Hongmeng law enforcement recorder data security storage method based on national secret algorithm
Patent Information
- Application Number
- CN202611149472.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-07-31
- Publication Date
- 2026-10-02
AI Technical Summary
[0004]提供一种基于国密算法的鸿蒙执法记录仪数据安全存储方法,以解决现有执法记录仪数据存储中密钥与存储硬件分离、加密密钥静态重复导致的抗攻击能力不足,以及数据集中存放、完整性校验可见化带来的易篡改和易破坏问题
通过存储介质物理特征参数生成硬件绑定密钥,利用该硬件绑定密钥对国密SM4工作密钥进行加密,形成保护密钥。硬件绑定密钥源自存储介质的序列号、生产批次标识和存储单元物理缺陷分布图这些随器件物理差异而不可复制的特征,使得保护密钥仅在原介质上可被解密还原,脱离原设备后任何析取保护密钥的行为均因缺失硬件特征而无法获得工作密钥,杜绝了存储介质克隆和数据离线破解。在此基础上,依据目标执法数据的写入Unix时间戳和存储介质当前写入计数值,交替取字节并逆序排列生成时间因子,再将时间因子与保护密钥进行异或运算得到派生密钥。每次写入操作的时间戳与计数值组合唯一变化,派生密钥随之动态变化,不同时刻记录的不同执法数据使用的加密密钥均不相同,实现一次一密。即使某段数据的派生密钥被偶然推知,其他数据段因时间因子差异仍保持安全隔离,且时间序列不可回退的特性有效抵御重放攻击和密钥碰撞分析。
Smart Images

Figure CN122870939A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of data security storage technology, specifically to a data security storage method for HarmonyOS law enforcement recorders based on national cryptographic algorithms. Background Technology
[0002] The audio and video data collected by law enforcement recorders serves as crucial evidence, and its storage security directly impacts its evidentiary value. Current methods for securely storing law enforcement recorder data generally employ common encryption algorithms, with working keys typically embedded in the firmware or software configuration of the security chip, lacking a strong correlation with the physical characteristics of the storage medium itself. Once the storage medium is physically disassembled, attackers can directly read the ciphertext using specialized equipment and exploit key migration to perform offline cracking. Encryption operations often use fixed or limited-number key updates for the entire data area, with multiple writes of law enforcement data sharing the same encryption parameters. This means that a single key leak can threaten all historical records, making it vulnerable to replay attacks and key backtracking analysis. Regarding integrity protection, existing solutions generally store verification information in a regular partition accessible to the operating system. Attackers can modify the verification value simultaneously after tampering with the data, rendering integrity verification ineffective. Data storage layouts often employ continuous logical block mapping, with ciphertext data stored centrally. This allows attackers to easily locate and replace or destroy the entire ciphertext, making unauthorized copying and transfer of data difficult to detect.
[0003] While law enforcement recorders equipped with the HarmonyOS operating system possess distributed security capabilities, specific methods tailored to law enforcement scenarios are still needed for a secure storage architecture that combines hardware-bound key derivation, dynamic time factor integration, and physical distributed storage with hidden integrity verification. It is necessary to address how to deeply integrate encryption keys with the unique physical characteristics of the storage medium and the dynamic time information of each write under the national cryptographic algorithm system to prevent security risks associated with static key storage, and to solve the problems of centralized ciphertext storage being easily stolen or damaged, and the inability of integrity protection to resist physical tampering. Summary of the Invention
[0004] This paper proposes a secure data storage method for HarmonyOS law enforcement recorders based on national cryptographic algorithms. This method addresses the problems of insufficient anti-attack capability caused by the separation of keys and storage hardware and the static repetition of encryption keys in existing law enforcement recorder data storage, as well as the susceptibility to tampering and damage caused by centralized data storage and the visibility of integrity verification.
[0005] To achieve the above objectives, this invention provides the following technical solution: This invention provides a method for secure data storage of HarmonyOS law enforcement recorders based on national cryptographic algorithms. When the law enforcement recorder initializes the storage medium, the physical characteristic parameters of the storage medium are obtained. Based on these parameters, a hardware binding key uniquely bound to specific hardware is generated. This hardware binding key is then used to encrypt the working key of the national cryptographic algorithm, forming a protection key. When target law enforcement data needs to be written, a time factor is dynamically generated based on the data writing time information. The time factor is XORed with the protection key to obtain a derived key. This derived key is then used to encrypt the target law enforcement data using the national cryptographic algorithm, generating ciphertext data. The ciphertext data is split into at least two data fragments. Each data fragment is assigned a storage address containing the physical block number of the storage medium and the offset within the block. Each data fragment, along with its corresponding storage address, is then associated and written into the free area of the storage medium. Simultaneously, the set of storage addresses for each data fragment is registered in the address mapping table of the storage medium. After the target law enforcement data is stored, the hash value of the protection key is bound to the physical characteristic parameters of the storage medium to generate an integrity verification code, which is then written to the hidden partition of the storage medium.
[0006] Preferably, the specific process for generating the hardware binding key is as follows: The serial number, production batch identifier, and physical defect distribution map of the storage medium are extracted from the physical characteristic parameters, and then concatenated bit by bit to obtain the original binding byte sequence; the original binding byte sequence is then processed using the national cryptographic SM3 hash algorithm to obtain a fixed-length hash digest, which is directly used as the hardware binding key. This achieves a strong binding between the key and a specific storage medium. Once the storage medium is replaced, the hardware binding key changes accordingly, and the encrypted data cannot be correctly decrypted.
[0007] Preferably, when obtaining the protection key by encrypting the working key using a hardware-bound key, a pre-stored SM4 symmetric working key is retrieved from the security chip of the law enforcement recorder. Using the hardware-bound key as the encryption key, an encryption operation is performed on the working key using the electronic cryptographic book mode of the SM4 algorithm to obtain the ciphertext of the working key. This ciphertext is then concatenated with the version identifier of the hardware-bound key to form the protection key. The working key always resides outside the security chip in ciphertext form, effectively reducing the risk of key leakage.
[0008] Preferably, the method for generating the time factor based on the write time information is as follows: Obtain the Unix timestamp corresponding to the write time information and convert it into a hexadecimal time byte string; simultaneously, obtain the current write count value of the storage medium and convert it into a hexadecimal count byte string; merge the time byte string and the count byte string by alternately taking bytes from the least significant bit to the most significant bit, obtaining a merged byte sequence; then, reverse the byte order of this merged byte sequence, and use the reversed merged byte sequence as the time factor. The time factor combines the timestamp and the write count, ensuring that the derived keys generated by different write requests are different, greatly enhancing the randomness and replay resistance of the encryption.
[0009] Preferably, when XORing the time factor and the protection key to obtain the derived key, the process first checks if their data lengths are equal. If the time factor's data length is less than the protection key's data length, zero-value bytes are padded before the most significant byte of the time factor until the lengths are equal. If the time factor's data length is greater than the protection key's data length, the time factor is truncated from its least significant byte until it matches the protection key's data length. Then, the time factor with the same data length is XORed bitwise with the protection key to obtain the derived key. This length alignment process ensures the compatibility and reliability of the XOR operation.
[0010] Preferably, when encrypting target law enforcement data using a derived key, the target law enforcement data is divided into multiple data blocks according to a preset block size, with zero-value bytes used to pad the last data block if it is insufficient; the first sixteen bytes of the derived key are used as the initial vector for the national cryptographic SM4 algorithm; for each data block, the ciphertext result of the previous data block is bitwise XORed with the plaintext of the current data block, and then encrypted using the derived key in the cryptographic block chaining mode of the national cryptographic SM4 algorithm to obtain the ciphertext of the current data block; finally, the ciphertexts of each data block are concatenated in the order of segmentation to form the ciphertext data. The cryptographic block chaining mode causes the same plaintext to produce completely different ciphertexts in different positions, eliminating data pattern characteristics and resisting statistical analysis attacks.
[0011] Preferably, the steps of dividing the encrypted data into data fragments and allocating storage addresses include: obtaining the total byte length of the encrypted data and calculating the base fragment size based on the preset number of fragments; starting from the first byte of the encrypted data, extracting data fragments sequentially according to the base fragment size, with the size of the last data fragment being the total byte length minus the number of extracted bytes; when allocating physical block numbers for each data fragment, obtaining free physical block numbers from the free block list of the storage medium in ascending order of block number, and allocating a continuous intra-block offset range as the storage address within the corresponding physical block. Distributed fragmented storage ensures that even if individual physical blocks are damaged, the remaining fragments can still recover most of the data using the address mapping table, improving data resilience.
[0012] Preferably, when storing each data fragment as associated with its storage address and recording the address mapping table, each data fragment is written to the physical location corresponding to its storage address; an address mapping record is created for each data fragment, including the fragment sequence number in the encrypted data, the corresponding physical block number, the starting value of the offset within the block, and the offset length; a check value is calculated for each address mapping record and appended to the end of the record; all address mapping records with appended check values are arranged in order of fragment sequence number and written to the address mapping table of the storage medium. The check value of the address mapping record can prevent the mapping table from being tampered with, ensuring the accuracy of data recovery.
[0013] Preferably, the process of generating the integrity check code is as follows: The protection key is used as input, and its hash value is calculated using the national cryptographic SM3 hash algorithm; the serial number of the storage medium is concatenated with the physical defect distribution map of the storage unit to form a physical feature byte string; the protection key hash value and the physical feature byte string are XORed bitwise to obtain a binding check byte string; then, the binding check byte string is hashed using the national cryptographic SM3 hash algorithm to generate the integrity check code. This check code simultaneously binds the protection key and the physical characteristics of the medium. Any unauthorized copying of the encrypted data or replacement of the storage medium will result in check failure, thus achieving strict integrity and originality verification.
[0014] Preferably, the operation of writing the integrity check code to the hidden partition is as follows: read the existing integrity check code record from the hidden partition of the storage medium; if the record is empty, write the current integrity check code directly to the first record position of the hidden partition; if the record is not empty, write the current integrity check code to the next free record position of the hidden partition, compare the latest timestamp of the existing record with the current timestamp, and update the record header information of the hidden partition according to the comparison result. The hidden partition is invisible to the operating system and users, and can only be accessed through a secure interface, ensuring the confidential storage and tamper-proof characteristics of the integrity check code.
[0015] The technical effects and advantages provided by the present invention in the above technical solution are as follows: A hardware-bound key is generated based on the physical characteristics of the storage medium. This hardware-bound key is then used to encrypt the SM4 working key, forming a protection key. The hardware-bound key originates from the storage medium's serial number, production batch identifier, and physical defect distribution map of the storage units—characteristics that are unique to the device due to its physical differences. This ensures the protection key can only be decrypted and restored on the original medium. Any attempt to extract the protection key after disconnecting from the original device will fail due to the lack of hardware characteristics, preventing storage medium cloning and offline data cracking. Furthermore, based on the target law enforcement data's Unix timestamp and the current write count of the storage medium, bytes are alternately extracted and arranged in reverse order to generate a time factor. This time factor is then XORed with the protection key to obtain a derived key. The combination of timestamp and count value changes uniquely with each write operation, dynamically changing the derived key. Different law enforcement data recorded at different times use different encryption keys, achieving one-time-one-key encryption. Even if the derived key of a certain data segment is accidentally deduced, other data segments remain securely isolated due to the time factor difference. The irreversible nature of the time series effectively resists replay attacks and key collision analysis.
[0016] The encrypted ciphertext data is divided into at least two data fragments, each assigned an independent physical block number and intra-block offset, forming a non-contiguous, physically distributed storage layout. These data fragments have no fixed logical order in the physical storage space. Attackers who only obtain a single physical block or a portion of the fragments cannot reconstruct a readable, complete ciphertext, increasing the difficulty of data reconstruction and concealing the storage structure. An address mapping table records the correspondence between each fragment's sequence number and its physical address, along with a checksum, providing redundant means for data recovery and fragment integrity checks. After storage, the SM3 hash value of the protection key is calculated, and then XORed with a physical characteristic byte string formed by concatenating the storage medium's serial number and a physical defect distribution map, followed by another hash, to generate an integrity checksum. This integrity checksum is written to a hidden partition invisible to the operating system and deeply bound to the physical characteristics of the storage medium. Any replacement or alteration of the ciphertext data, protection key, or physical blocks of the storage medium will result in a mismatch in the checksum, thus detecting unauthorized modifications. The physical characteristic binding feature also renders the checksum invalid on other media, preventing full-disk data copying and integrity forgery. The sharded storage model distributes the risk of data corruption across multiple independent physical blocks. Even if some storage units fail, the remaining shards and mapping records can still maintain partial data availability, thus avoiding overall data loss. Attached Figure Description
[0017] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the drawings used in the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments recorded in this invention. For those skilled in the art, other drawings can be obtained based on these drawings.
[0018] Figure 1 This is a flowchart of a method for secure data storage in HarmonyOS law enforcement recorders based on national cryptographic algorithms; Figure 2 This is a flowchart of generating a hardware binding key based on physical characteristic parameters and encrypting the working key to obtain a protection key; Figure 3 This is a flowchart of the time factor generation and derived key generation process; Figure 4 This is a diagram illustrating the writing of integrity check codes to timestamps and exception markers. Detailed Implementation
[0019] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0020] See Figure 1 This invention provides a method for secure data storage of a HarmonyOS law enforcement recorder based on national cryptographic algorithms, comprising: responding to a storage medium initialization command of the law enforcement recorder, obtaining physical characteristic parameters of the storage medium; generating a hardware binding key based on the physical characteristic parameters, and using the hardware binding key to encrypt and protect the working key of the national cryptographic algorithm to obtain a protection key; responding to a write request for target law enforcement data, generating a time factor based on the write time information of the target law enforcement data, and performing an XOR operation between the time factor and the protection key to obtain a derived key; using the derived key to encrypt the target law enforcement data using the national cryptographic algorithm to generate ciphertext data; dividing the ciphertext data into at least two data fragments, assigning a storage address to each data fragment, the storage address including the physical block number of the storage medium and the offset within the block; associating and storing each data fragment and its corresponding storage address in a free area of the storage medium, and recording the set of storage addresses of each data fragment in the address mapping table of the storage medium; responding to the completion of target law enforcement data storage, binding the hash value of the protection key with the physical characteristic parameters of the storage medium to generate an integrity verification code, and writing the integrity verification code into a hidden partition of the storage medium.
[0021] Example 1: In specific implementation, please refer to Figure 2 The process of generating a hardware binding key based on physical characteristic parameters is implemented in the following way.
[0022] The serial number, production batch identifier, and physical defect distribution map of the storage cells are extracted from the physical characteristic parameters of the storage medium. The serial number is a unique identifier fixed at the factory, the production batch identifier represents the production batch information to which the storage medium belongs, and the physical defect distribution map of the storage cells is bitmap data formed by the location information of bad blocks marked during the factory inspection of the storage medium.
[0023] The extracted serial number of the storage medium, the production batch identifier of the storage medium, and the physical defect distribution map of the storage cells of the storage medium are concatenated byte by byte in the following order: serial number first, production batch identifier in the middle, and physical defect distribution map of storage cells last. This concatenation results in a continuous byte sequence, which is then used as the original binding byte sequence.
[0024] The original binding byte sequence is hashed using the national cryptographic SM3 hash algorithm. The hash digest output by the national cryptographic SM3 hash algorithm has a fixed length of 256 bits, and this fixed-length hash digest is directly used as the hardware binding key.
[0025] The process of encrypting and protecting the working key of the national cryptographic algorithm using a hardware-bound key, and obtaining the protection key, is achieved in the following way.
[0026] Obtain the working key pre-stored inside the security chip of the law enforcement recorder. The working key is a symmetric key of the national cryptographic SM4 algorithm. The security chip of the law enforcement recorder has written the working key into its internal non-volatile storage area during the device initialization stage, and the working key is guaranteed by the security chip of the law enforcement recorder to not be directly read by the outside.
[0027] The hardware-bound key is used as the encryption key, and the working key is encrypted using the electronic codebook mode of the Chinese national cryptographic algorithm SM4. The electronic codebook mode of the SM4 algorithm uses the hardware-bound key to encrypt the plaintext data of the working key in 128-bit blocks, outputting a ciphertext working key of the same length as the plaintext.
[0028] The hardware binding key is accompanied by a version identifier, which is used to distinguish hardware binding keys generated in different batches or under different production conditions. The encrypted working key ciphertext is concatenated with the version identifier of the hardware binding key, with the working key ciphertext first and the hardware binding key version identifier last, to form the protection key.
[0029] Example 2: In specific implementation, please refer to Figure 3 The process of generating time factors based on the writing time information of target law enforcement data is implemented in the following manner.
[0030] Obtain the Unix timestamp corresponding to the write time information. The write time information refers to the precise system time recorded by the law enforcement recorder when generating target law enforcement data. Convert the Unix timestamp into a hexadecimal time byte string using big-endian byte order. After representing the Unix timestamp value as a hexadecimal string, divide it into two hexadecimal characters as one byte to obtain the time byte string.
[0031] Retrieve the current write count value of the storage medium. The current write count value is the total number of data write operations performed on the storage medium since its initialization. This count value is maintained internally by the storage medium and continuously increments. Convert the current write count value into a hexadecimal count byte string. The conversion also uses big-endian byte order. After representing the count value as a hexadecimal string, split it into bytes to obtain the count byte string.
[0032] The time byte string and the count byte string are merged by alternately extracting bytes from the least significant bit to the most significant bit, resulting in a merged byte sequence. During the merge, the byte sequences of both the time and count byte strings are considered to be arranged from least significant bit to most significant bit, starting at index 0. The alternating byte extraction process is as follows: first, extract the byte at index 0 of the time byte string, then the byte at index 0 of the count byte string, then the byte at index 1 of the time byte string, then the byte at index 1 of the count byte string, and so on, until all bytes in the byte strings have been extracted, forming the merged byte sequence.
[0033] The merged byte sequence is reversed by swapping the first byte with the last byte, the second byte with the second-to-last byte, and so on, until the entire byte sequence is reversed. The reversed merged byte sequence is used as the time factor.
[0034] After the time factor is generated, the process of XORing the time factor with the protection key to obtain the derived key is achieved through the following steps.
[0035] Determine whether the data length of the time factor is equal to the data length of the protection key. The data length is measured in bytes.
[0036] If the data length of the time factor is less than the data length of the protection key, a zero byte is padded before the most significant byte of the time factor. The value of the zero byte is 0x00. Each time a zero byte is padded, the data length of the time factor increases by one. This process continues until the data length of the time factor is equal to the data length of the protection key.
[0037] If the data length of the time factor is greater than the data length of the protection key, then the time factor is truncated from the least significant byte to a number of bytes equal to the data length of the protection key. That is, the least significant byte of the time factor is retained, and the higher significant byte is discarded.
[0038] The time factor, whose data length is consistent after length adjustment, and the protection key are XORed one by one according to the byte order. The XOR operation is performed on 8 bits within each byte to obtain a derived key with the same data length as the protection key.
[0039] Example 3: In practice, the process of using a derived key to encrypt target law enforcement data with national cryptographic algorithms to generate ciphertext data is achieved in the following way.
[0040] The target law enforcement data is divided into multiple data blocks according to a preset block size of 1024 bytes. This value is determined based on the minimum erase unit size of the storage medium and the block length of the SM4 cryptographic algorithm, ensuring that each data block size is aligned with the physical operation unit of the storage medium while also meeting the requirement of the cryptographic block chaining mode that data blocks must be multiples of 16 bytes. The segmentation begins with the first byte of the target law enforcement data, dividing it into blocks of 1024 bytes each, and continues until the end of the target law enforcement data. When the last data block is less than 1024 bytes, a zero-value byte (0x00) is added to the end of the last data block, until the total length of the last data block reaches 1024 bytes.
[0041] The first sixteen bytes of the derived key are used as the initial vector of the national cryptographic SM4 algorithm. The derived key is generated by XORing the time factor and the protection key. The total length of the derived key is the same as that of the protection key. The initial vector is taken from the sixteen consecutive bytes in the byte sequence of the derived key, starting from index 0 and ending at index 15.
[0042] When encrypting each data block, the SM4 national cryptographic algorithm is used in the cipher block chaining mode. The encryption process is expressed as follows:
[0043] in, Indicates the first The ciphertext output corresponding to each data block, where m represents the index number of the data block currently being processed. The range of values is , The total number of data blocks obtained after segmenting the target law enforcement data; This indicates a Chinese national standard SM4 encryption function that uses a derived key as the encryption key. Indicates the first Plaintext data of data blocks, when hour This is the plaintext of the first data block; This represents the bitwise XOR operator; Indicates the first The ciphertext output corresponding to each data block, when hour This does not represent any ciphertext block; in this case, the initialization vector is used. Alternative Initial vectors involved in XOR operations The first sixteen bytes of the derived key.
[0044] For the first data block, the initialization vector is XORed bitwise with the plaintext of the first data block, and then encrypted using the derived key in the ciphertext block chaining mode of the SM4 algorithm to obtain the ciphertext of the first data block. For each subsequent data block, the ciphertext result of the previous data block is XORed bitwise with the plaintext of the current data block, and then encrypted using the derived key in the ciphertext block chaining mode of the SM4 algorithm to obtain the ciphertext of the current data block.
[0045] The ciphertext of each data block is concatenated sequentially according to the order in which the data blocks were split, that is, the ciphertext of the first data block is placed first, and the ciphertext of subsequent data blocks is appended to it in order, forming a complete ciphertext data after concatenation.
[0046] Example 4: In practice, the process of dividing the encrypted data into at least two data fragments and allocating storage addresses to each data fragment is achieved in the following way.
[0047] The total byte length of the ciphertext data is obtained, which is the complete byte count from the first byte to the last byte of the ciphertext data. The base fragment size is calculated based on the total byte length and the preset fragment number. The preset fragment number is the system-preset number of data fragments, which is set to 4. This value is determined by a combination of the number of parallel write channels on the storage medium and the efficiency of the address mapping table index. This ensures that the ciphertext data is distributed across 4 independent physical blocks, which can improve write throughput by utilizing multi-channel parallel writes while controlling the number of mapping records corresponding to a single ciphertext data entry in the address mapping table to maintain index retrieval efficiency. The base fragment size is calculated by dividing the total byte length by the preset fragment number and rounding up. The base fragment size represents the number of bytes contained in each of the first three data fragments.
[0048] Starting from the first byte of the ciphertext data, data fragments are extracted sequentially according to the base fragment size. When extracting the first data fragment, starting from byte 0 of the ciphertext data, continuously extract bytes of the base fragment size to form the first data fragment; when extracting the second data fragment, starting from the 1st base fragment size byte of the ciphertext data, continuously extract bytes of the base fragment size to form the second data fragment; when extracting the third data fragment, starting from the 2nd base fragment size byte of the ciphertext data, continuously extract bytes of the base fragment size to form the third data fragment; when extracting the fourth data fragment, starting from the 3rd base fragment size byte of the ciphertext data, extract all remaining bytes to form the fourth data fragment. The size of the fourth data fragment is the total byte length minus the number of extracted bytes, where the number of extracted bytes is 3 times the base fragment size.
[0049] When assigning physical block numbers to each data fragment, free physical block numbers are retrieved sequentially from the free block list of the storage medium in ascending order. The free block list records the numbers of all currently unoccupied physical blocks in the storage medium, arranged in ascending order of value. Starting with the first free physical block number in the free block list, corresponding free physical block numbers are assigned to the first, second, third, and fourth data fragments in sequence. Within the storage area corresponding to each free physical block number, a continuous intra-block offset range is allocated as the storage address of the data fragment. The intra-block offset range is defined by a starting offset and an offset length. The starting offset indicates the write start point of the data fragment within the physical block, and the offset length is equal to the size of the corresponding data fragment in bytes. The storage address is represented by the physical block number of the storage medium and the intra-block offset range.
[0050] The process of associating each data fragment and its corresponding storage address with a free area of the storage medium is achieved in the following way.
[0051] Each data fragment is written to the storage location indicated by the physical block number and the offset within the block corresponding to the storage address of the data fragment. The write operation is directly oriented towards the physical address of the storage medium. After locating the target physical block according to the physical block number, all bytes of the data fragment are written sequentially starting from the initial value of the offset within the physical block.
[0052] Each data fragment's fragment number in the ciphertext data, its corresponding physical block number, and the starting and length of its offset within the block are recorded as an address mapping record. The fragment number indicates the sequential numbering of the data fragments during the ciphertext data segmentation; the first data fragment has a fragment number of 1, the second data fragment has a fragment number of 2, and so on.
[0053] Calculate the check value for each address mapping record. The check value is generated using a cyclic redundancy check (CR) method. The fragment sequence number field, physical block number field, starting value of intra-block offset field, and offset length field in the address mapping record are concatenated to form a byte sequence to be checked. Perform CR calculation on the byte sequence to be checked to obtain the check value. The check value is then appended to the corresponding address mapping record to form an address mapping record with check protection.
[0054] All address mapping records with the added check value are arranged in order of fragment number, that is, the address mapping record with fragment number 1 is placed first, the address mapping record with fragment number 2 is placed next, and so on. All the arranged address mapping records are written into the address mapping table of the storage medium in sequence. The address mapping table is located in the address mapping storage area specially designated in the storage medium.
[0055] Example 5: In practice, the process of binding the hash value of the protection key with the physical characteristic parameters of the storage medium to generate an integrity check code is achieved in the following way.
[0056] The protection key is used as input data, and its hash value is calculated using the Chinese national cryptographic SM3 hash algorithm. The protection key is formed by concatenating the working key ciphertext and the version identifier of the hardware binding key. The complete byte sequence of the protection key is fed into the Chinese national cryptographic SM3 hash algorithm. The algorithm performs message padding, message expansion, and compression function iterations on each byte of the protection key in sequence, and finally outputs a protection key hash value with a length of 256 bits.
[0057] The serial number of the storage medium and the physical defect distribution map of its storage cells are concatenated into a physical feature byte string. The serial number of the storage medium is a unique identifier fixed at the factory, and the physical defect distribution map of its storage cells is bitmap data formed by marking the location of bad blocks during factory testing. During concatenation, the byte sequence of the storage medium's serial number is placed first, followed by the byte sequence of the storage cell physical defect distribution map, and the two bytes are linked together to form the physical feature byte string.
[0058] The binding verification byte string is obtained by bitwise XORing the protection key hash value and the physical feature byte string. The bitwise XOR operation is performed byte by byte. The first byte of the protection key hash value is XORed with the first byte of the physical feature byte string, the second byte of the protection key hash value is XORed with the second byte of the physical feature byte string, and so on, until all bytes of the two byte sequences have been XORed. The resulting byte sequence is the binding verification byte string.
[0059] The binding verification byte string is hashed again using the national cryptographic SM3 hash algorithm to generate an integrity check code. The binding verification byte string is completely fed into the national cryptographic SM3 hash algorithm. After iterative operations of message padding, message expansion, and compression functions, a hash value of 256 bits is output, which is the integrity check code.
[0060] In practice, the process of writing the integrity check code into the hidden partition of the storage medium is achieved in the following way.
[0061] Read existing integrity check records from the hidden partition of the storage medium. The hidden partition is an independent storage area defined on the storage medium. This area is invisible to the operating system and can only be accessed through dedicated commands provided by the storage medium controller. The hidden partition is organized by record entries. Each record entry consists of a record header and a record body. The record header contains the total number of records, the index of the latest record, and the timestamp of the latest record. The record body stores the integrity check code and the corresponding timestamp.
[0062] Read the record header information of the hidden partition to obtain the total number of records. If the total number of records is zero, it is determined that there are no existing integrity check code records. If the total number of records is not zero, the corresponding integrity check code record is read from the record body area based on the latest record index value to determine the existence status of existing integrity check code records.
[0063] If an existing integrity checksum record is empty, the integrity checksum is directly written to the first record position of the hidden partition. The first record position of the hidden partition corresponds to the physical start address of the record body area. The integrity checksum is written to this start address as record body data, and the current timestamp is also written to the timestamp field of the record body. The record header information is updated, the total number of records is set to 1, the latest record index is set to 0, and the latest record timestamp is set to the current timestamp.
[0064] If an existing integrity check record is not empty, the integrity check code is written to the next free record location in the hidden partition. The location of the next free record is determined as follows: read the total number of records in the record header information, use the total number of records as the index value of the next free record, calculate the physical address of the record body corresponding to the index value, and write the integrity check code and the current timestamp to that physical address.
[0065] The system compares the timestamp of the latest record in the existing integrity checksum records with the current timestamp, and updates the record header information of the hidden partition based on the comparison result. If the current timestamp is greater than the timestamp of the latest record in the existing integrity checksum records, the total number of records is increased by 1, the index of the latest record is updated to the index value of the next free record, and the timestamp of the latest record is updated to the current timestamp. If the current timestamp is not greater than the timestamp of the latest record in the existing integrity checksum records, the index and timestamp of the latest record remain unchanged, the total number of records is increased by 1, and an exception flag value is written to the exception flag bit of the hidden partition, indicating that there is an abnormal timestamp order in this write operation.
[0066] See Figure 4 In the graph, the horizontal axis represents the write sequence number, and the vertical axis represents the corresponding record timestamp (Unix timestamp, in seconds, marked with an offset of +1.7e9 on the axis). The curve "Record Timestamp" shows the overall trend of the record timestamp as the write sequence number changes, exhibiting an approximately linear and monotonically increasing trend. This indicates that as the write sequence number increases, the record timestamp generally shows a stable increase, which is consistent with the reasonable expectation of chronological order.
[0067] In the diagram, red "×" marks indicate abnormal write markers, distributed across multiple locations on the curve. These abnormal write markers correspond to write sequence points where the recorded timestamp does not meet the increment condition compared to the previous record's timestamp, indicating an abnormal timestamp order. As described in Example 5, the abnormal write marker reflects an event where the current write timestamp is less than or equal to the timestamp of the latest existing record; the system records this abnormality in the hidden partition's abnormal flag bit.
[0068] As can be seen from the figure, the abnormal write markers do not appear in a concentrated manner, but are scattered throughout the entire write sequence, and their number is relatively limited. They do not significantly interfere with the overall timestamp increment trend, which reflects the effective execution of the timestamp anomaly detection and marking mechanism during the writing of integrity check codes in this embodiment.
[0069] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any changes or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application.
Claims
1. A method for secure data storage of HarmonyOS law enforcement recorders based on national cryptographic algorithms, characterized in that: include: In response to the storage medium initialization command of the law enforcement recorder, the physical characteristic parameters of the storage medium are obtained; A hardware binding key is generated based on the physical feature parameters. The working key of the national cryptographic algorithm is encrypted and protected using the hardware binding key to obtain the protection key. In response to a write request for target law enforcement data, a time factor is generated based on the write time information of the target law enforcement data, and a derived key is obtained by XORing the time factor with the protection key. The target law enforcement data is encrypted using the derived key using a national cryptographic algorithm to generate ciphertext data; The encrypted data is divided into at least two data fragments, and a storage address is assigned to each data fragment. The storage address includes the physical block number of the storage medium and the offset within the block. Each data fragment and its corresponding storage address are associated and stored in the free area of the storage medium, and the set of storage addresses of each data fragment is recorded in the address mapping table of the storage medium; In response to the completion of the storage of the target law enforcement data, the hash value of the protection key is bound to the physical characteristic parameters of the storage medium to generate an integrity check code, and the integrity check code is written to the hidden partition of the storage medium.
2. The method for secure data storage of HarmonyOS law enforcement recorders based on national cryptographic algorithms according to claim 1, characterized in that, Generating a hardware binding key based on the physical characteristic parameters includes: Extract the serial number, production batch identifier, and physical defect distribution map of the storage medium from the physical characteristic parameters; The serial number, the production batch identifier, and the physical defect distribution map of the storage unit are concatenated bit by bit to form the original binding byte sequence; The original bound byte sequence is hashed using the national cryptographic SM3 hash algorithm to obtain a fixed-length hash digest. The hash digest is used as the hardware binding key.
3. The method for secure data storage of HarmonyOS law enforcement recorders based on national cryptographic algorithms according to claim 1, characterized in that, The working key of the national cryptographic algorithm is encrypted and protected using the hardware-bound key to obtain the protection key, which includes: Obtain the working key pre-stored inside the security chip of the law enforcement recorder, wherein the working key is a symmetric key of the national cryptographic SM4 algorithm; The hardware binding key is used as the encryption key, and the working key is encrypted using the electronic cryptographic book mode of the national cryptographic SM4 algorithm to obtain the working key ciphertext. The working key ciphertext is concatenated with the version identifier of the hardware binding key to obtain the protection key.
4. The method for secure data storage of HarmonyOS law enforcement recorders based on national cryptographic algorithms according to claim 1, characterized in that, Generate a time factor based on the writing time information of the target law enforcement data, including: Obtain the Unix timestamp corresponding to the write time information, and convert the Unix timestamp into a hexadecimal time byte string; Obtain the current write count value of the storage medium and convert the current write count value into a hexadecimal count byte string; The time byte string and the count byte string are merged by taking bytes alternately from the least significant bit to the most significant bit to obtain a merged byte sequence; The merged byte sequence is reversed in byte order, and the reversed merged byte sequence is used as the time factor.
5. The method for secure data storage of HarmonyOS law enforcement recorders based on national cryptographic algorithms according to claim 1, characterized in that, The derived key is obtained by performing an XOR operation between the time factor and the protection key, including: Determine whether the data length of the time factor is equal to the data length of the protection key; If the data length of the time factor is less than the data length of the protection key, then zero-value bytes are padded before the most significant byte of the time factor until the data length of the time factor is equal to the data length of the protection key; If the data length of the time factor is greater than the data length of the protection key, then the time factor is truncated from the least significant byte to a number of bytes equal to the data length of the protection key. The derived key is obtained by performing a bitwise XOR operation between the time factor after the data length is consistent and the protection key.
6. The method for secure data storage of HarmonyOS law enforcement recorders based on national cryptographic algorithms according to claim 1, characterized in that, The target law enforcement data is encrypted using the derived key using a national cryptographic algorithm to generate ciphertext data, including: The target law enforcement data is divided into multiple data blocks according to a preset block size, and the last data block is padded with zero-value bytes if it is less than the preset block size. The first sixteen bytes of the derived key are obtained as the initial vector for the national cryptographic SM4 algorithm; For each data block, the ciphertext result of the previous data block is XORed with the plaintext of the current data block bitwise, and then encrypted using the derived key through the cryptographic block chaining mode of the national cryptographic SM4 algorithm to obtain the ciphertext of the current data block. The ciphertext of each data block is concatenated according to the segmentation order to obtain the ciphertext data.
7. The method for secure data storage of HarmonyOS law enforcement recorders based on national cryptographic algorithms according to claim 1, characterized in that, The encrypted data is divided into at least two data fragments, and a storage address is allocated to each data fragment, including: Obtain the total byte length of the encrypted data, and calculate the basic fragment size based on the total byte length and the preset fragment number; Starting from the first byte of the encrypted data, data fragments are extracted sequentially according to the basic fragment size, and the size of the last data fragment is the total byte length minus the number of extracted bytes; When allocating physical block numbers for each data fragment, free physical block numbers are sequentially obtained from the list of free blocks in the storage medium in ascending order of block number, and a continuous intra-block offset range is allocated within the storage area corresponding to each free physical block number as the storage address of that data fragment.
8. The method for secure data storage of HarmonyOS law enforcement recorders based on national cryptographic algorithms according to claim 1, characterized in that, The step of associating and storing each data fragment and its corresponding storage address in a free area of the storage medium, and recording the set of storage addresses of each data fragment in the address mapping table of the storage medium, includes: Write each data fragment to the storage location indicated by the physical block number and the offset within the block corresponding to the storage address of that data fragment; Each data fragment in the encrypted data, along with its fragment number, corresponding physical block number, starting offset value within the block, and offset length, is recorded as an address mapping record. Calculate the check value for each address mapping record and append the check value to the corresponding address mapping record; All address mapping records with the added check value are arranged in order of fragment number and written into the address mapping table of the storage medium.
9. The method for secure data storage of HarmonyOS law enforcement recorders based on national cryptographic algorithms according to claim 1, characterized in that, The integrity check code is generated by binding the hash value of the protection key with the physical characteristic parameters of the storage medium, including: The protection key is used as input data, and the hash value of the protection key is calculated using the national cryptographic SM3 hash algorithm. The serial number of the storage medium and the physical defect distribution map of the storage unit are concatenated into a physical feature byte string; The protection key hash value and the physical feature byte string are bitwise XORed to obtain the binding verification byte string; The binding verification byte string is hashed again using the national cryptographic SM3 hash algorithm to generate the integrity verification code.
10. The method for secure data storage of HarmonyOS law enforcement recorders based on national cryptographic algorithms according to claim 1, characterized in that, Writing the integrity check code to the hidden partition of the storage medium includes: Read existing integrity check code records from the hidden partition of the storage medium; Determine whether the existing integrity check code record is empty. If it is empty, write the integrity check code directly into the first record position of the hidden partition. If it is not empty, the integrity check code is written to the next free record position of the hidden partition, and the timestamp of the latest record in the existing integrity check code record is compared with the current timestamp. The record header information of the hidden partition is updated according to the comparison result.