Methods and systems for session-based and secure access control to a data storage system

The method provides session-based secure access control with cryptographic encryption, addressing data protection and compliance issues in recording systems by protecting data from unauthorized access during and after write sessions.

DE102021131424B4Active Publication Date: 2025-06-26SWISSBIT AG
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
DE102021131424
Authority / Receiving Office
DE · DE
Patent Type
Patents
Current Assignee / Owner
Filing Date
2021-11-30
Publication Date
2025-06-26
Estimated Expiration
2041-11-30

AI Technical Summary

Technical Problem

Existing recording systems lack secure access control and encryption mechanisms for data storage, failing to meet data protection requirements, especially in sensitive areas like security services and industrial monitoring, leading to potential data loss and legal compliance issues.

Method used

A method for session-based secure access control to a data storage system, involving detection of an activation signal, assignment of a free memory sub-area, cryptographic encryption, and session-specific access protection, ensuring data is protected from unauthorized access during and after write sessions.

Benefits of technology

Ensures secure storage and access to recording data, preventing unauthorized viewing, overwriting, or deletion, while allowing authorized access, thus meeting data protection and legal compliance requirements.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000000_0000_ABST
    Figure 00000000_0000_ABST
  • Figure 00000000_0001_ABST
    Figure 00000000_0001_ABST
Patent Text Reader

Abstract

A method (100) for session-based and secure access control to a data storage system, the method (100) comprising: Detecting (110) an activation signal to initiate access to the data storage system; and at least one writing session (W i ) for writing session-related data (WD i ) into the data storage system (210); wherein each of the at least one writing session (W i ) includes: in response to detecting (110) the activation signal, determining (135) a write session for writing the data (WD i ) free physical memory subarea (211,...,215; M i ) of the data storage system (210) and selectively allocating this memory subarea (211,...,215; Mi) to this write session (W i ); Receiving (140) or generating the data received during the write session (W i) data to be written (WDi); protecting (155) the data (WDi) by means of access protection that protects them from subsequent access by unauthorized other access sessions to the data storage system (210); and Outputting (160) the access-protected data in order to store them in the memory subarea (211,...,215; M) selectively assigned to the write session i ) of the data storage system (210) or to cause this to be done.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] The present invention relates to a method and a data processing system for session-based and secure access control to a data storage system, as well as a storage medium with such a data processing system and a data storage system, as well as a recording system that is configured to interact with the data processing system in order to use the storage medium to store recording data.

[0002] Recording systems of various types typically serve the purpose of capturing recorded data and storing it for later processing. Such recording systems can include, in particular, photo or video cameras, audio recording devices such as voice recorders, data loggers for sensor data, particularly with regard to the so-called "Internet of Things" (IoT), or other surveillance systems, for example, for monitoring machines or public spaces or buildings or security-relevant areas.

[0003] Typically, such a recording system has a storage interface for accessing a data storage system, which can be permanently integrated into the recording system or easily replaceable, particularly in the form of a removable data storage device such as a memory card or memory stick. Such recording systems are usually not equipped to provide the data to be stored with access protection, such as encryption, because this would require additional computing power requirements and expenditures for access protection, particularly for a key exchange with regard to encryption, or would require significantly more complex operation.

[0004] While the need for data recordings of all kinds is constantly increasing in many areas, such as in the field of security services, rescue services, protection systems for taxi drivers or bus drivers or in the field of industrial measurement and monitoring technology, for example with regard to continuous temperature monitoring of a cold chain, energy consumption data for associated billing and much more, such data recordings often have to meet high requirements for the associated data protection.

[0005] Data protection typically and often necessarily begins at the source of the data, followed by secure archiving, ensuring only event-related further processing and secure deletion of unnecessary data.

[0006] Implementing the requirements for legally compliant data processing therefore regularly requires a data protection concept, as recorded data is often only usable if it has been properly recorded. Adequate precautions must also be taken against the loss of data that may affect the rights of individuals in the records, and such loss is often subject to severe penalties.

[0007] US 2010 / 281273 A1 describes a system for providing processor-based security. It comprises: a processor with a processor core, a cache memory, a plurality of registers for storing at least one hash value and at least one encryption key, a memory interface, and at least one on-chip instruction for creating a secure memory area in an external memory outside the processor; and a hypervisor program executed by the processor. The hypervisor program instructs the processor to execute the at least one on-chip instruction to create a secure memory area for a software module. In doing so, the processor encrypts data written to the external memory and decrypts data read from the external memory.This is done using at least one encryption key and verification data that are read from the external memory using the hash value.

[0008] It is an object of the invention to provide methods and systems with which protected access to a data storage system, in particular for storing recording data, is technically further improved with regard to the data protection that can be achieved thereby.

[0009] This object is achieved according to the teaching of the independent claims. Various embodiments and developments of the invention are the subject of the dependent claims.

[0010] A first aspect of the solution relates to a method, in particular a computer-implemented method, for session-based and secure access control to a data storage system. The method comprises: (i) detecting an activation signal to initiate access to the data storage system; and (ii) at least one write session for writing write-session-related data to the data storage system. In the method, each of the at least one write session comprises: (iii) in response to detecting the activation signal, determining a free physical memory sub-area of ​​the data storage system to be used for writing the data during the write session and selectively assigning this memory sub-area to this write session; (iv) receiving or generating the data to be written during the write session;(v) protecting the data by means of access protection, in particular individually assigned to the write session, which protects it from subsequent access to the data storage system by other unauthorized access sessions; and (vi) outputting the access-protected data, in particular directly to the data storage system, in order to write it to the memory sub-area of ​​the data storage system selectively assigned to the write session or to cause this to happen, the latter in particular within the framework of indirect access to the data storage system via one or more intermediary communication nodes;

[0011] The term "activation signal," as used herein, refers in particular to a signal, such as a wired or wireless electrical, electromagnetic, or optical signal, which is configured such that it is or will be detectable by the entity executing the method, such as a correspondingly configured data processing system, as an activation signal within the meaning of the method. Such an activation signal could be triggered, in particular, upon switching on, switching between different operating modes, or switching off a recording system or a data processing system itself executing the method, and then detected as mentioned under (i).

[0012] The term "free physical memory sub-area," as used herein, refers in particular to a physical area of ​​a memory system, such as one or more specific memory pages or memory blocks, or the physical area of ​​the memory system associated with a specific range of physical memory addresses, which is still "free" at the time in question. "Free" in this context means that the free physical memory sub-area is available for writing data, in particular because it has not yet been written to (at least since a last memory reset), or because it is released for overwriting data already present there, or because it is available for other reasons.

[0013] The term “write session-related data” as used herein means, with respect to a particular write session, data that is specifically associated with that write session in order to be output during that session for writing to the storage sub-area of ​​the data storage system associated with the write session.

[0014] The terms "comprises," "includes," "includes," "has," "has," "with," or any other variation thereof, as used herein, are intended to cover non-exclusive inclusion. For example, a method or apparatus that includes or has a list of elements is not necessarily limited to those elements, but may include other elements not expressly listed or that are inherent in such a method or apparatus.

[0015] Furthermore, unless explicitly stated to the contrary, "or" refers to an inclusive "or" and not an exclusive "or." For example, a condition A or B is satisfied by one of the following conditions: A is true (or present) and B is false (or absent), A is false (or absent) and B is true (or present), and both A and B are true (or present).

[0016] As used herein, the terms "a" or "an" are defined to mean "one or more." The terms "another" and "another," and any other variations thereof, are defined to mean "at least one other."

[0017] The term “plurality” as used herein shall mean “two or more”.

[0018] The terms “configured” or “set up” (to) fulfill a specific function (and respective modifications thereof) are to be understood within the meaning of the invention that the corresponding device or a corresponding system is already in a configuration or setting in which it can perform the function or is at least adjustable - i.e. configurable - so that it can perform the function after being set accordingly. The configuration can be carried out, for example, by appropriately setting parameters of a process sequence or of switches or the like for activating or deactivating functionalities or settings. In particular, the device can have a plurality of predetermined configurations or operating modes, so that configuration can be carried out by selecting one of these configurations or operating modes.

[0019] The method according to the first aspect thus enables secure data storage in the data storage system, in which the access security has the effect, in particular, that data written during previous write sessions cannot be accessed or can only be accessed after prior successful authorization.

[0020] By way of analogy, this can be compared to a mailbox, into which one can deposit mail, such as letters, at various times, but when depositing mail items one cannot gain access to mail items already in the mailbox from previous deposits unless one is authorized, i.e. in possession of the mailbox key. Since the various write sessions are separated from one another by the occurrence and detection of at least one activation signal, it is sufficient, in terms of data protection, to prove that such an activation signal occurred and was actually or at least most likely detected in order to demonstrate that the previously stored data was protected thereafter and thus also during any subsequent access session (e.g., for write access, read access, or delete access).

[0021] The data written to the data storage system during a previous write session can thus be protected from access in such a way that they cannot be viewed (in particular read), overwritten or deleted, nor can their existence be detected, during subsequent (unauthorized) access sessions.

[0022] In the following, various exemplary embodiments of the method are first described, which can each be combined with each other as well as with the other aspects of the solution described, unless this is expressly excluded or is technically impossible.

[0023] In some embodiments, the received or generated writing session-related data is at least partially recording data that represents one or more real events or states of objects recorded continuously or repeatedly over a specific period of time by means of a recording system, in particular sensory. Thus, the method is particularly suitable for recording and storing recording data using a sequence of different writing sessions, while protecting it such that it can only be read in an authorized manner, in particular individually for each writing session. For example, the recording data could originate from a police officer's so-called dash cam and represent only recordings of separate, specific events within the scope of the police officer's operations.If, for example, the recording data were to be read as evidence for a selected operation, this could be done selectively for that operation by only authorizing the lifting of access protection for the recording data for the writing session corresponding to that operation. Furthermore, this ensures that the recordings can also be used as evidence if an activation signal is subsequently detected, for example, because the device was turned off or a subsequent writing session exists.

[0024] In some embodiments, the access protection comprises at least one of the following measures: (i) cryptographic encryption of the write session-related data; (ii) the or each further write session is opened only depending on a prior successful authentication of a write request requesting the write session.

[0025] According to some of these embodiments, the write session-related data is encrypted in particular by means of integrity-protecting and / or symmetric encryption, for example using AES GCM (AES Galois Counter Mode) encryption. An authenticated encryption mode with associated data is thus available to enable both the authentication and the encryption of the data to be stored. Furthermore, the method is designed for high data throughput, with the option of parallelizing data streams, and is therefore particularly advantageous with regard to real-time encryption of the data. The term “integrity-protecting encryption,” as used here, is to be understood as encryption that enables a recipient of a correspondingly encrypted message to recognize, if necessary, whether or not the message has been encrypted.that the message was altered during transmission and / or was only received incompletely.

[0026] In some embodiments, the write session-related data is encrypted for each write session using a cryptographic key individually assigned to that respective write session. This allows session-related access protection to be implemented at all or, if another protection concept already exists, to be further strengthened. The key(s) can, in particular, be defined in advance. For this purpose, they can be stored, for example, in a data processing device configured to execute the method itself or in a memory assigned to it. However, it is also possible to define the key(s) only during the process flow, for example, based on a random process or pseudo-random process or depending on a session counter.

[0027] In some embodiments, the method comprises multiple write sessions, and the determination of the physical memory sub-area of ​​the data storage system to be assigned to the respective write session is carried out within the framework of a direct or indirect (in particular multi-level) address mapping from an address space with logical memory addresses to an address space with physical memory addresses of the physical memory area to be assigned to the respective write session. For at least two of the write sessions, the respective logical address spaces for the address mapping match at least with regard to their logical start address. Thus, on the input side of the address mapping, a uniform address space can be used for the at least two, in particular all, access sessions (e.g.starting at the logical address “0” or any other fixed starting address), which corresponds on the output side to different physical address ranges depending on the session.

[0028] Indirect address mapping is particularly applicable when the method is implemented by a system separate from the data storage system, in particular a data processing system (e.g., a separate semiconductor chip). This allows, in particular, the use of known standard memories, e.g., commercially available memory cards. Then, the mapping of logical addresses to physical addresses can be performed in a first stage by mapping logical addresses of one medium (data processing system) to logical addresses of the other medium (memory card, etc.), and in a second stage by mapping the logical addresses of the other medium (memory card, etc.) to its physical memory addresses.

[0029] In some embodiments, the method further comprises receiving or generating an additional secret defined independently of the cryptographic key. To encrypt the data to be written, the additional secret is used for each write session in addition to the respective cryptographic key intended for encryption, so that targeted decryption of the encrypted data is only possible with knowledge of both a secret decryption key corresponding to the cryptographic key and the additional secret. In this way, a user can incorporate the additional secret even without knowledge of the key and thus influence the encryption. However, when the data is read out, this key derivation information must be available again. This allows the owner of the data to ensure who will be able to decrypt the data from the relevant write session.

[0030] In some embodiments, the determination of a free physical memory sub-area of ​​the data storage system to be used during the respective write session for writing the write-session-related data and the selective assignment of this memory sub-area to this write session are performed as a function of a session counter that is changed each time the activation signal is detected, so that each counter reading of the session counter is selectively assigned to exactly one write session and exactly one specific corresponding memory sub-area. In this way, a distinction and assignment of different memory areas to different access sessions, in particular write sessions, can be achieved in a particularly efficient manner using a simple counter.It is particularly efficient if, according to some of these embodiments, the changes in the count of the session counter always occur in the same counting direction, ie in the sense of a strictly monotonic function.

[0031] In some embodiments, at the beginning of each write session, a file management structure is defined for the storage sub-area assigned to the respective write session, which file management structure is individually adapted to and assigned to this storage sub-area and is used for the subsequent writing of data within the scope of the write session. The file management structure thus corresponds to the storage sub-area and ensures that for each access session, in particular write session, a valid file system for file-related storage access is available based on the file management structure defined for the storage sub-area assigned to the access session. This is necessary to ensure the logical structure in each access session. In the example of a FAT format, the master boot record, the partition boot record, the file allocation table and the root directory would therefore be components of the file management structure.A typical size of this file management structure (management data) is a few megabytes, starting, for example, at the logical memory address “0”.

[0032] According to some of these embodiments, the size of the assigned physical memory sub-area available for writing within the scope of the respective write session via the file management structure adapted thereto can be offered by the file management structure in particular as one of the two following options: (a) the complete physical remaining memory size of the data storage system that is still unwritten or released for overwriting; (b) a predefined memory size that is particularly configurable in advance (e.g. session-specific) or, if this is no longer fully available, a physical remaining memory size of the data storage system that is actually still available that is unwritten or released for overwriting.

[0033] In particular in the case of option b), the memory size can be configurable within the scope of the actually still available unwritten or overwritten physical residual memory size and can be predefined depending on the respective write session. In this way, the memory sizes available for each session can be variably defined, in particular on an application-specific basis. In some embodiments, the method further comprises at least one read session for read access to data previously written to the data storage system in at least one write session. The read session comprises: (i) checking the admissibility of the respective pending read access by authenticating an object, in particular a user or device, to which orto which read access should be granted; (ii) if the check shows that read access is permitted, determining at least one memory sub-area assigned to the authenticated object from the set of memory sub-areas assigned to one or more of the previous write sessions; (iii) reading access-protected data from the one or more memory sub-areas thus determined; (iv) making the read data accessible by removing the access protection within the current read session; and (v) outputting the data made accessible. In this way, particularly with regard to the technical implementation of data protection requirements, it can be ensured that during read access to the file storage system, only those write session-related data stored therein are accessible for which there is appropriate authorization.

[0034] According to some of these embodiments, the check is or will be defined such that it results in the read access being permissible if and to the extent that at least one of the following conditions applies during the read access: (a) the data to be read during the read access was written after an activation signal was last detected; (b) the data to be read during the read access is classified as data that should be readable during every permissible read access. This classification can be or will be identified, in particular, by a corresponding identification of the data itself, the file management structure, or by a (logical or physical) address range of the memory area storing it.While option (a) enables easier access to newly written data, option (b) serves in particular to always present the file management structure in a readable manner in order to enable smooth functioning of the memory access management within the respective read session.

[0035] In some embodiments ("Variant 1"), the file management structure assigned to the memory sub-area for the respective write session is written, in particular copied, into the memory sub-area. This can occur, in particular, at the beginning of the write session, before data is written for the first time during the write session. This allows for particularly simple, low-complexity address handling to be implemented during the further course of the write or a subsequent read operation.

[0036] During write access within a write session, directories and files may be created, modified, or deleted, resulting in a modified file management structure that should or even must be retained for later reading of this specific session. Write accesses to the address space of the adapted file management structure can therefore be recorded in such a way that an overwriting of the predefined file management structure is recorded. In this way, it is possible to determine whether and which write accesses were made to the memory area of ​​the file management structure, in particular to implement variant 2 below.

[0037] In some embodiments (hereinafter "variant 2"), reading the access-protected data from a respective specific memory sub-area comprises: (i) checking whether the respective read access relates to a memory address in the specific memory sub-area into which data has already been written as part of a previous write session relating to the memory sub-area; (ii-1) if this is the case according to the result of the check for the respective read access, reading the access-protected data using a mapping of logical memory addresses to physical addresses of the memory sub-area; and (ii-2) otherwise, reading the access-protected data using the file management structure individually assigned to the memory sub-area.

[0038] In some of these embodiments (“variant 3”), the method further comprises: (iii) checking whether the respective read access relates to a logical memory address for the specific memory sub-area that is accessible via the file management structure associated with the memory sub-area; (iv-1) if this is the case, reading out the access-protected data according to the method according to variant 2; and (iv-2) otherwise, reading out the access-protected data using a mapping of this logical memory address to a physical address of the memory sub-area that is not accessible via the file management structure.

[0039] The case distinction between variants 2 and 3 enables the efficient reversal of the file management structure (overlay) when reading a previous session. This way, a file management structure modified in a session (adding, modifying, and / or deleting files, resulting in a slightly modified file management structure) can be read back despite the overlay logic.

[0040] A second aspect of the solution relates to a data processing system for session-based and secure access control to a data storage system, wherein the data processing system is configured to execute the method according to the first aspect. The data processing system can, in particular, be implemented separately from the data storage system, for example, as a separate semiconductor component (e.g., an integrated circuit, IC).

[0041] In some embodiments, the data processing system comprises: (i) an access protection device for protecting the write session-related data based on the access protection; (ii) a detection device for detecting the activation signal; and (iii) an allocation device for determining a free physical memory sub-area of ​​the data storage system to be used during the respective write session for storing the write session-related data and for selectively allocating this memory sub-area to the respective write session; and (iv) an interface for outputting the access-protected data in order to write it to the memory sub-area of ​​the data storage system selectively allocated to the respective current write session or to cause this to happen.

[0042] A third aspect of the solution relates to a storage medium comprising a data processing system according to the second aspect and a data storage system with at least one data storage. The data processing system and the data storage system are integrated into the storage medium as a common structural unit. Furthermore, the data processing system is configured to execute the method according to the first aspect for session-based and secure access control to the data storage system.

[0043] In some embodiments, the storage medium is designed as a mobile, particularly hand-portable, device, for example, a memory card. Such a storage medium can also be referred to as an "intelligent storage medium" due to the data processing system integrated therein, which distinguishes it in particular from "normal" standard storage systems such as conventional memory cards for cameras.

[0044] A fourth aspect of the solution relates to a recording system for the continuous or repeated sensory detection of real events or states of objects over a period of time and for providing recording data representing these detected events or states. The recording system is configured to interact with a data processing system according to the second aspect in order to use a storage medium according to the third aspect to store the recording data. For this purpose, the recording system can in particular itself comprise this storage medium.

[0045] In some embodiments, the recording system is configured to enable a user of the recording system to exchange the storage medium, alternatively using multiple interchangeable mobile storage media (thus removable data storage devices) according to the third aspect, each temporarily used as a storage medium for storing the recording data. This is particularly advantageous if the storage media are to be read outside of or without using the recording system, for example, in a central data protection, evaluation, or monitoring center.

[0046] In some embodiments, the recording system has a data processing system according to the second aspect integrated therein, in particular permanently. Thus, the recording system can also be easily operated with conventional (not intelligent in the above-mentioned sense) data storage systems, such as conventional memory sticks or memory cards, using the method according to the first aspect.

[0047] A fifth aspect of the solution relates to a computer program or computer program product comprising instructions which, when executed on one or more processors of a data processing system according to the second aspect, a storage medium according to the third aspect, or a recording system according to the fourth aspect with an integrated data processing system according to the second aspect, cause the method according to the first aspect to be carried out.

[0048] The computer program can in particular be stored on a non-volatile data carrier. This is preferably a data carrier in the form of an optical data carrier or a flash memory module. This can be advantageous if the computer program as such is to be handled independently of a processor platform on which the one or more programs are to be executed. In another implementation, the computer program can be present as a file on a data processing unit, in particular on a server, and can be downloaded via a data connection, for example the Internet or a dedicated data connection, such as a proprietary or local network. In addition, the computer program can have a plurality of interacting individual program modules. The modules can in particular be configured or at least be usable in such a way that they can be used in the sense of distributed computing (DC).“Distributed computing”) are executed on different devices (computers or processor units) that are geographically separated from each other and connected via a data network.

[0049] The data processing system can accordingly have a program memory in which the computer program is stored. Alternatively, the data processing system can also be configured to access an external computer program, for example, available on one or more servers or other data processing units, via a communication connection, in particular to exchange data with the program that is used during the execution of the method or computer program or that represents outputs of the computer program.

[0050] The features and benefits explained with regard to the first aspect of the solution also apply to the other aspects of the solution.

[0051] Further advantages, features and possible applications of the present solution will become apparent from the following detailed description in conjunction with the figures.

[0052] It shows: Fig. 1A / 1B schematically shows a flow chart illustrating an exemplary embodiment of the method according to the solution; and Fig. 2 schematically shows an exemplary embodiment of a storage medium according to the solution with integrated data processing device, which is used to carry out the method according to Fig. 1A / 1B is configured; Fig. 3 is a schematic diagram illustrating the use of a file management structure for write and read sessions, according to an exemplary embodiment of the solution; and Fig. 4 schematically shows an overall system for recording data management, including recording system, storage medium and archiving system.

[0053] In the figures, like reference numerals designate like, similar, or corresponding elements. Elements shown in the figures are not necessarily drawn to scale. Rather, the various elements shown in the figures are depicted in such a way that their function and general purpose will be understood by those skilled in the art. Connections and couplings between functional units and elements shown in the figures can, unless expressly stated otherwise, also be implemented as indirect connections or couplings. Functional units can, in particular, be implemented as hardware, software, or a combination of hardware and software.

[0054] In the two connected by the connectors “A” and “B” Fig. 1A and Fig. 1B illustrates an exemplary embodiment 100 of a method according to the invention. Fig. 1A in particular a writing of data in the context of one or more writing sessions, during Fig. 1B relates to reading data within one or more reading sessions. The method 100 is described with additional reference to the further Fig. 2 to 4 are explained below.

[0055] Therefore, we will first briefly discuss Fig. 2, which illustrates an exemplary storage medium 200 according to the solution, for example a memory card or a so-called memory stick. Fig. 2(a) illustrates a write access, while the Fig. 2(b) serves to illustrate a read access, in particular within the framework of the method 100. The storage medium 200 has, in particular, a data processing system 205 and a data storage system 210, for example a flash memory system. A memory controller (e.g., flash controller in the case of a flash memory) for the data storage system 210 can, in particular, be integrated either in the data storage system 210 itself or in the data processing system 205. The data processing system 205 and / or the data storage system 210 can, in particular, each be integrated circuits or cumulatively be composed of several, in particular integrated, circuits. It is also conceivable that the data processing system 205 and the data storage system 210 are contained together in a single integrated circuit. The storage medium 200 has a plurality of interfaces or connections 250 to 275 for data input or data output or a supply voltage and, if applicable,other signals. The storage medium 200, in particular the data processing system 205, is configured to execute the method 100 for the ball game using appropriate computer programming. The computer program can be stored in particular in the data processing system 205 itself or in the data storage system 210.

[0056] Now back on Fig. Referring to Figure 1A, the method 100 begins with a start step 105, in which an initialization of an index i or a counter 230 implementing it of the data processing system 205 takes place, wherein the index i serves as an index with respect to various write sessions. In a further step 110, which may also coincide with step 105, a possibly present activation signal is detected, which in Fig. 2 (a) corresponds to a voltage supply signal VCC, which can be applied to the interface 260. Each time the storage medium is re-applied with the voltage supply signal VCC and thus activated, which can occur in particular when the storage medium 200 is connected to a host device that also supplies it with electricity, such as a recording system 405 (cf. Fig. 4) is connected to or disconnected from the input, the index i is also incremented. This is done by incrementing a counter 230 in Fig. 2 (a).

[0057] If in a step 115 an access request is received from an access object, for example a recording system 405 (cf. Fig. 4) or a reading system, such as a data archiving system 410, an authentication process 120 is performed to authenticate the access object or its access request. This can be done in particular by (i) receiving (from the access object) at an interface 275 and (ii) verifying 125 an authentication information AT i , such as a password (e.g., a PIN), using an authentication unit 240. If it is determined in test step 125 that the authentication was unsuccessful (125 - no), the process branches back to step 115. In a possible modification, the authentication according to steps 120 and 125 can also be omitted.

[0058] Otherwise (125 - yes), the next step is to check whether the access request requests a write or a read of data to or from the data storage system 210. In the case of a read request (130 - "Read"), the Fig. 1B, which will be explained separately below. In the case of a write request (130 - "Write"), a new write session W is initiated in a further step 135. i which is assigned the current value of index i. Furthermore, the write session W i a still free, ie released for writing, physical memory subarea M i in file storage system 210. The storage subarea M i In particular, it can either still be unwritten or it can be released for overwriting by a memory management system, which can in particular be part of the data processing system 205.

[0059] In particular, it is possible that the physical memory subarea M i via its own file management structure OL i (which can also be called an “overlay”) and for the current writing session W i is assigned to a logical address space with a logical start address (e.g. the logical address “0”) that is the same for all write sessions using an address mapping, so that the memory subarea M i can be addressed by the data processing device 205 via logical addresses. If, as proposed here, the same logical starting address is used for all write sessions, this simplifies the address mapping, since it does not have to be individualized for each session, at least with regard to the starting address.

[0060] The file management structure (overlay) OL iIts primary purpose is to ensure that the storage medium always has a valid file system, providing a logical structure, particularly logical addressing, for each access session. For example, in the case of a known FAT format, the master boot record, the partition boot record, the file allocation table, and the root directory could be located in the overlay. This administrative data is typically a few megabytes in size, e.g., starting at logical memory address 0. Alternatively, multiple overlays per session, or even omitting an overlay, are conceivable.

[0061] Now the write session is prepared for actual writing and in a further step 140 write data WD i that are in the current writing session W i are to be written are received from the access object. In addition, in a step 145, an individual cryptographic key K ifor the current writing session W i generated (or received). It is also conceivable that the key K i is already stored in advance on the storage medium 200 and does not have to be generated during a write session or received externally. It is also conceivable that the key is the same for several or even all sessions.

[0062] Optionally, in a further step 150, an additional secret Z i for the current writing session W i are received at the interface 255 which is coupled, for example, to a user interface of a device signal-connected to the storage medium, such as the recording system 405, via which the additional secret Z i can be entered by a user.

[0063] Now, in a step 155, the received write data WD i depending on the key K i and, if applicable, the additional secret Zi be cryptographically encrypted by an encryption unit 225, which can be done in particular using symmetric encryption, in particular according to the AES GCM standard.

[0064] The additional secret Z i can be used in particular to further increase the security of data storage in the storage medium 200, since a successful subsequent reading is additionally possible in addition to knowing the key K i knowledge of the additional secret Z i For example, a user can ensure that only he or someone else in possession of the additional secret Z i can reconstruct the stored data, even if the key K i would be accessible to other people.

[0065] The write data encrypted in this way can now be transmitted directly or indirectly to the data storage system 210 in a step 160 in order to store them in the current write session W i assigned memory subarea M i to write or to cause the data storage system 210 to perform the write operation. To enable transmission to the data storage system 210, a switch 245 in the transmission path is closed (position "1"). The session-related write data WD i are thus securely stored in the storage medium 200, more precisely in its data storage system 210. The current write session W i is now finished and the process returns to step 110.

[0066] Upon renewed detection of an activation signal VCC, for example, when the storage medium is reconnected to the recording system 405 or another data source, a new process run is started, in which, if necessary, after successful authentication in step 125 and the detection of the access type "write", a new write session with incremented index i is opened. As in Fig. 2 (a) by way of example, an incrementation of the index i or the counter 230 causes the memory addressing to be adapted within the framework of an address mapping between logical and physical memory addresses in such a way that a different physical memory sub-area M i used than in the previous writing session. In Fig. 2 (a) shows five different such memory sub-areas 211 to 215 as examples.

[0067] Opening new write sessions is possible as long as there is still sufficient writable residual storage space 220 in the data storage system 410. In particular, the following various alternative operating modes can be provided: (i) a first mode ("maximum size mode"), in which the entire remaining storage that has not yet been written to or is released for overwriting is presented as the available file system size for the current write session, and (ii) a second mode ("fixed size mode"), in which a fixed, but optionally configurable storage size is presented as the available file system size. Only when the available residual storage size falls below the aforementioned fixed size as the data storage system is increasingly written to is only the current remaining storage amount presented as the available file system size.

[0068] Now Fig. 1B and Fig. 2 (b), in which a method section of the method 100 associated with reading data from the data storage system 210 and the storage medium during a read access r are illustrated.

[0069] This method section is initiated when it is determined in the previously described step 130 that for an existing access request of an access object, for example a data archiving system 410 (cf. Fig. 4), the access type is “Read” and the previous authentication of the access object in steps 120 / 125 was successful (125 - yes).

[0070] First, in a step 165, a read index j is determined depending on the authentication information AT fed into the interface 275. j authenticated access object to create a new read session R associated with this access request jwhich is opened in step 170. The new reading session R j a memory subarea M identified by the current value of index j j uniquely assigned in the data storage system 210.

[0071] During the reading session R j can therefore only be accessed in this memory subarea M j stored data can be accessed, while the other memory sub-areas are inaccessible and preferably not even presented as present. The authentication unit 240 also sets the switch 245 to the "2" position, which, on the one hand, prevents write data from being written to the file storage system 210 and, on the other hand, opens a strictly unidirectional data path for reading (this is indicated by the diode symbol, but this does not mean that a physical diode actually has to be present here).

[0072] The following steps 175 to 185c illustrate in conjunction with Fig. 3 an exemplary read access using a session-related file management system (overlay) OL j . Fig. 3 illustrates the logical address range (start address A0, end address A3) for a corresponding session-related physical memory subarea M j , and on the other hand the logical address range of the file management system OL j (Start address A0, end address A1). In addition, Fig. 3 shows an exemplary logical end address A2 of the data-occupied area within the session-related logical address space [A0,...,A3].

[0073] In step 175 of the method 100, it is now checked whether a respective one for the read access r to the memory subarea M j required logical memory address 315, 320 or 325 via the file management system OL jaccessible. If this is not the case (175 - no; see logical memory address 320 in Fig. 3) branches to step 185c, in which the data stored in the current reading session R j data to be read (read data) from the data storage system 210 using an address mapping from the logical memory address 320 to an assigned physical address in the memory subarea M j Otherwise (175 - yes), a check is made in step 180 whether in M j has already been written to a physical memory address assigned to the logical memory address. If this is not the case (180 - no, see logical memory address 325 in Fig. 3), the process branches to step 185b, in which in the current reading session R j instead of data from one of the memory subareas M j or 211 - 215 only the contents of the file management system OL assigned to this address jbe read out (written data in M j do not exist (yet). Otherwise (180 - yes; see logical memory address 315 in Fig. 3) instead, a branch is made to a step 185a in which the data to be read in the current read session is read from the data storage system 210 using an address mapping from the logical memory address 315 to an assigned physical address in M j takes place.

[0074] In a step 190, the access protection for the read data is removed and these are then sent to the output interface 265 as read data RD j The removal of the access protection corresponds to a decryption of the read data in an encryption unit 235 of the data processing system 205. For decryption, the decryption unit 235 must firstly be provided with the key K j and again the additional secret Z Jbe made available, the latter via interface 270.

[0075] The storage medium 200 thus already contains all the necessary capabilities to carry out the method 100, so that no special adaptations with regard to the method 100 need to be provided on a host device that uses the storage medium 200. The storage medium 200 can thus be used by the host device like a conventional standard storage medium, such as an SD memory card or a memory stick, and yet still offer the advantages of the solution proposed here, in particular of the method 100. The integration of the data processing device according to the solution into a (thus) intelligent storage medium allows, in particular, data storage that complies with data protection regulations, without the host device itself, e.g., the recording system 405, having to be modified.

[0076] With reference to Fig. 4, an overall system 400 for recording data management, including a recording system 405 (or any other host device configured for use with the storage medium), the storage medium 200, and a data archiving system 410, as well as an exemplary application of the overall system, is explained.

[0077] Before using the storage medium 200 "in the field," it can be configured, for example, for a data protection officer, using a corresponding application program. In particular, at least one overlay can be defined, whether globally the same for all sessions (OL) or session-specific (OL i). Each overlay can, in particular, define required formatting and / or standard memory content, such as program installation files or application documentation. When setting up the storage medium 200, it can also be determined whether the maximum size mode or the fixed size mode, or instead a differently defined third mode, should be used to define the memory sub-area to be presented within a session. The storage medium 200 is then ready for use.

[0078] It can now be connected to the recording system 405, in particular in the case of a pluggable storage medium 200, plugged into a corresponding slot of the recording system 405, and the recording device 405 can be brought into a state in which it outputs the activation signal VCC to the storage medium 200. This can occur, in particular, as part of switching on the recording system 405. The recording system 405 now recognizes the valid file management system (overlay) and can write data to the file storage system 210 of the storage medium 200 as part of the writing process, in particular according to the method 100. After recording and writing the data, it is switched off on its system, so that the activation signal VCC is no longer present.

[0079] The next time the device is switched on, the activation signal VCC present on the storage medium 200 is detected again, whereby the recording device is again presented with an empty memory so that the previously written data is no longer visible.

[0080] After completion of the recording, the user can start an archiving application 415 associated with the data archiving system 410, in particular for the purpose of archiving the data stored in the storage medium 200. Within the scope of the application 415, the user is requested to authenticate himself to the storage medium 200 then connected to the data archiving system 410 by means of corresponding authentication data AT, as previously described with reference to Fig. 1B. After successful authentication, he can select one, several, or all of the recorded sessions from a list of recorded sessions, depending on the authentication, and transfer the data from these sessions, for example, to an archive 420 for archiving purposes. If a respective session-dependent additional secret Z i was used, this must also be made available to the storage medium 200 to read out the corresponding data, as previously described with reference to Fig. 1B. The authentication data AT and, if applicable, the additional secret(s) Z i can be stored in particular in an access-protected data storage 425 assigned to the data archiving system 410.

[0081] After completion of the data export of all data to be exported, in particular all previous write sessions, into the archive 420, the intelligent storage medium is reset, all data is deleted by discarding the key K or the session-related keys K i cryptographically deleted and / or dedicated overwritten, and the session counter 230 is reset. If a change to the overlay(s) is necessary, this can also be done now. The user can now reinsert the storage medium 200 into the recording device 405 and make new secure recordings. LIST OF REFERENCE SYMBOLS 100 Method for access control according to an exemplary embodiment 105 - 190 steps or sub-processes of the procedure 100 200 storage medium with data processing system and data storage system 205 Data processing system 210 Data storage system 211 - 215 memory subareas 220 remaining free physical memory size 225 Encryption Unit 230 unidirectional session counter, also detection device 235 Decryption unit 240 Authentication Unit 245 switches 250-275 Interfaces for data input or data output 300 write and read accesses when using a file management system 305 logical address range of a session-related memory subarea 310 logical address range of a file management system 315 already session-related logical address, which is available in both the 305 and 310 address ranges 320 logical address already described session-related, outside the address range 310 325 logical address not yet described session-related in the address range 310 400 Complete system for recording data management, including recording system, storage medium and archiving system 405 Recording system 410 Data Archiving System 415 Archiving application 420 data archive storage 425 Authentication data storage i, j session-related indices A0 logical start address of the session-related memory subarea A1 logical end address of the session-related file management system A2 logical end address of the area occupied with data within the session-related memory subarea A3 Logical end address of the session-related memory subarea AT i , AT j session-related authentication data K i session-related key M i ; M j Memory subarea(s) OIL isession-based file management system (overlay) RD i session-related read data R Read access VCC activation signal, especially power supply signal W i Writing session WD i session-related write data w write access Z i session-related additional secrecy

Claims

[1] A method (100) for session-based and secure access control to a data storage system, the method (100) comprising: Detecting (110) an activation signal to initiate access to the data storage system; and at least one writing session (W i ) for writing session-related data (WD i ) into the data storage system (210); wherein each of the at least one writing session (W i ) includes: in response to detecting (110) the activation signal, determining (135) a write session for writing the data (WD i ) free physical memory subarea (211,...,215; M i ) of the data storage system (210) and selectively allocating this memory subarea (211,...,215; Mi) to this write session (W i ); Receiving (140) or generating the data received during the write session (W i) data to be written (WDi); protecting (155) the data (WDi) by means of access protection that protects them from subsequent access by unauthorized other access sessions to the data storage system (210); and Outputting (160) the access-protected data in order to store them in the memory subarea (211,...,215; M) selectively assigned to the write session i ) of the data storage system (210) or to cause this to be done. [2] The method (100) of claim 1, wherein the received or generated write session-related data (WD i ) are at least partially recording data which represent one or more real events or states of objects recorded continuously or repeatedly over a certain period of time by means of a recording system (405). [3] Method (100) according to one of the preceding claims, wherein the access protection comprises at least one of the following measures: a cryptographic encryption (155) of the write session-related data (WD i ); the or each further write session is only initiated depending on a previous successful authentication (120, 125) of a write session (W i ) requesting a write request. [4] The method (100) of claim 3, wherein the encryption (155) of the write session-related data (WD i ) using integrity-protecting and / or symmetric encryption. [5] Method (100) according to claim 3 or 4, wherein the encryption (155) of the write session-related data (WD i ) per writing session (W i ) using one of these respective writing sessions (W i ) individually assigned cryptographic key (K i ) takes place. [6] The method (100) of claim 5, further comprising: Receiving (150) or generating a cryptographic key (K i ) defined additional secret (Z i ); where for encrypting (155) the data to be written (WD i ) per writing session (W i ) in addition to the respective cryptographic key intended for encryption (K i ) the additional secret (Z i ) is used, so that a targeted decryption of the encrypted data is only possible with knowledge of both a secret decryption key corresponding to the cryptographic key and the additional secret (Z i ) is possible. [7] Method (100) according to one of the preceding claims, wherein: the method (100) several writing sessions (W i ); determining (135) the respective writing session (W i) to be assigned to the physical memory sub-area (211,...,215; Mi) of the data storage system (210) within the framework of a direct or indirect address mapping from an address space (305) with logical memory addresses to an address space with physical memory addresses of the respective write session (W i ) to be allocated physical memory area (211,...,215; M i ) takes place; and for at least two of the writing sessions (W i ) the respective logical address spaces (305) for the address mapping match at least with regard to their logical start address. [8] Method (100) according to one of the preceding claims, wherein determining (135) a value during the respective writing session (W i ) for writing (160) the write session-related data (WD i) to be used free physical memory subarea (211,...,215; Mi) of the data storage system (210) and the selective allocation of this memory subarea (211,...,215; Mi) to this write session in dependence on a session counter (230) which is changed each time the activation signal is detected (110), so that each counter reading (i) of the session counter (230;) is selectively assigned exactly one write session (W i ) and exactly one specific corresponding memory subarea (211,...,215; Mi) is assigned. [9] Method (100) according to claim 8, wherein the changes in the counter reading (i) always occur in the same counting direction. [10] Method (100) according to one of the preceding claims, wherein at the beginning of each writing session (W i ) for the respective writing session (W i) assigned to a memory subarea (211,...,215; Mi) a file management structure (OL i ) is defined (135), which is used for the subsequent writing (160) of data within the write session (W i ) is used. [11] Method (100) according to claim 10, wherein the data for writing (160) within the respective writing session (W i ) via the adapted file management structure (OL i ) available size of the allocated physical memory subarea (211,...,215; Mi) by the file management structure (OL i ) is offered as one of the following two options: a) The total remaining physical memory size (220) of the data storage system (210) that is still unwritten or released for overwriting; b) A predefined memory size or, if this is no longer fully available, a physical remaining memory size (220) of the data storage system (210) that is still available and unwritten or released for overwriting. [12] Method (100) according to claim 11, wherein in the context of option b) the memory size is configurable within the scope of the actually still available unwritten or overwriting enabled physical residual memory size (220) and, for this purpose, depending on the respective write session (W i ) is predefined. [13] Method (100) according to one of the preceding claims, further comprising at least one reading session (R j ) for read access to data previously stored in at least one write session (W j ) data written into the data storage system (210), wherein the read session (R j ) includes: Checking (120, 125) the admissibility of the respective pending read access by authenticating an object to which read access is to be granted; If the check (120, 125) shows that the read access is permissible, determining (170) at least one memory subarea (211,...,215; Mi) assigned to the authenticated object from the set of one or more of the previous write sessions (W j ) respectively assigned memory sub-areas (211,...,215; Mi); Reading (185a; 185b; 185c) access-protected data from the one or more memory sub-areas (211,...,215; Mi) thus determined; Making the read data accessible (RD j ) by removing (190) the access protection within the current reading session (R j ); and Output (190) of the data made accessible (RD j ). [14] Method (100) according to claim 13, wherein the check (120, 125) is or is defined such that it results in the read access being permissible if and to the extent that at least one of the following conditions applies within the scope of the read access: The data to be read out during read access (RD j ) were written after an activation signal was last detected; The data to be read out during read access (RD j ) are classified as data that should be readable with every permitted read access. [15] Method (100) according to claim 13 or 14 in conjunction with one of claims 10 to 12, wherein the reading of the access-protected data (RD j ) from a respective specific memory sub-area (211,...,215; Mi): Checking (180) whether the respective read access relates to a memory address (315) in the specific memory sub-area (211,...,215; Mi) into which data has already been written in the context of a preceding write session relating to the memory sub-area (211,...,215; Mi); If this is the case according to the result of the test (180) for the respective read access, reading (185a) the access-protected data (RD j ) using a mapping of logical memory addresses to physical addresses of the memory subarea (211,...,215; Mi); and Otherwise, reading (185b) the access-protected data (RD j ) using the file management structure (OL) individually assigned to the memory subarea (211,...,215; Mi) j ). [16] The method (100) of claim 15, further comprising: Checking (175) whether the respective read access refers to a logical memory address (315; 325) for the specific memory sub-area (211,...,215; Mi) which is accessible via the file management structure (OL j ) is accessible; if this is the case, reading (185a; 185b) the access-protected data (RD j ) according to the method (100) of claim 15; and otherwise, reading (185c) the access-protected data (RD j ) using a mapping of this logical memory address to a non-file management structure (OL j ) accessible physical address of the memory subarea (211,...,215; Mi). [17] Method (100) according to one of claims 10 to 12, wherein the file management structure (OL) assigned to the memory subarea (211,...,215; Mi) for the respective write session j) is written into the memory subarea (211,...,215; Mi). [18] Data processing system (205) for session-based and secure access control to a data storage system (210), wherein the data processing system (205) is configured to carry out the method (100) according to one of the preceding claims. [19] Data processing system (205) according to claim 18, comprising: An access protection device (225) for protecting the write session-related data (WD i ) based on access protection; A detection device (230) for detecting the activation signal; and an allocation device for determining a free physical memory sub-area (211,...,215; Mi) of the data storage system (210) to be used during the respective write session for storing the write session-related data and for selectively allocating this memory sub-area (211,...,215; Mi) to the respective write session; and an interface for outputting the access-protected data in order to write them into the memory sub-area (211,...,215; Mi) of the data storage system (210) selectively assigned to the respective current write session or to cause this to be done. [20] Storage medium, comprising: a data processing system (205) according to claim 18 or 19; and a data storage system (210) having at least one data memory; wherein the data processing system (205) and the data storage system (210) are integrated in the storage medium (200) as a common structural unit; and the data processing system (205) is configured to execute the method (100) according to one of claims 1 to 17 for session-based and secure access control to the data storage system (210). [21] Storage medium (200) according to claim 20, wherein the storage medium (200) is designed as a mobile device. [22] A recording system (405) for continuously or repeatedly sensorily detecting real events or states of objects over a period of time and for providing recording data representing these detected events or states; wherein the recording system (405) is configured to cooperate with a data processing system (205) according to claim 18 or 19 to use a storage medium (200) according to claim 20 or 21 to store the recording data. [23] Recording system (405) according to claim 22, wherein the recording system (405) is configured to enable an exchange of the storage medium (200) by a user of the recording system (405) in order to alternatively use a plurality of mutually interchangeable mobile storage media (200) according to claim 21, each temporarily for storing the recording data as the storage medium (200). [24] A recording system (405) according to claim 22, comprising a data processing system (205) according to claim 18 or 19 integrated therein. [25] A computer program or computer program product comprising instructions which, when executed on one or more processors of a data processing system (205) according to claim 18 or 19, a storage medium (200) according to claim 20 or 21, or a recording system (405) according to claim 24, cause the method (100) according to any one of claims 1 to 17 to be carried out.

Citation Information

Patent Citations

  • System and Method for Processor-Based Security

    US20100281273A1