor generated by mutual information entanglement, the metadata update characteristics are deeply bound to the isolation boundary attributes of the image protection area. This ensures that the protection layer parameters have device uniqueness and non-forgeability, guaranteeing that metadata of different importance can obtain protection strength commensurate with its risk level, thereby improving the overall reliability of the metadata protection mechanism.
[0017] In summary, the technical solution adopted in this application can construct an unforgeable metadata protection mechanism within the limited power loss energy window of a solid-state drive (SSD) to improve the integrity of metadata after an abnormal power loss. Attached Figure Description
[0018] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only for this embodiment of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0019] Figure 1 This is an exemplary flowchart of a solid-state drive power-loss data protection and rapid recovery method provided in this application; Figure 2 This is a flowchart illustrating the process for determining the current metadata write status, as provided in this application. Figure 3 This is based on the schematic diagram of solid-state drive abnormal power loss metadata protection provided in this application. Detailed Implementation
[0020] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.
[0021] This application provides a method for power-loss data protection and rapid recovery of a solid-state drive (SSD). The core of this method is to respond to a detected abnormal drop in the SSD's power supply voltage by acquiring the data status information of the physical block currently undergoing a write operation; determining the data update characteristics of the corresponding physical block based on the data status information, and judging the current metadata's write status through the write completion flag in the data update characteristics; if the current metadata has not been written, then after constructing an update protection layer based on the update mapping relationship corresponding to the current metadata, storing the current metadata in the image protection area, and updating the corresponding status flag after storage is completed; upon power-on, sequentially verifying the status flag; if the verification is valid, activating the recovery process queue in stages according to the update protection layer, and clearing the status flag after the recovery process queue has been executed.
[0022] To better understand the above technical solutions, a detailed description of the technical solutions will be provided below in conjunction with the accompanying drawings and specific embodiments. (Refer to...) Figure 1 As shown in the figure, this is an exemplary flowchart of a solid-state drive power-loss data protection and rapid recovery method according to this embodiment of the application. The data protection and rapid recovery method includes the following steps: In step S1, in response to detecting an abnormal drop in the power supply voltage of the solid-state drive, the data status information of the physical block currently being written is obtained.
[0023] In specific implementation, the response to the detection of an abnormal drop in the power supply voltage of the solid-state drive can be achieved in the following way: a high-precision resistor voltage divider sampling circuit is built into the power management module of the solid-state drive to continuously collect the instantaneous value of the input power supply voltage at a fixed frequency of 1 microsecond. The collected voltage value is compared with a preset abnormal threshold, which is usually 85% of the rated operating voltage. When the voltage value is lower than the threshold for three consecutive sampling cycles, it is determined that an abnormal drop in the power supply voltage has occurred. At this time, the main control chip immediately triggers the highest priority non-maskable interrupt, forcibly suspends all new user write requests, and freezes the internal write status register, cache write pointer, and temporary updates of the logical-physical mapping table.
[0024] It should be noted that, in this application, abnormal power supply voltage drop refers to an abnormal power supply state in which the input voltage of the solid-state drive drops below the normal operating limit for a short period of time, and the duration is sufficient to interrupt the write operation.
[0025] In addition, in specific implementation, the data status information of the physical block currently undergoing a write operation can be obtained in the following way: After a non-maskable interrupt is triggered, the SSD controller immediately reads the internally maintained write task scheduling queue. This queue records all write tasks in execution status in real time. The controller extracts the physical block number and flash channel number corresponding to each incomplete write task from the queue. Through the flash controller of the corresponding channel, it reads the status field in the header of the target physical block's status page, including the write start offset, the number of bytes written, the current write pointer position, and the operation validity flag. Simultaneously, it reads the write context information of the corresponding physical block from the controller cache, including the remaining length of the data to be written and the pre-calculated checksum. All the read information is used as the data status information of the corresponding physical block.
[0026] It should be noted that, in this application, a write operation refers to the complete data transfer process in which the solid-state drive controller writes user data or management data from the cache to the non-volatile storage medium; a physical block refers to the smallest independent addressable non-volatile storage unit in a solid-state drive; and data status information refers to a set of management information used to record the writing progress of physical blocks, the integrity of the written data, and the validity of the operation.
[0027] In step S2, the data update characteristics of the corresponding physical block are determined based on the data status information, and the write status of the current metadata is determined by the write completion flag in the data update characteristics.
[0028] In this embodiment, the data update characteristics of the corresponding physical block can be determined based on the data status information in the following manner: Based on the data status information, determine the entropy of the erase / write degradation hysteresis loop and data residence time of the corresponding physical block, and construct the block wear state vector; The block wear state vector is injected into the block interconnect failure propagation map to generate a data update tendency entropy spectrum. The data update tendency entropy spectrum is projected using a hot and cold gradient to output the data update characteristics of the corresponding physical block.
[0029] In specific implementation, firstly, the historical erase / write counts, average write latency after each erase / write, current data write time, and current system time of the target physical block are extracted from the data status information. The Pearson correlation coefficient calculation method can be used to calculate the correlation entropy between data dwell time and average write latency. Based on the three feature point values of the erase / write degradation hysteresis loop of this type of flash memory chip pre-stored, they are concatenated in the order of historical erase / write counts, correlation entropy, and feature point values to generate a one-dimensional block wear state vector. Then, a pre-built block interconnect failure propagation map is loaded. This map uses each physical block as a node, with the failure propagation probability between adjacent blocks in the same channel as the edge weight. The block wear state vector is used as the initial state value of the corresponding node, and a random walk algorithm is used for a preset number of iterations (ranging from 50 to 200). The final state update probability of each node is sorted by number to generate a data update tendency entropy spectrum. Finally, a one-dimensional hot-cold gradient coordinate axis is pre-constructed, with the two ends corresponding to hot data and cold data respectively. The update probability value corresponding to the target physical block in the data update tendency entropy spectrum is used as the ordinate of the projection point. A linear projection algorithm can be used to project the projection point onto the hot-cold gradient coordinate axis. The relative position of the projection point on the coordinate axis is calculated. Based on the preset three interval division thresholds, the data update characteristics of the corresponding physical block are determined to be hot data, warm data, or cold data update characteristics.
[0030] It should be noted that, in this application, the erase / write degradation hysteresis loop refers to the characteristic curve of the hysteresis correspondence between the number of physical block erases / writes and the write performance degradation; the data residence time correlation entropy refers to the statistic that quantifies the correlation between data residence time and block write performance; the block wear state vector refers to a one-dimensional vector spliced together by block wear-related characteristic parameters in a fixed order; the block interconnect failure propagation graph refers to a directed graph with physical blocks as nodes and failure propagation probabilities as edge weights; the data update tendency entropy spectrum refers to the sequence of update probabilities of each block arranged according to the physical block number; the cold and hot gradient projection refers to the projection method that maps the data update tendency entropy spectrum to the cold and hot data dimensions; and the data update feature refers to the feature identifier that describes the data update frequency and access popularity within a physical block.
[0031] Preferably, in this embodiment, the write status of the current metadata is determined by the write completion flag in the data update feature, with reference to... Figure 2 As shown in the figure, this is a flowchart illustrating the process of determining the current metadata write status in some embodiments of this application. In this embodiment, determining the current metadata write status can be achieved using the following steps: In step S21, the charge trap feature code of the write completion mark and the block erase cycle phase are extracted from the data update features to generate the write state question vector; In step S22, the write status challenge vector and the device circuit breaker feature code are synchronously injected into the time-wrap hash chain to generate a write integrity verification code; In step S23, the atomic write evidence at the end of the metadata page is matched and decrypted using the write integrity verification code to obtain the current metadata write status. The write status includes determining that the metadata write is complete if the decryption matches, otherwise a checkpoint rollback is triggered.
[0032] In practice, firstly, the threshold voltage distribution characteristics of the flash memory cells corresponding to the target metadata block are read from the data update characteristics. A predefined charge trap feature code is extracted. This charge trap feature code is an inherent physical identifier formed by the natural charge trapping after the flash memory cell is written. Simultaneously, the phase value of the current erase / write cycle of the physical block is read from the block status page. This phase value is a counter value that automatically increments after each erase operation. The charge trap feature code and the block erase / write cycle phase are concatenated in a fixed byte order to generate a fixed-length write status challenge vector, which is stored in the controller's dedicated verification cache. Then, the SSD controller pre-maintains a time-wrap hash chain based on the SHA-256 algorithm. This time-wrap hash chain automatically updates its head at fixed time intervals and retains the most recently preset number of historical chain nodes. The write status challenge vector is concatenated byte-by-byte with the device fuse feature code stored in the controller's one-time programmable area. The concatenated result is XORed with the latest head of the hash chain and then input into the SHA-256 algorithm for hash calculation to generate a fixed-length write integrity verification code. Finally, the encrypted verification value stored in the evidence storage area is read from the end of the target metadata page. This encrypted verification value is generated and encrypted during the metadata writing process. Using the write integrity verification code as the key, the encrypted verification value can be decrypted using the AES-ECB decryption algorithm. If the decryption result is completely consistent with the preset fixed verification string, the metadata writing is determined to be complete; if the decryption fails or the result does not match, the writing is determined to be incomplete, and the rollback operation of the previous valid checkpoint is automatically triggered.
[0033] It should be noted that, in this application, the charge trap feature code of the write completion marker refers to a unique identifier generated based on the inherent physical characteristics of the natural charge trapping after the flash memory cell is written; the current metadata refers to the solid-state drive management data that is in the process of writing and has not yet completed all write operations when the current abnormal drop in power supply voltage occurs; the block erase / write cycle phase refers to the identifier of the physical block in the current erase / write cycle; the write state question vector refers to the vector formed by concatenating the charge trap feature code and the block erase / write cycle phase; the device fuse feature code refers to the unique, tamper-proof identifier written once at the solid-state drive when it leaves the factory; the time-wrap hash chain refers to the hash chain structure that is updated periodically at fixed time intervals; the write integrity verification code refers to the unique verification value generated by the time-wrap hash chain; the metadata page tail refers to the fixed-length dedicated area pre-divided at the end of the metadata physical page; the atomic write proof refers to the dedicated storage area reserved at the end of the metadata page; the matching decryption refers to decrypting the atomic write proof value using the generated write integrity verification code as the key; and the checkpoint rollback refers to the operation of restoring the metadata to the previous complete and valid state.
[0034] In addition, in this embodiment, the charge trap feature code of the write completion mark and the block erase / write cycle phase are extracted from the data update features to generate the write state challenge vector, which can be achieved by the following steps: Based on the charge trap feature code of the write completion marker and the associated attractor of the block erase / write cycle phase in the topological phase space, the write state entropy kernel seed is determined. A time-varying nonlinear tensor expansion is performed using the write state entropy kernel seed and the write timestamp extracted from the data update features to generate a write state question vector.
[0035] In specific implementation, firstly, a two-dimensional topological phase space can be constructed based on experimental data from successful write operations of multiple sets of flash memory chips of different models. The horizontal axis represents the normalized charge trap feature code, and the vertical axis represents the normalized block erase / write cycle phase. The K-means clustering algorithm is used to cluster historical feature points. The number of clusters can be set to 8 to balance accuracy and computation. The number of clusters can be verified experimentally based on different chips, and is not limited here. Eight stable associated attractor centers are obtained. The current charge trap feature code and block erase / write cycle phase are mapped to this topological phase space, and the Euclidean distance to each attractor center is calculated. The coordinate value of the nearest attractor center is taken as the seed of the write state entropy kernel. Then, the write state entropy kernel seed is converted into an initial 2×2 two-dimensional tensor. The precise timestamp of this write operation is extracted from the data update features and decomposed into six independent time-varying parameters: year, month, day, hour, minute, and second. Tensor product operation can be used to sequentially perform tensor product operation on the initial tensor and the six time-varying parameters, gradually expanding it into an eight-dimensional tensor. The expanded high-dimensional tensor is then expanded into a one-dimensional vector in row-major order, and the first 256 bits are truncated as the final write state question vector.
[0036] It should be noted that, in this application, the topological phase space refers to the two-dimensional mathematical space that represents the stable correlation between the charge trap feature code and the phase of the block erase / write cycle; the correlation attractor refers to the convergence point in the topological phase space that characterizes the stable correspondence between the charge trap feature code and the phase of the block erase / write cycle under a successful write operation; the write state entropy kernel seed refers to the initial core value used to generate the write state question vector; the write timestamp refers to the precise time identifier that records the start time of this metadata write operation; and the time-varying nonlinear tensor expansion refers to the mathematical transformation method that expands low-dimensional seed data into a high-dimensional vector based on time dimension information.
[0037] In step S3, if the current metadata has not been written, the update protection layer is constructed based on the update mapping relationship corresponding to the current metadata, the current metadata is stored in the image protection area, and the corresponding status flag is updated after storage is completed.
[0038] In this embodiment, if the current metadata has not been completely written, the following steps can be used to store the current metadata in the image protection area after constructing an update protection layer based on the update mapping relationship corresponding to the current metadata: Based on the current metadata and the corresponding update mapping relationship, extract the inverse dependency graph from logical pages to physical blocks, and construct the update rollback seed vector; The update rollback seed vector and the isolation boundary attribute of the image protection region are mutually entangled to generate a protection level derivation factor. The current metadata is wrapped by write-time redirection using the protection layer derivation factor to generate an image protection region storage structure, and the current metadata is stored in the image protection region.
[0039] In specific implementation, firstly, all logical page numbers involved in this update are extracted from the current metadata. Then, the physical block number corresponding to each logical page is matched from the update mapping relationship. A directed graph construction method can be used, with physical blocks as nodes and the dependencies of logical pages on physical blocks as directed edges, to generate a reverse dependency graph. The adjacency matrix of the reverse dependency graph is expanded into a one-dimensional array in row-major order, and the array is hashed using the SHA-256 algorithm. The resulting hash value is used as the update rollback seed vector. Next, the quantified attribute values of the physical isolation level, power supply independence level, and write reliability level of the image protection region are extracted. A mutual information calculation method can be used to calculate the mutual information between the entropy value of the update rollback seed vector and the entropy value of each attribute. The three mutual information values are then weighted and summed. The weights are determined based on the degree of influence of each attribute on the protection effect. The range of weight values can be determined through power outage simulation experiments. The summation result is normalized to the interval between 0 and 1 to obtain the protection level derivation factor. Finally, based on the preset value range of the protection level derivation factor, three protection levels are divided, corresponding to different storage encapsulation strategies. By modifying the write address mapping register in the solid-state drive controller chip, the write address originally planned to be written to the ordinary metadata area is redirected to the free address of the image protection area. Cyclic redundancy check information, backup fragments, and status identifiers are added to the metadata according to the corresponding protection level to generate a standardized image protection area storage structure. After writing the image protection area storage structure to the specified address, the free address management table of the image protection area is updated.
[0040] It should be noted that in this application, "update mapping relationship" refers to management information that records the correspondence between logical and physical addresses before and after changes during the metadata update process; "update protection level" refers to the protection level divided according to the importance and scope of impact of metadata; "image protection region" refers to a pre-defined, highly reliable dedicated area with independent power supply in a solid-state drive; "logical page" refers to the smallest logical addressing unit used by the operating system when accessing the solid-state drive; "physical block" refers to the smallest erasable storage unit in the solid-state drive flash memory chip; "inverse dependency graph" refers to a graph that records the dependency relationship between physical blocks and corresponding logical page metadata; "update rollback seed vector" refers to a feature vector that identifies the metadata update operation; "isolation boundary attribute" is a set of inherent attributes characterizing the physical isolation, power supply independence, and write reliability between the image protection region and the ordinary storage region; "mutual information entanglement" refers to a statistical calculation method that quantifies the correlation between the update rollback seed vector and the isolation boundary attribute; "protection level derivation factor" refers to a quantitative parameter used to determine the metadata protection priority and storage encapsulation method; "write-time redirection wrapping" refers to redirecting metadata originally planned to be written to the ordinary region to the image protection region; and "image protection region storage structure" refers to the standardized format used to organize and store metadata and protection information in the image protection region.
[0041] In addition, in this embodiment, the mutual information entanglement of the update rollback seed vector and the isolation boundary attribute of the image protection region to generate the protection level derivation factor can be achieved by the following steps: An entangled mapping seed is generated by projecting mutual information between the updated rollback seed vector and the isolation boundary properties of the image protection region. The protection level derivation factor is obtained by indexing the entanglement mapping seed in a pre-set protection level derivation function library.
[0042] In specific implementation, firstly, the update rollback seed vector and the isolation boundary attributes of the image protection region are normalized to a unified numerical range of 0 to 1, respectively, to construct a two-dimensional mutual information projection matrix. The rows correspond to the feature dimensions of the seed vector, and the columns correspond to the three dimensions of the isolation boundary attributes. Mutual information calculation methods can be used to calculate the mutual information value between each pair of dimensions and fill it into the matrix. Singular value decomposition is performed on the projection matrix to extract the unit feature vector corresponding to the largest singular value, which serves as the entanglement mapping seed. Then, a protection level derivation function library is pre-installed before the solid-state drive leaves the factory. This protection level derivation function library can be constructed based on experimental data from multiple sets of different flash memory chips and different power-loss scenarios. There are no restrictions here. Each index value corresponds to a unique protection level derivation factor. The entanglement mapping seed is converted into an integer index value according to a preset rule. Direct addressing lookup is performed in the function library using this integer index value to obtain the corresponding protection level derivation factor.
[0043] It should be noted that, in this application, mutual information projection refers to mapping the update rollback seed vector and the isolation boundary attribute to a unified feature space; entanglement mapping seed refers to the intermediate identifier for finding the corresponding derived factor in the protection layer derived function library using the unique index value; the protection layer derived function library refers to the lookup table pre-installed on the solid-state drive before it leaves the factory, which stores protection layer derived factors corresponding to different degrees of association.
[0044] In this embodiment, updating the corresponding status flag after storage is completed can be achieved using the following steps: Entanglement projection is performed based on the mapping snapshot from logical pages to physical blocks after storage is completed and the isolation boundary attributes of the image protection region to generate a state completion entropy kernel; The state completes the mutual information diffusion between the entropy kernel and the storage verification certificate generated in the storage process, generating a marker-derived kernel; The image storage identifier is determined by indexing the preset tag attribute library based on the tag-derived kernel, so as to update the corresponding state tag.
[0045] In specific implementation, firstly, after the metadata is written to the image protection region, a mapping snapshot of the current logical page to the physical block is immediately generated. This snapshot contains the final mapping relationship between all logical pages involved in this update and their corresponding physical blocks. The mapping snapshot is converted into a one-dimensional feature vector and concatenated with the normalized isolation boundary attribute vector. Principal component analysis can be used to reduce the dimensionality of the concatenated vector, and the first principal component is extracted as the state completion entropy kernel. Then, the storage verification certificate generated synchronously during the metadata storage process is read. This storage verification certificate is the result of concatenating the cyclic redundancy check value of the metadata with the write completion timestamp. The information entropy of the state completion entropy kernel and the storage verification certificate are calculated separately. The mutual information value between the two can be calculated using the mutual information calculation method. The state completion entropy kernel and the mutual information value are then XORed bitwise. The result is then hashed using the SHA-256 algorithm to generate a fixed-length tag derivation kernel. Finally, a tag attribute library is pre-installed before the solid-state drive leaves the factory. This tag attribute library is built based on the storage characteristics and power loss protection requirements of different types of flash memory chips. Each index value corresponds to a unique and valid image storage identifier. The tag-derived core is converted into an integer index value according to a preset bit width truncation rule. The corresponding image storage identifier is found in the tag attribute library through direct addressing. The image storage identifier is written into the status tag field of the image protection area header. At the same time, the checksum field of the status tag is updated to complete the status tag update.
[0046] It should be noted that, in this application, a mapping snapshot refers to an instantaneous copy of the final logical-physical correspondence of the current update recorded when metadata storage is completed; entanglement projection refers to the calculation process of fusing the mapping snapshot and isolation boundary attributes into a unified feature space; state completion entropy kernel refers to the feature value of the actual completed state of this metadata storage operation; storage verification and evidence storage refers to the integrity verification information generated synchronously during the process of writing metadata into the image protection area; mutual information diffusion refers to the calculation method of deeply fusing the features of the state completion entropy kernel and storage verification and evidence storage; tag derivation kernel refers to the intermediate feature value of indexing in the tag attribute library; tag attribute library refers to the standardized lookup table pre-installed by the solid-state drive before it leaves the factory; image storage identifier refers to the identifier that there is complete and valid metadata to be recovered in the image protection area; and state tag refers to a dedicated management identifier used to identify the validity and related attributes of the metadata to be recovered.
[0047] Furthermore, in this embodiment, the generation of the tag-derived kernel can be achieved by performing mutual information diffusion between the entropy kernel and the storage verification certificate generated in the storage process through the state completion entropy kernel, as follows: The state completes the nonlinear mutual information projection of the entropy kernel and the storage verification certificate to generate a diffusion seed vector. The label-derived kernel is determined by indexing the pre-set label-derived kernel library based on the diffusion seed vector.
[0048] In practical implementation, firstly, the state completion entropy kernel and storage verification certificate are normalized to a unified numerical range of 0 to 1. A Gaussian kernel function can be used to construct a nonlinear mutual information calculation model. The kernel width parameter can be determined based on the statistical distribution of multiple sets of historical storage data, which is not limited here. The nonlinear mutual information matrix between two eigenvectors is calculated. Singular value decomposition is performed on the nonlinear mutual information matrix, and the eigenvectors corresponding to the two largest singular values are extracted and concatenated to generate a diffusion seed vector. Then, a pre-configured tag-derived kernel library is installed on the solid-state drive before it leaves the factory. Each index value corresponds to a unique tag-derived kernel. The diffusion seed vector is converted into an integer index value according to a preset bit-width truncation rule. A single-cycle lookup operation is performed in the tag-derived kernel library through the direct addressing circuit of the main control hardware to obtain the corresponding tag-derived kernel.
[0049] It should be noted that in this application, nonlinear mutual information projection refers to a feature fusion method that uses a nonlinear kernel function to quantify the state and complete the complex relationship between the entropy kernel and the storage verification evidence; diffusion seed vector refers to the output result of nonlinear mutual information projection; and the tag-derived kernel library refers to the standardized lookup table pre-installed on the solid-state drive before it leaves the factory.
[0050] In step S4, upon power-on, the status flag is sequentially verified. If the verification is valid, the recovery process queue is activated in stages according to the updated protection level, and the status flag is cleared after the recovery process queue has been completed.
[0051] In this embodiment, upon power-on, the status flags are sequentially verified. If the verification is valid, the recovery process queue is activated in stages according to the updated protection level, which can be achieved through the following steps: Based on the atomic write confirmation token and mirror consistency token read during power-on, a temporal sequential interleaving is performed to generate a verification challenge vector; A one-way hash chain consistency check is performed using the verification challenge vector and the circuit breaker signature of the device trust root. If the check passes, a valid verification token is generated. The protection strength coefficient and recovery phase dependency weight are parsed from the updated protection level, and the recovery process queue is activated sequentially by the valid verification token.
[0052] In practice, firstly, after the solid-state drive (SSD) is powered on again and completes hardware initialization, the atomic write confirmation token and image consistency token are read from the status flag in the image protection region header. A time-domain sequential interleaving technique can be used to alternately concatenate the two tokens at fixed intervals of 4 bits each. The lower 16 bits of the current power-on timestamp are inserted at the end of the concatenated vector to generate a fixed-length verification challenge vector. Next, the circuit breaker signature of the device trust root stored in the one-time programmable area of the main controller is read and concatenated byte-wise with the verification challenge vector. The concatenation result is input into a preset SHA-256 one-way hash function for calculation to obtain the current hash value. The current hash value is then compared bit-by-bit with the hash chain node values stored in the status flag. If they match completely, the verification is considered successful, and an internal valid verification token is generated. Finally, after the valid token is generated, the updated protection level field is read from the status flag, and the protection strength coefficient and recovery stage dependency weight are parsed according to the preset bit field division rules. The preset recovery process templates are sorted according to the size of the recovery stage dependency weight. The recovery process with higher weight has higher priority. The highest priority recovery process is triggered by the valid token. After the process is completed and returns a success signal, the next priority recovery process is activated in turn until all recovery processes are completed.
[0053] It should be noted that in this application, sequential verification refers to the verification process of checking the integrity and legality of each field of the status flag in a preset fixed order when power is restarted; phased activation refers to the operation of starting the recovery process sequentially according to the priority of the updated protection level; atomic write confirmation token refers to a special verification identifier used to identify the actual completion of the atomic write operation of metadata; image consistency token refers to a special verification identifier used to verify the integrity and consistency of metadata within the image protection area; temporal sequential interleaving unwrapping refers to a feature fusion method that splices two verification tokens bit-level in a fixed order of time dimension; verification challenge vector refers to the input feature vector used to initiate the legality verification of the status flag; the device trust root fuse feature code refers to the immutable unique hardware identifier that is written once to the one-time programmable area of the main controller when the solid-state drive is manufactured; one-way hash chain consistency verification refers to a cryptographic method that verifies the legality and integrity of data based on the irreversible property of one-way hash function; verification valid token refers to the internal authorization identifier generated after the status flag verification is passed; protection strength coefficient is a level characterizing the required protection strength of metadata; recovery stage dependency weight is a characterizing the dependency relationship and execution priority between different recovery stages; and recovery process queue refers to a set of metadata recovery tasks arranged according to recovery priority.
[0054] In this embodiment, clearing the status flag after the recovery process queue has been completed can be achieved by the following steps: Securely bind the recovery completion certificate vector generated after the recovery process queue is completed with the circuit breaker signature of the device trust root to generate a clearing authorization credential; The storage area of the status marker is overwritten and erased using the clear authorization credential, and the mirror consistency token and atomic write confirmation token are reset to their initial state.
[0055] In practice, firstly, after the last process in the recovery process queue completes, the completion verification values returned by all recovery processes are collected and concatenated into a one-dimensional array according to the recovery execution order. A recovery completion timestamp is added to the end of the array to generate a recovery completion evidence vector. This vector is then concatenated byte-wise with the circuit breaker signature of the device trust root stored in the one-time programmable area of the main controller, and input into the SHA-256 one-way hash function for calculation to generate a fixed-length clearing authorization credential. Next, the generated clearing authorization credential is compared bit-by-bit with the expected credential pre-calculated internally by the main controller. If they match, a status mark clearing operation is triggered. The flash memory controller performs an atomic overwrite erase operation on the physical page containing the status mark, overwriting the mirror consistency token and atomic write confirmation token fields byte-by-byte with an all-zero initial value, while simultaneously updating the cyclic redundancy check value of the status mark area.
[0056] It should be noted that in this application, the recovery completion evidence vector refers to the set of feature vectors generated after all recovery processes are completed; secure binding refers to the cryptographic operation of irreversibly fusing the recovery completion evidence with the device's unique hardware identifier; clearing authorization credential refers to the cryptographic credential that uniquely authorizes the execution of the status mark clearing operation; overwrite erasure refers to the operation of overwriting the status mark storage area byte by byte with a preset initial value; and the initial state refers to the default value when the status mark does not store valid metadata to be recovered.
[0057] In this embodiment, reference Figure 3 As shown in the diagram, this is a schematic diagram of the solid-state drive (SSD) abnormal power loss metadata protection principle. In this schematic diagram, the SSD storage array on the left serves as the basic storage carrier for user data and metadata. Its power input is continuously monitored by the voltage detection module above using a high-frequency sampling method. When an abnormal drop in power supply voltage is detected, the protection process module is immediately triggered. This module suspends all new write requests, obtains the data status information of the currently active physical blocks being written, determines the integrity of the metadata write, constructs a differentiated update protection level for the metadata that has not been written, and then writes the metadata to be protected into the image protection area with independent power supply, and updates the status flags simultaneously. After power is restored, the system first reads the status flags of the image protection area for legality verification. After successful verification, the metadata recovery operation is performed in stages according to the protection level. After all recovery is completed, the status flags are cleared, and finally the SSD returns to normal operation.
[0058] Therefore, in this application, the recovery process queue is activated in stages according to the updated protection level, and the status flag is cleared after the recovery process queue is completed. Determining the current metadata write status yields the true completion status of the metadata write operation and the unalterable integrity verification result, thus accurately distinguishing between valid metadata that has been written and metadata that is not yet written and awaits protection. This avoids redundant protection operations on complete metadata, significantly reducing the execution time and energy consumption of the power-down protection process. Based on the flash memory physical charge trap characteristics and the time-wound hash chain determination mechanism, it can effectively resist software flag tampering and replay attacks, ensuring the uniqueness and unforgeability of the write status determination result. By constructing and updating the protection layer, the protection strength level and recovery execution priority parameters of the metadata can be obtained. This allows for the implementation of differentiated storage and encapsulation strategies based on the importance and impact of the metadata. Within a limited power outage energy window, the safe storage of core metadata is prioritized, preventing the loss of critical metadata due to energy depletion. Based on the protection layer derivation factor generated by mutual information entanglement, the metadata update characteristics are deeply bound to the isolation boundary attributes of the image protection area. This ensures that the protection layer parameters have device uniqueness and non-forgeability, guaranteeing that metadata of different importance can obtain protection strength commensurate with its risk level, thereby improving the overall reliability of the metadata protection mechanism.
[0059] In summary, the technical solution adopted in this application can construct an unforgeable metadata protection mechanism within the limited power loss energy window of a solid-state drive (SSD) to improve the integrity of metadata after an abnormal power loss.
[0060] This application is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of this application. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.
[0061] Those skilled in the art will understand that all or part of the steps in the various methods of the above embodiments can be implemented by a program instructing related hardware. The program can be stored in a computer-readable storage medium, including read-only memory (ROM), random access memory (RAM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), one-time programmable read-only memory (OTPROM), electrically-Erasable Programmable Read-Only Memory (EEPROM), compactdisc read-only memory (CD-ROM) or other optical disc storage, disk storage, magnetic tape storage, or any other computer-readable medium capable of carrying or storing data.
[0062] It should also be noted that the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such process, method, article, or apparatus. Unless otherwise specified, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes that element.
Claims
1. A method for power-loss data protection and rapid recovery of a solid-state drive, characterized in that, The data protection and rapid recovery method includes: In response to the detection of an abnormal drop in the power supply voltage of the solid-state drive, the data status information of the physical block currently being written is obtained; The data update characteristics of the corresponding physical block are determined based on the data status information, and the write status of the current metadata is determined by the write completion flag in the data update characteristics. If the current metadata has not been written, an update protection layer is constructed based on the update mapping relationship corresponding to the current metadata, the current metadata is stored in the image protection area, and the corresponding status flag is updated after storage is completed. Upon power-on, the status flags are sequentially verified. If the verification is valid, the recovery process queue is activated in stages according to the updated protection level, and the status flags are cleared after the recovery process queue has been completed.
2. The method for power-loss data protection and rapid recovery of a solid-state drive as described in claim 1, characterized in that, Determining the data update characteristics of the corresponding physical block based on the data status information specifically includes: Based on the data status information, determine the entropy of the erase / write degradation hysteresis loop and data residence time of the corresponding physical block, and construct the block wear state vector; The block wear state vector is injected into the block interconnect failure propagation map to generate a data update tendency entropy spectrum. The data update tendency entropy spectrum is projected using a hot and cold gradient to output the data update characteristics of the corresponding physical block.
3. The method for power-loss data protection and rapid recovery of a solid-state drive as described in claim 1, characterized in that, Determining the write status of the current metadata through the write completion flag in the data update feature specifically includes: Extract the charge trap feature code of the write completion mark and the block erase cycle phase from the data update features to generate a write state question vector; The write status challenge vector and the device circuit breaker feature code are synchronously injected into the time-wrap hash chain to generate a write integrity verification code. The atomic write verification code at the end of the metadata page is matched and decrypted to obtain the current metadata write status. The write status includes determining that the metadata write is complete if the decryption matches, otherwise a checkpoint rollback is triggered.
4. The method for power-loss data protection and rapid recovery of a solid-state drive as described in claim 3, characterized in that, Extracting the charge trap feature code of the write completion marker and the block erase / write cycle phase from the data update features, and generating the write state challenge vector specifically includes: Based on the charge trap feature code of the write completion marker and the associated attractor of the block erase / write cycle phase in the topological phase space, the write state entropy kernel seed is determined. A time-varying nonlinear tensor expansion is performed using the write state entropy kernel seed and the write timestamp extracted from the data update features to generate a write state question vector.
5. A method for power-loss data protection and rapid recovery of a solid-state drive as described in claim 1, characterized in that, If the current metadata has not been written, then after constructing an update protection layer based on the update mapping relationship corresponding to the current metadata, the current metadata is stored in the image protection area, specifically including: Based on the current metadata and the corresponding update mapping relationship, extract the inverse dependency graph from logical pages to physical blocks, and construct the update rollback seed vector; The update rollback seed vector and the isolation boundary attribute of the image protection region are mutually entangled to generate a protection level derivation factor. The current metadata is wrapped by write-time redirection using the protection layer derivation factor to generate an image protection region storage structure, and the current metadata is stored in the image protection region.
6. The method for power-loss data protection and rapid recovery of a solid-state drive as described in claim 5, characterized in that, The process of mutual information entanglement between the updated rollback seed vector and the isolation boundary attribute of the image protection region to generate the protection level derivation factor specifically includes: An entangled mapping seed is generated by projecting mutual information between the updated rollback seed vector and the isolation boundary properties of the image protection region. The protection level derivation factor is obtained by indexing the entanglement mapping seed in a pre-set protection level derivation function library.
7. The method for power-loss data protection and rapid recovery of a solid-state drive as described in claim 1, characterized in that, Updating the corresponding status flag after storage is complete specifically includes: Entanglement projection is performed based on the mapping snapshot from logical pages to physical blocks after storage is completed and the isolation boundary attributes of the image protection region to generate a state completion entropy kernel; The state completes the mutual information diffusion between the entropy kernel and the storage verification certificate generated in the storage process, generating a marker-derived kernel; The image storage identifier is determined by indexing the preset tag attribute library based on the tag-derived kernel, so as to update the corresponding state tag.
8. A method for power-loss data protection and rapid recovery of a solid-state drive as described in claim 7, characterized in that, The process of generating a marker-derived kernel involves mutual information diffusion between the entropy kernel and the storage verification certificate generated during the storage process, based on the aforementioned state. The state completes the nonlinear mutual information projection of the entropy kernel and the storage verification certificate to generate a diffusion seed vector. The label-derived kernel is determined by indexing the pre-set label-derived kernel library based on the diffusion seed vector.
9. A method for power-loss data protection and rapid recovery of a solid-state drive as described in claim 1, characterized in that, Upon power-on, the status flags are sequentially verified. If the verification is valid, the recovery process queue is activated in stages according to the updated protection level, specifically including: Based on the atomic write confirmation token and mirror consistency token read during power-on, a temporal sequential interleaving is performed to generate a verification challenge vector; A one-way hash chain consistency check is performed using the verification challenge vector and the circuit breaker signature of the device trust root. If the check passes, a valid verification token is generated. The protection strength coefficient and recovery phase dependency weight are parsed from the updated protection level, and the recovery process queue is activated sequentially by the valid verification token.
10. A method for power-loss data protection and rapid recovery of a solid-state drive as described in claim 1, characterized in that, Clearing the status flag after the recovery process queue has been completed specifically includes: Securely bind the recovery completion certificate vector generated after the recovery process queue is completed with the circuit breaker signature of the device trust root to generate a clearing authorization credential; The storage area of the status marker is overwritten and erased using the clear authorization credential, and the mirror consistency token and atomic write confirmation token are reset to their initial state.