Data security protection method, device, system, security control framework, and storage medium
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- 黄建邦
- Filing Date
- 2023-05-09
- Publication Date
- 2026-05-19
AI Technical Summary
Existing technologies lack effective solutions for ensuring data security when removable storage devices are connected to computers, as they often pose threats to each other's data security, leading to potential data risks and leakage.
A data security protection method and apparatus that includes a protection module installed in a target device, which controls read-write permissions of a storage device connected to a computer device, ensuring secure data interaction by matching the permissions with pre-set protection modes.
The solution effectively protects data security by controlling permissions, preventing data destruction and leakage, and enhancing the security of both computer and storage devices without the need for additional security software.
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
Technical Field
[0001] <Cross - reference to Related Applications> This application claims the benefit of Chinese Patent Application No. 202210504332.8, filed on May 10, 2022, and titled "Data Security Protection Method, Apparatus, Protection Apparatus, and Storage Medium", and Chinese Patent Application No. 202210781724.9, filed on July 4, 2022, and titled "Data Security Protection Method, Apparatus, Target Apparatus, and Storage Medium", both of which are incorporated herein by reference in their entirety.
[0002] This application relates to the field of information security technology, and in particular, to a data security protection method, apparatus, system, security control framework, and storage medium.
Background Art
[0003] Removable storage devices are widely used in daily work and life. However, when a removable storage device is connected to a computer for data processing operations such as data copying, data risks are likely to occur. The removable storage device and the computer may pose threats to each other's data security.
Summary of the Invention
[0004] Embodiments of the present application provide a data security protection method, apparatus, system, security control framework, and storage medium, which can protect the data security of a storage device and a computer device.
[0005] According to a first aspect, the present application provides a data security protection method applied to a target device. A protection module is installed in the target device. The protection module has at least one protection mode, and the protection mode is used to control the read - write permissions of a storage device of a computer device. The method includes: performing permission control on a data interaction command for data interaction between a computer device and a storage device transmitted by the computer device according to the current protection mode of the target device; including, when the data interaction command meets the permission requirements corresponding to the current protection mode, responding to the data interaction command.
[0006] Specifically, the data security protection method suitable for the protection module is when receiving a data interaction command transmitted by a computer device, determining a current protection mode which is one of at least one pre-set protection modes by the protection module; wherein a data source targeted by the data interaction command is one of at least one data source specified in the current protection mode, and when an operation type on data in the data source of the data interaction command matches an operation type specified in the current protection mode, including responding to the data interaction command; the protection module is arranged at an interface for connecting to the storage device of the computer device, or a storage device, or an intermediate device; the intermediate device connects the computer device to the storage device.
[0007] According to a second aspect, the present application further provides a data security protection module applied to a target device, wherein a protection module is installed in the target device, the protection module has at least one protection mode, and the protection mode is for controlling read and write permissions to a storage device of a computer device, and the device includes a control unit configured to perform permission control on a data interaction command for data interaction between a computer device and a storage device transmitted by the computer device according to the current protection mode of the target device; When the data interaction instruction meets the permission requirements corresponding to the current protection mode, it includes a response unit configured to respond to the data interaction instruction.
[0008] According to a third aspect, the present application further provides a target device provided with a protection module, a first interface for connecting to a storage device, and a second interface for connecting to a computer. The protection module has at least one protection mode, and the protection mode is for setting read and write permissions to the storage device of a computer device. The target device includes one or more processors and a memory. The memory is configured to store a computer program. When the computer program is executed by the processor, it implements the steps of the data security protection method described in the first aspect.
[0009] According to a fourth aspect, the present application further provides a target device provided with a protection module integrated in a processor. The protection module has at least one protection mode, and the protection mode is for setting read permissions to the storage device of a computer device. The target device includes one or more processors and a memory. The memory is configured to store a computer program. When the computer program is executed by the processor, it implements the steps of the data security protection method described in the first aspect.
[0010] According to a fifth aspect, the present application further provides a computer-readable storage medium storing a computer program. When the computer program is executed by a processor, it implements the steps of the data security protection method described in the first aspect.
[0011] According to the sixth aspect, the present application further provides a computer program product, which, when executed on a computer device, causes the computer device to execute the steps of the data security protection method of the first aspect.
[0012] Another embodiment of the present application provides an intermediate device. The intermediate device a first port for connecting to a computer device, a second port for connecting to a storage device, a dialogue module including at least one of a touch screen, a voice dialogue device, a plurality of buttons, a slide switch, and an interactive control having at least two options, and a protection module connected between the first port and the second port and configured to implement the steps of the data security protection method provided by the above embodiment.
[0013] Another embodiment of the present application provides a device system including a computer device, a storage device, and the intermediate device provided by the above embodiment.
[0014] Another embodiment of the present application provides a storage device, which has a first port for connecting to a computer device, a protection chip configured to implement the steps of the data security protection method provided by the above embodiment, a control chip connected to the first port via the protection chip, and a memory chip connected to the control chip and configured to perform memory management on the data in the memory area under the control of the control chip.
[0015] One embodiment of the present application further provides a storage device, which has a first port for connecting to a computer device, A protection module is arranged, and a control chip configured to implement the steps of the data security protection method provided by the above embodiment, A memory chip that is connected to the first port via the control chip and is configured to perform memory management on the data in the memory area under the control of the control chip.
[0016] Another embodiment of the present application provides a storage device. The storage device A first port for connecting to a computer device, A control chip that is connected to the first port and is configured to generate a corresponding control command based on a data interaction command transmitted by the computer device, A memory chip connected to the control chip, A protection module is arranged in the memory chip, and by adopting the steps of the data security protection method described in the above embodiment, it is configured to process the control command transmitted by the control chip.
[0017] Another embodiment of the present application provides a security control framework. The security control framework A setting module configured to set a protection scenario, A generation module configured to generate setting information of the protection scenario or software having the protection scenario, and One protection scenario corresponds to at least one protection mode. By arranging the setting information or the software having the protection scenario in the hardware device, the hardware device has a function corresponding to the steps of the data security protection method described in the above embodiment.
[0018] Compared with the prior art, the beneficial effects of the present application are as follows. In this application, in order to control the read / write permissions to the storage device of a computer device, a protection module is arranged in the target device to ensure the communication security between storage devices, avoid the computer data security risks caused by the connection of malicious storage devices to the computer device, and avoid the data leakage of the storage device caused by the computer device maliciously accessing the private data of the storage device. At the same time, in this application, according to the current protection mode of the target device, the permission control of the data interaction command sent by the computer device is executed. When the data interaction command meets the permission requirements corresponding to the current protection mode, by responding to the data interaction command, it is ensured that the computer device accesses the storage device under the current protection mode of the target device, avoiding the data destruction of the storage device caused by viruses in the computer device, avoiding the data leakage caused by direct access to the storage device, and improving the data security of the storage device.
Brief Description of the Drawings
[0019] To more clearly illustrate the embodiments of this application or the prior art solutions, the attached drawings used in the embodiments or the prior descriptions are briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. Those skilled in the art can obtain other drawings based on these drawings without creative labor.
Figure 1
Figure 2a
Figure 2b
Figure 2c
Figure 3
Figure 4
Figure 5
Figure 6a
Figure 6b - 6d
Figure 7
Figure 8
Figure 9a
Figure 9b
Figure 9c
Figure 9d
Figure 10a - 10d
Figure 11a - 11b
Figure 12
Figure 13
Figure 14a
Figure 14b
Figure 14c
Figure 14d
Figure 14e
Figure 14f
Figure 14g
Figure 14h
Figure 14i
Figure 14j
Figure 15
Figure 16
Figure 17
Figure 18a
Figure 18b
Figure 19
Figure 20a - 20b
Figure 21
Figure 22
Figure 23
Figure 24
Figure 25
Figure 26a
Figure 26b
Figure 27
Figure 28a
Figure 28b
Figure 28c
Figure 28d
Figure 29
Figure 30
Figure 31
Embodiments for Carrying Out the Invention
[0020] Hereinafter, the technical solution according to the embodiments of the present application will be clearly and completely described with reference to the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, not all of the embodiments. All other embodiments obtained by those skilled in the art based on the embodiments of the present application without creative labor are included in the protection scope of the present application.
[0021] As described in the related art, current storage devices and computer devices may pose threats to each other's data security. In the case of computer devices: 1. There is a possibility that the storage device contains malicious code. If the antivirus software or other security software installed on the computer device fails to detect and remove it, the computer device may accidentally copy and execute Trojan horses, viruses, or other malicious programs. 2. The storage device may contain malicious hardware parameters, which may cause a buffer overflow in vulnerable security software when read by the computer, and execute pre-set malicious instructions. 3. The storage device may disguise itself as an input device such as a keyboard or mouse, perform preset keyboard or mouse input operations when connected to the computer, copy and execute malicious programs on the computer, or perform other malicious input operations. In the case of storage devices: 1. The computer device can modify or delete the data on the storage device, or write malicious programs such as Trojan horses and viruses to the storage device. 2. Some private file data may be read and copied by the computer device, and even some deleted file data and hidden file data may be read and copied by the computer device, which may cause data leakage from the storage device. 3. In addition, due to improper storage by the user of the storage device, the data on the storage device may also be stolen.
[0022] Regarding the protection of computer devices, the prior art usually involves installing antivirus software on a computer to scan files in the connected storage device, or installing access control software for the storage device and not permitting access to storage devices that are not pre-registered. Whether installing antivirus software or installing control software on a computer, firstly, the cost is high. For computer users, installing software requires some computer resources and software costs. For storage device users, it is not practical to install software corresponding to the connected computer for safe use when connecting to a computer. Secondly, there are also limitations in software, and some viruses and Trojan horses cannot be effectively detected and removed. Thirdly, the process of installing software is also dangerous. For example, there are problems with the software source, and some malicious programs are pre-bundled, forming new security risk points. Fourthly, software needs to determine the hardware characteristic parameters of the connected device. If there are coding vulnerabilities (such as buffer overflows) in the software itself, a malicious device can control the computer device by sending malicious hardware characteristic parameters to attack the software. Fifthly, existing security software has difficulty determining whether the device to be connected is a storage device, a keyboard, or a mouse device. The device to be connected itself may report its device type (for example, a device that appears to be a USB flash drive may be reported as a large-capacity storage device type, or a mouse device type, or a keyboard device type, or a combination of the above device types), and a malicious device can report the type of the keyboard or mouse to the computer device and maliciously operate the computer device.
[0023] The prior art mainly focuses on the protection of computer devices, and there is almost no protection scheme for storage devices. The main reason is that in the design of the control chip of the storage device, usually, the security function of the storage device cannot be changed or security software cannot be installed. There are read-only storage devices in the market. Although the data in the storage device cannot be tampered with, the data can be read. There are also storage devices with data encryption functions, and the encryption functions installed in such storage devices can be easily decrypted by reverse technology.
[0024] Before introducing the embodiments of the present application, some technical terms in this specification will be briefly explained.
[0025] USB communication rules: USB can be divided into a master mode (computer) and a slave mode (USB flash drive). The master actively sends data interaction commands to the slave, and the slave responds passively according to the data interaction commands.
[0026] Regarding the principle of enumeration, in the case of a storage device such as a USB flash drive, enumeration is a process in which a computer reads the storage device. In the case of a removable storage device (mass storage device), first, it is to read the basic hardware parameters including the parameters of the hardware descriptor, configuration descriptor, port descriptor, and endpoint descriptor, and load driver information according to various parameters to realize the connection of the hardware. Second, it is to read the parameters of the removable storage device, such as the size of the capacity and whether it is read-only. Third, it is to read the file system information so that the computer's operating system can display the drive letter. However, during the use of the protection module, the enumeration process of the operating system may not be strictly observed, but it is necessary to read the data required for the enumeration of the removable storage device.
[0027] Differences between Files and Folders: According to some file system protocols (such as FAT32 and ExFAT), the above root directory is essentially the same as a specific folder, and the root directory is a special folder. A folder is essentially the same as a file, and a folder is just a special file. For example, a file with the file name A.txt may have the content "123456". The folder named showdir contains information about the folders or files within that directory. For example, it is the attribute and the first sector address of the file test.txt, or the attribute and the first sector address of the folder test2. Furthermore, when reading the data at the first sector address of the file test.txt, the content of the file "123456" is read.
[0028] JPEG2025517181000002.jpg78170 Table 1 takes the FAT32 file system as an example (file information of A.txt): The starting cluster number is 0x1d, the first sector (starting sector address) can be obtained according to the calculation of the file system, the corresponding cluster chain can be obtained from the FAT table, and the collection of sector addresses of the file data can be obtained by calculating according to the cluster chain. The data of the collection of sector addresses is the content data of the file A.txt, such as the binary data of the string "123456".
[0029] JPEG2025517181000003.jpg78170Table 2 takes the FAT32 file system as an example (folder showdir): The starting cluster number of the folder showdir is 0x09, and according to the file system of the storage device for this test, the corresponding first sector (starting sector address) is 0x00010038 (note: the sector addresses calculated by different file systems and storage devices are different). The corresponding cluster chain can be obtained from the FAT table, and the collection of sector addresses of the file data can be obtained by calculating according to the cluster chain. The data of the collection of sector addresses is the information of subfolders and files included in the folder showdir, such as the information of file A.txt and the subfolder information that matches the data structure of the folder showdir.
[0030] The first embodiment of the present application provides a protection module, which may be an independent device (also called an intermediate device) for connecting a storage device and a computer device. For example, the portable device may be a USB guard interface fixed to the computer device. This may be called a portable USB flash drive hardware firewall, a removable storage media data ferry device (manual confirmation mode), a secure USB HUB, etc. Among them, the removable storage media includes USB flash drives, TF cards, SD cards, removable hard disks, etc. The protection module may also be a storage device having the corresponding functions of the protection method provided by each embodiment of the present application, and the storage device may be called a new type of secure USB flash drive or a removable hard disk, a dividable USB flash drive or a corresponding memory card (TF card, SD card, etc.). The storage device is a measure that simultaneously mounts intermediate protection (USB interface), card readers (SD, TF card interfaces), and memory chips, and is also a physical data source that can be selected and connected through a slide switch, a touch screen, a button, an interactive control having at least two options, etc. The storage device can also be made into a network storage disk that can switch between different network data sources. In the technical solution provided by each embodiment of the present application, innovation is made in the software form in which the protection module can have at least one protection mode, for example, read-only mode, specific file mode, blank file mode, logical split disk mode, sector limit mode, file type limit mode, encrypted write mode, decrypted read mode, manual confirmation mode, hardware type connection protection mode, data information protection mode of the storage device, device privacy protection mode, backup mode, etc.
[0031] The protection module can be made small in size, and the user can carry it around or attach it to the data interface (USB connection port) of a computer device or the connection port of a storage device for a long time. The protection module is an intermediate device for physical communication transmission between a computer device and a storage device, and controls security restrictions, security changes, etc. for communication transmission data packets according to user settings, protecting the computer or the connected storage device. It should be noted that the protection module corresponding to the technical solution provided by the embodiments of the present application can also be incorporated and adopted in the storage device, and the intermediate device is not required. A storage device integrated with a protection module or a security main control chip can protect the data security of the storage device according to user settings.
[0032] In the technical solution provided by the embodiments of the present application, the transmission and reception of communication data between a storage device and a computer device are controlled by an intermediate device and then transmitted. The computer device and the storage device are separated from each other and cannot directly obtain data from each other. Here, the intermediate device may be in the form of firmware without an operating system, and it is difficult for a computer device or a storage device containing a malicious program to change the operation logic of the intermediate device through vulnerabilities. The intermediate device uses a standard communication protocol and can run in matching with the driver of a large-capacity storage device attached to the operating system, so it can be connected to most storage devices without installing a driver when connecting to a computer device.
[0033] The user of the intermediate device can operate selectable interactive controls such as buttons and switches on the intermediate device to execute settings of protection modes, such as read-only mode, specific file mode, blank file mode, logical split disk mode, sector limit mode, file type limit mode, encrypted writing mode, decrypted reading mode, manual confirmation mode, hardware type connection protection mode, data information protection mode of the storage device, device privacy protection mode, backup mode, etc., according to various usage scenarios such as writing and reading data to / from the removable storage device. At the same time, the intermediate device also has three auxiliary settings: encryption of file content data, log retention, and extended settings.
[0034] That is, in the data security protection method provided by the present application, in order to set the read / write permission to the storage device of the computer device, a protection module is arranged on the target device, so as to ensure the communication security between storage devices, avoid the computer data security risk caused by the connection of malicious storage devices to the computer device, and avoid the data leakage of the storage device caused by the computer device maliciously accessing the private data of the storage device. Without installing security software on the computer device, the security risks existing in the installation of security software can be effectively avoided. At the same time, in the present application, according to the current protection mode of the target device, the permission control of the data interaction command sent by the computer device is executed. When the data interaction command meets the permission requirements corresponding to the current protection mode, by responding to the data interaction command, it is ensured that the computer device accesses the storage device under the current protection mode of the target device, avoiding the data destruction of the storage device caused by viruses in the computer device, and also avoiding the data leakage caused by direct access to the storage device. In addition, the protection module is arranged on the target device, effectively avoiding cracking the protection mode of the protection module from the computer operating system level by malicious programs, and further improving the data security of the storage device.
[0035] Referring to FIG. 1, FIG. 1 is a flowchart of a data security protection method provided by an embodiment of the present application. The data security protection method in the embodiment of the present application is applied to a target device, and a protection module is installed on the target device. The protection module has at least one protection mode, and the protection mode is used to control the read / write permission to the storage device of the computer device.
[0036] Optionally, the target device is an intermediate device equipped with a protection module such that the storage device functions as an intermediate connection node when establishing a communication connection with the computer device. Naturally, the communication connection includes both wired and wireless connections. Exemplarily, in one scenario of a wired connection, a schematic diagram of the structure of the intermediate device is shown in FIG. 2a. The intermediate device 200 is provided with a first interface 201 for connecting to the storage device and a second interface 202 for connecting to the computer device. When it is necessary to establish a communication connection between the storage device and the computer device, connect the storage device to the first interface 201 of the intermediate device and connect the second interface 202 of the intermediate device 200 to the computer device. Note that the number of the first interfaces may be plural, and the intermediate device can be connected to a plurality of storage devices simultaneously. It should be noted that the first and second interfaces may be Universal Serial Bus (USB) interfaces. The first interface may include an eMMC (Embedded Multi Media Card) interface for directly connecting to an SD card, a TF card, etc., and a SATA (Serial Advanced Technology Attachment) interface, an NVMe (NVM Express), an M.2, etc. data interface for directly connecting to a hard disk, a flash memory, an SSD storage device, etc. The structure of the intermediate device shown in FIG. 2a is used only as an example and not as a limitation. It should be understood that other embodiments, such as the structure shown in FIG. 2b, may include more or less components. The first interface 201 in FIG. 2b may be a slot type interface. FIG. 2c shows an example of a structural form of the intermediate device with the protection module integrated. The user can select the current protection mode of the protection module through an interactive control (such as a control on the operating storage device).
[0037] Optionally, the target device is a storage device equipped with a protection module, and the protection module may be integrated into the chip (processor), integrated circuit, or hardware of the storage device so that the storage device has the function of the data security protection method according to the embodiments of the present application. When the target device is an intermediate device, the data transmitted by the computer device (or storage device) is transferred by the intermediate device to the storage device (or computer device). When the target device is a storage device equipped with a protection module, the computer device (or storage device) directly transmits data to the storage device (or computer device), but the protection module in the storage device needs to perform rights control and the like on the received (or transmitted) data. This will not be repeated hereinafter. It should be noted that when the target device is an intermediate device equipped with a protection module, the storage device may be a storage device without a protection module.
[0038] Optionally, the storage device includes, but is not limited to, a USB flash drive, a removable hard disk, a hard disk, a card reader (SD card, TF card), an external optical drive, etc., and the storage device may also have a networking function. The computer device includes, but is not limited to, a laptop, a desktop computer, an embedded device, an IoT device, and an industrial control device.
[0039] Optionally, the protection module may be arranged at the interface of the computer device for connecting the storage device.
[0040] Another embodiment of the present application provides an intermediate device (or module) connected between a computer and a removable storage device to solve the problem that when a removable storage device (such as a USB flash drive, an SD card, a removable optical drive, a removable hard disk, etc.) is connected to a computer to copy data, the current communication protocol and related technologies do not enforce data rights restrictions, thereby causing a data risk problem.
[0041] It can be seen that there are two types of interaction logics provided in the embodiments of the present application. One is the interaction logic as an intermediate device: the computer device sends a command -> the intermediate device performs permission control -> the storage device responds -> the internal storage medium is read and written.
[0042] The other is that as an integrated device (such as a storage device with a protection module), the interaction logic is reduced as follows: the computer device sends a command -> the control chip of the storage device filters and responds (hardware integration: protection chip + control chip, software integration: the control chip includes a protection method module + a read / write control module) -> the internal storage medium is read and written.
[0043] As shown in FIG. 1, the data security protection method in the embodiments of the present application includes steps S101 to S102, which are described in detail as follows.
[0044] Step S101, perform permission control on the data interaction command for the data interaction between the computer device and the storage device sent by the computer device according to the current protection mode of the target device.
[0045] That is, before step S101 above, when receiving the data interaction command sent by the computer device, it may include the step of determining the current protection mode, which is one of at least one preset protection mode by the protection module.
[0046] Here, "performing permission control on the data interaction command" specifically means judging whether the data source targeted by the data interaction command is one of at least one data source specified in the current protection mode, It may also be to determine whether the operation type on the data in the data source of the data interaction command matches the operation type specified in the current protection mode.
[0047] The data source targeted by the data interaction command is one of at least one data source specified in the current protection mode. When the operation type on the data in the data source of the data interaction command matches the operation type specified in the current protection mode, the data interaction command meets the permission requirements corresponding to the current protection mode.
[0048] In a specific embodiment, if the protection module is an intermediate device or a storage device, and if the intermediate device or the storage device is equipped with an interactive device, the method provided in this embodiment is A. Obtaining a target protection mode selected by the user from the at least one protection mode according to the user's operation on the interactive device of the first device; B. Setting the target protection mode as the current protection mode of the protection module, and may include Here, the interactive device includes at least one of a touch screen, a voice interaction device, a plurality of buttons, a slide switch, and an interactive control having at least two options.
[0049] Here, the interactive control having at least two options is, for example, a knob switch, a switch having a plurality of stop positions, a switch having a plurality of toggle postures, etc.
[0050] Optionally, the intermediate device or the storage device provided with the protection module may not be provided with an interactive device. The current protection mode can be set in advance or in real time. Specifically, the current protection mode can be set by a toggle switch, a remote control, or computer settings. Exemplarily, in one possible implementation form, the target device (such as the intermediate device described above or the storage device provided with the protection module) is provided with a physical switch for selecting the protection mode, and the current protection mode is selected by toggling the physical switch. In another possible implementation form, the target device is provided with a communication unit such as Bluetooth (registered trademark), infrared, or ultra-wideband for connection to a remote control device, and the current protection mode is selected through the remote control device. In another possible implementation form, the target device communicates with a computer device having global authority, and the current protection mode is selected through the computer device. In the case of the computer setting method, it should be noted that the computer needs to be set before the storage device executes data interaction with the computer device.
[0051] In this step, the protection modes include, but are not limited to, full disk read-only mode, specific file read-write mode, location-limited read-write mode, file-limited read-write mode, decryption read mode, encryption write mode, and logical split disk mode. The full disk read-only mode means that reading of all files in the storage device is permitted. The specific file read-write mode means that reading and writing of specific files in the storage device are permitted. The read-write mode of the location-limited read-write mode means that reading and writing of files corresponding to the target sector address in the storage device are permitted. The read-write mode of the file-limited mode means that reading and writing of files with the characteristics of the target file in the storage device are permitted. The decryption read mode means that data in the read process is decrypted. The encryption write mode means that data in the write process is encrypted. The logical split disk mode means a mode of splitting the storage device and connecting it to a computer.
[0052] More specifically, the at least one protection mode may include, but is not limited to, read-only mode, specific file mode, blank file mode, sector-limited mode, file type-limited mode, encryption write mode, decryption read mode, manual confirmation mode, logical split disk mode, hardware type connection protection mode, data information protection mode of the storage device, device privacy protection mode, backup mode, etc. Here,
[0053] The read-only mode means that the data source specified in the read-only mode is the data of the entire disk of the storage device, and the specified operation type is of the read-only type. The above full disk read-only mode can be understood as the read-only mode.
[0054] The specific file mode means that the data source specified in the specific file mode is at least one specific file in the storage device, and the specified operation type is read, write, or read-write type.
[0055] The blank file mode means that the data source specified in the blank file mode is at least one blank file automatically created or manually created in the storage device, and the specified operation type is a write type or a read / write type.
[0056] The sector limit mode means that the data source specified in the sector limit mode is at least one specific sector interval in the storage device, and the specified operation type is a read type, a write type, or a read / write type.
[0057] The file type limit mode means that the data source specified in the file type limit mode is at least one specific type of file in the storage device, and the specified operation type is a read type, a write type, or a read / write type.
[0058] The encrypted write mode means that the data source specified in the encrypted write mode is data within at least one second sector interval in the storage device, at least one first file, and / or at least one type of file, and the specified operation type is a write type.
[0059] The decrypted read mode means that the data source specified in the decrypted read mode is data within at least one second sector interval in the storage device, at least one second file, and / or at least one type of file, and the specified operation type is a read type.
[0060] The manual confirmation mode means that the data source specified in the manual confirmation mode is data within at least one third sector interval in the storage device, at least one third file, and / or at least one type of file, and the specified operation type is a read / write type.
[0061] The logical split disk mode is such that the data source specified in the logical split disk mode is at least one split disk in the storage device, and the specified operation type is read, write, or read / write type.
[0062] The hardware type connection protection mode determines whether there is no data source specified for the hardware type connection protection mode and whether the storage device is of the specified device type in the hardware type connection protection mode.
[0063] The data information protection mode of the storage device is such that there is no data source specified for the data information protection mode of the storage device, and in the data information protection mode of the storage device, the data information of the storage device sent to the computer device is processed protectively, and the data information of the storage device after the protection process is sent to the computer device at the enumeration stage.
[0064] The device privacy protection mode is such that there is no data source specified for the device privacy protection mode, and in the device privacy protection mode, the device privacy information sent to the computer device is processed protectively.
[0065] Here, the protective processing includes, but is not limited to, protective processing (such as packaging, deletion, etc.) for the hardware feature parameters of the storage device, protective processing for the storage information related parameters of the storage device, and protective processing for the device information (such as manufacturer information) of the storage device to protect the device privacy of the storage device.
[0066] In the backup mode, when there is no data source specified for the backup mode, in the backup mode, the data written to the computer device is synchronously written to the specified backup storage area, and / or before the protection module executes a write command, it reads the sector address data written by the computer device and writes it to the specified backup storage area, and / or the data of the important data sectors of the connected storage device is backed up and stored in the specified backup storage area. When restoration is triggered, the data in the specified backup storage area is read and written to the original data sectors of the storage device.
[0067] Each of the above protection modes can also be combined in various modes. For example, the logical split disk mode, the specific file mode, and the sector restriction mode can be combined, and thus the current protection mode becomes a combined mode after the combination of these three modes. In this combined mode, by restricting operations on specific files after logical splitting and performing sector restrictions, it is possible to make files other than specific files unreadable and writable.
[0068] It should be added here that the rights control in this embodiment is a process of controlling the data interaction between the computer device and the storage device based on the read / write range corresponding to the current protection mode. This should be understood as rights control in a broad sense, that is, as long as the purpose of controlling data interaction can be achieved, it belongs to the rights control defined in the embodiments of this application.
[0069] Optionally, read / write permissions include read-only permissions, write-only permissions, and read / write permissions. In different protection modes, the read / write permissions can be set to read-only, write-only, or read / write for different targets. For example, in the case of full disk read-only mode, the read / write permissions are read-only permissions for all files in the storage device. In the case of specific file read / write mode, the read / write permissions are at least one of read-only, write-only, and read / write permissions for a specific file. It can be understood that the read / write permissions in other modes can be derived based on the above examples and will not be repeated here.
[0070] Step S102, when the data interaction command meets the permission requirements corresponding to the current protection mode, respond to the data interaction command.
[0071] Specifically, the data source targeted by the data interaction command is one of at least one data source specified in the current protection mode, and when the operation type for the data in the data source of the data interaction command matches the operation type specified in the current protection mode, respond to the data interaction command.
[0072] In this step, the data interaction command includes a data read command for reading data in the storage device transmitted by the computer device and a data write command for writing data to the storage device. It can be understood that when the read / write permission is read-only permission, the data read command can be supported; when the read / write permission is write-only permission, the data write command can be supported; and when the read / write permission is read / write permission, both the data read command and the write command can be supported.
[0073] In one possible embodiment, when the target device is an intermediate device equipped with a protection module, the intermediate device receives a data interaction instruction sent by a computer device, performs permission control on the data interaction instruction based on the current protection mode, and transfers the data interaction instruction to a storage device when the data interaction instruction meets the permission requirements, and causes the storage device to execute a read / write operation corresponding to the data interaction instruction. In another possible embodiment, when the target device is a storage device equipped with a protection module, the storage device receives a data interaction instruction sent by a computer device, performs permission control on the data interaction instruction according to the current protection mode of the protection module, and when the data interaction instruction meets the permission requirements, the storage device executes a read / write operation corresponding to the data interaction instruction.
[0074] It should be noted that this application can protect the computer device and the storage device through various protection modes, meet the user's usage needs in various protection scenarios, and at the same time, perform permission control in the protection model of the target device to improve the security of the computer device and the storage device.
[0075] In some embodiments, based on the embodiment shown in FIG. 1, FIG. 3 shows a flowchart of the data security protection method of the second embodiment. Here, the same steps as in FIG. 1 are not repeated. As shown in FIG. 3, the method further includes Step S301: When a communication connection request between the computer device and the storage device is detected, identifying the device type of the first interface; Step S302: When the device type is a preset communication permission type, establishing a communication connection between the computer device and the storage device.
[0076] In this embodiment, the preset communication permission types include, but are not limited to, a mass storage device type or other preset security types. Optionally, the device type of the first interface can be determined by the read descriptor parameters. When the target device is an intermediate device equipped with a protection module, it can be understood that the descriptor parameters of the storage device are read from the storage device via the first interface of the intermediate device. When the target device is a storage device equipped with a protection module, the storage device can obtain the pre-stored descriptor parameters.
[0077] In some embodiments, when the target device is an intermediate device equipped with a protection module, and the intermediate device includes a first interface for connecting a storage device and a second interface for connecting a computer device, before step S301, further, when the storage device is connected to the first interface and the computer device is connected to the second interface, it includes the step of detecting a communication connection request between the computer device and the storage device.
[0078] In this embodiment, when a storage device and a computer device are respectively connected to the intermediate device, the intermediate device is powered on. After analyzing the data information of the storage device, if it is determined that the requirements are met (for example, it is determined that the storage device belongs to the device type specified in the current protection mode), an enumeration permission signal is sent to the computer device, and the computer device starts an enumeration operation to obtain the data information in the storage device. Based on the current protection mode, the intermediate device performs protection processing on the data information of the storage device, and feeds back the protected data information of the storage device to the computer device to establish a communication connection between the computer device and the storage device.
[0079] In some embodiments, when the target device is a storage device equipped with a protection module, before step S301, further, When the memory device is connected to the computer device, a communication connection request with the computer device is detected.
[0080] In this embodiment, after the memory device is physically connected to the computer device, in order to realize data interaction between the two, the computer device sends a communication connection request to the memory device, or the memory device sends a communication connection request to the computer device, and monitors the communication connection request through the protection module in the memory device.
[0081] Note that there is a possibility that a malicious program such as a Trojan virus is embedded in the memory device by some other means for some reason, and when the power is not supplied, the memory device itself does not detect the malicious program. Therefore, after the memory device is physically connected to the computer device and the memory device is powered on, in order to ensure the security of the computer device, the communication connection request between the computer device and the memory device is monitored to facilitate the subsequent identification of the memory device.
[0082] In some embodiments, after step S301, further, When the device type is a preset communication prohibition type, the communication connection request is interrupted.
[0083] In this embodiment, the preset communication prohibition types include, but are not limited to, human interface devices (HID), mass storage devices, and composite devices with HID, or other composite device types with functions. Among them, the human interface device is a definition of a device category, and HID devices include keyboards, mice, game controllers, joysticks, barcode readers, headphone / speaker volume controls, auxiliary displays, sensors, etc. Optionally, when the device type is a preset communication prohibition type, intercept information is also fed back, and the intercept information is for reminding that the memory device is a communication prohibited device.
[0084] Optionally, the intercept information is used to instruct the computer device to prompt with the drive letter string. For example, the computer device displays a device connected with the name "illegal device". The target device is provided with an indicator, and the intercept information can be displayed by the indicator. For example, when the indicator blinks (or lights up in red), it indicates that the currently connected storage device is a device whose connection is prohibited.
[0085] It should be noted that in this embodiment, by verifying the device type of the storage device, it is possible to avoid an illegal device disguising itself as a keyboard or a mouse device and connecting to the computer device, thereby avoiding the illegal device causing a security risk to the computer device and improving the security of the computer device.
[0086] In some embodiments, step S302 is transmitting the target hardware feature parameters of the storage device to the computer device, where the target hardware feature parameters are for establishing a communication connection between the computer device and the storage device.
[0087] In this embodiment, when the target device is an intermediate device, the target hardware feature parameters of the storage device are obtained and transferred to the computer device. When the target device is a storage device equipped with a protection module, the pre-stored target hardware feature parameters are transmitted to the computer device.
[0088] Optionally, the hardware feature parameter is a parameter for expressing the features of the storage device, including but not limited to the device manufacturer and product ID, device attributes, types used in the interface (such as mass storage devices), endpoint attributes (such as batch transmission), character strings, transmission speed, and power requirements. When the device is connected, it is necessary to verify the hardware feature parameter. If it is determined that the hardware feature parameter meets the requirements for establishing a communication connection, the computer device establishes a communication connection with the storage device according to the hardware feature parameter.
[0089] In one embodiment, the target hardware feature parameter may be a hardware feature parameter directly obtained from the storage device. In another embodiment, the target hardware feature parameter may be a feature parameter after filtering the hardware feature parameter directly obtained from the storage device. In yet another embodiment, the target hardware feature parameter may be a preset hardware feature parameter that matches the hardware feature parameter directly obtained from the storage device. In yet another embodiment, the target hardware feature parameter can also be directly preset by the protection module.
[0090] In some embodiments, transmitting the target hardware feature parameter of the storage device to the computer device includes the steps of obtaining, according to the device type of the storage device, the target hardware feature parameter corresponding to the device type from a preset parameter template, and transmitting the target hardware feature parameter to the computer device.
[0091] In this embodiment, according to the device type of the storage device, preset hardware characteristic parameters corresponding to the device type are obtained from a preset parameter template, and the hardware characteristic parameters obtained from the storage device are replaced with the preset hardware characteristic parameters with the target hardware characteristic parameters. Optionally, the preset parameter template includes preset hardware characteristics that can be read by a computer and establish communication corresponding to various device types.
[0092] Note that in this embodiment, by replacing and changing the hardware characteristic parameters of the storage device according to the hardware characteristic parameters corresponding to the device type, when the storage device is connected to and enumerated by the computer device, the hardware characteristic parameters of the storage device can be protected from being collected, so as to protect the privacy of the storage device while realizing a secure connection.
[0093] In some other embodiments, transmitting the target hardware characteristic parameters of the storage device to the computer device includes the step of obtaining the hardware characteristic parameters of the storage device, screening the hardware characteristic parameters according to the preset parameter type, and determining the target hardware characteristic parameters corresponding to the parameter type, and transmitting the target hardware characteristic parameters to the computer.
[0094] In this embodiment, the hardware characteristic parameters are screened to hold the target hardware characteristic parameters corresponding to the preset parameter type, and the filtered target hardware characteristic parameters conforming to the preset parameter type are transmitted to the computer device, and other parameters are not transmitted to the computer device as unknown parameters, so as to avoid transmitting the illegal parameters of the storage device to the computer device and ensure the data security of the computer device.
[0095] To avoid sending incorrect parameters of the storage device to the computer device, thereby ensuring the data security of the computer device, embodiments of the present application provide a mechanism for simulating the characteristic parameters of the storage device. That is, the method provided in this embodiment is as follows: Step 11: Before the communication connection between the computer device and the storage device is established through the protection module, simulate the control command of the computer device to obtain the first characteristic parameter of the storage device; Step 12: Based on the first characteristic parameter, determine whether the storage device is the device type specified in the current protection mode. If so, execute Step 13; otherwise, execute Step 15 (see below); Step 13: Based on the first characteristic parameter, generate a second characteristic parameter for simulating the storage device; Step 14 may include sending the second characteristic parameter to the computer device and establishing a communication connection between the computer device and the storage device.
[0096] Here, the step of "generating a second characteristic parameter for simulating the storage device based on the first characteristic parameter" in Step 13 described above is as follows: 131. Obtain a preset parameter template, and according to the device type of the storage device reflected in the first characteristic parameter, obtain at least one parameter item that can represent the device of the device type from the preset parameter template to obtain the second characteristic parameter, or 132. Screen the parameter items in the first characteristic parameter, and obtain the second characteristic parameter based on at least one parameter item of the screened parameter items.
[0097] By replacing the above parameter template, the computer device and hardware features are further protected. That is, before the computer is formally connected, the parameter template is used for replacement or filtering. Using a fixed template can prevent the hardware descriptors of the connected storage device from attacking the computer using malicious parameters or unknown and dangerous parameters. For example, the storage device may contain malicious hardware parameters, and security software with a buffer overflow vulnerability may execute malicious instructions contained in this malicious hardware parameter when the computer is connected to the computer. By replacing the parameter features, the hardware parameter values such as the vendor ID, product ID, and string of the connected storage device can also be changed through the protection module, and the computer device reads from USB1 with the parameters changed after connection. Usually, there are two usage scenarios. The first is to protect the hardware feature parameters of the storage device such as the vendor ID, product ID, and string from leakage. The second is that some computer device security software can identify the existence of the protection module and execute connection control of the USB device. Non-specific USB hardware parameters are not allowed to be connected, and the hardware parameters set by the protection module are allowed to be connected. The connection of the storage device can be forced to be connected to the computer device only through the protection module, and direct connection of the storage device is not allowed, thereby protecting the data security of the computer device.
[0098] The method provided by this embodiment further Step 15, when it is determined based on the first feature parameter that the storage device is not the device type specified in the current protection mode, a step of ending communication with the storage device; Step 16, a step of transmitting first information to the computer device so that the computer device displays an identifier of a virtual disk and / or prompt information of an unauthorized device based on the first information. Here, when the virtual disk identifier is displayed, the first information further includes text corresponding to the first feature parameter, and the text is stored in a root folder corresponding to the virtual disk identifier.
[0099] It should be added here that steps 11 to 16 above may be steps in the enumeration stage in the interaction process between the computer device and the protection module. Of course, in the enumeration stage, in addition to performing protection processing on the first feature parameter of the storage device, protection processing may also be performed on the first storage information related parameter of the storage device. In this part of the content, a single technical point is explained using the method of disassembling technical points. There are overall embodiments below, and the solution provided by the embodiments of the present application will be described in detail. For example, the interaction process between the computer device and the protection module includes a preparation stage, an enumeration stage, and a data exchange stage. According to the current protection mode of the target device, permission control is executed on the data interaction command sent from the computer device. When the data interaction command meets the permission requirements corresponding to the current protection mode, the step in the data interaction stage responds to the data interaction command.
[0100] In some embodiments, based on the embodiment shown in FIG. 1, FIG. 4 shows a specific flowchart of step S101. As shown in FIG. 4, step S101 includes step S401, identifying the command type of the data interaction command, and step S402, when the command type is a preset command type corresponding to the permission requirements, determining that the data interaction command meets the permission requirements corresponding to the current protection mode.
[0101] In this embodiment, the instruction type includes a data read instruction for reading data in a storage device transmitted from a computer device, and a data write instruction for writing data to a destination in the storage device. Optionally, the data interaction instruction is analyzed via a protection module based on a preset analysis rule to identify the actual interaction function of the data interaction instruction, and the instruction type is determined according to the actual interaction function. Therefore, the instruction type can be used as an identification criterion, and rights control can be directly and effectively executed on the data interaction instruction transmitted from the computer device, preventing the data interaction instruction from illegally reading and writing to the storage device through camouflage or other means, thereby improving the security of the storage device.
[0102] Exemplarily, when the current protection mode is a read-only mode for File A, and the instruction type corresponding to the read-only mode should be a data read instruction, if the instruction type is a data write instruction for File A, the instruction type cannot meet the permission requirements of the current protection mode. If the instruction type is a data read instruction for File A, the instruction type meets the permission requirements of the current protection mode.
[0103] In some embodiments, based on the embodiment shown in FIG. 1, the protection mode is a read-only mode, and FIG. 5 shows a flowchart of the data security protection method of the third embodiment. The same steps as in FIG. 1 are not repeated. As shown in FIG. 5, the method further includes Step S501: In response to a parameter reading request transmitted from the computer device, return a read-only parameter to the computer device to cause the computer device to identify the storage device as a read-only device.
[0104] In this embodiment, the read-only parameter is for the computer device to identify the storage device as a read-only device. Exemplarily, after the computer device establishes a communication connection with the storage device and reads the read / write state of the device from the storage device, in the read-only mode, the target device feeds back the read-only parameter to the computer device to indicate that the storage device is a read-only device, so that the computer device can identify it as a read-only device, and the computer device only sends a data read command to the storage device under normal circumstances and reduces the trust in invalid commands other than the data read command.
[0105] Optionally, the above read-only mode is compatible with any one of other read / write modes, such as the full disk read-only mode, the read-only mode under the specific file read / write mode, the read-only mode under the position-limited read / write mode, and the read-only mode under the file-limited read / write mode.
[0106] The specific implementation effects of the read-only mode are as follows.
[0107] When the computer device recognizes the storage device as a read-only device and sends a request to obtain the read / write state of the device, the protection module returns the parameters in the read-only state. For example, when the computer device sends a command (MODE 6) to obtain the configuration of the storage device, the protection module returns a response indicating that the storage device is a read-only device. The computer device sets the device to read-only at the driver layer and does not permit data writing.
[0108] Specifically, when the protection module receives a request that the SCSI (Intelligent Universal Interface Standard) or UFI (Command Block Protocol) command sent by the computer device is 0x1A (MODE 6), it responds with a parameter date in a read-only state. For example, a normal storage device (such as a USB flash drive) responds with a state of "0x03 0x00 0x00 0x00" being readable and writable. In the read-only protection mode, the second bit (calculated from bit 0) is replaced with 0x08 and it responds with "0x03 0x00 0x08 0x00". When the computer device identifies it, it sets it as a read-only device. For example, there is no button to create a folder on the interface, and files on the computer device cannot be dragged and copied to the storage device.
[0109] Prevent the computer device from sending a data write command. The protection module filters all communication commands sent from the computer device with a white list, and allows only information related to initialization and data reading to be transferred to the storage device. Other information not in the white list (for example, SCSI or UFI command code is 0x28 (write command)) is directly discarded. Also, by prohibiting the storage device from sending information about write operations (for example, SCSI or UFI command code is 0x28 (write command)) and making the storage device always write-protected at the communication layer, malware can be effectively prevented from avoiding the restrictions of the operating system and forcibly writing data to the storage device.
[0110] Figure 6a is a schematic diagram of an example of an unrestricted (readable and writable) state of a USB flash drive. In the unrestricted (readable and writable) state, the contents of files on the disk can be deleted, new files can be created, and files can be edited. For example, as shown in Figure 6a, there is a menu button to select a "new" file, and the created file can also be selected.
[0111] Figures 6b, 6c, and 6d are schematic diagrams corresponding to the full-disk read-only mode. As shown in Figure 6b, in the full-disk read-only mode (where the removable storage medium with the intermediate device connected is set to read-only), there is no [Create] menu button for files in the menu called (such as by right-clicking). As shown in Figure 6c, in the full-disk read-only mode, there is no [Delete] menu button in the called menu. In the full-disk read-only mode, files cannot be edited or written, and as shown in Figure 6d, a prompt window is displayed. Examples corresponding to Figures 6b, 6c, and 6d are read-only configurations based on read-only parameters at the operating system level. When the user forcibly writes, the protection module also intercepts the written data interaction commands. The "full disk" in the full-disk read-only mode has a special meaning and does not refer to the entire hard disk, but rather to the "full disk" of the connected data source. For example, in the following logical split disk mode and specific folder mode, it can also be set to read-only.
[0112] In some embodiments, based on the embodiment shown in FIG. 1, FIG. 7 shows a schematic diagram of the specific steps of step S102. As shown in FIG. 7, the step S102 includes Step S601, in response to the data interaction command, perform a read and write operation on the target file in the storage device, and the read and write operation includes at least one of a read operation and a write operation.
[0113] In this embodiment, the reading operation includes reading the file data in the target file (i.e., the data of the corresponding sector address) and returning the file data to the computer device, and the writing operation includes writing the data carried by the data interaction command to the target file (i.e., the corresponding sector address). The target file is a file that is displayed on the computer device and is permitted to be read and written by the computer device, and includes, but is not limited to, a specific file based on sector mapping, a file corresponding to a preset sector address, a file having preset file characteristics, etc.
[0114] Optionally, when the target device is an intermediate device, if the data interaction command is a data reading command, the intermediate device transfers a data reading command that meets the permission requirements to the storage device for the reading operation on the target file in the storage device. When the target device is a storage device with a protection module, if the data interaction command is a data reading command, the storage device executes the reading operation on the target file based on the data reading command.
[0115] Note that in this embodiment, by using the target file as the object of the reading and writing operations and restricting the reading and writing of the computer device within the reading and writing range of the current protection mode, effective control of the reading and writing operations is realized, and the security of the computer device and the storage device is improved.
[0116] In some embodiments, when the protection mode is the specific file reading and writing mode, step S601 includes: mapping the sector address of the target file, which is a file displayed on the computer device, to a target address according to the data interaction command; and executing a reading and writing operation on the target file based on the target address.
[0117] In this step, the target file is a specific file, and the specific file is a file that the user has pre-selected or that is automatically created by the protection module and is permitted to be read and written by a computer device, and can be displayed to the user on the computer device. Mapping the specific file to the target address means mapping the sector address of the specific file in the storage device to the target address.
[0118] Optionally, the target address may be a certain sector address in the target device, a certain sector address in a storage device different from the specific file, or a sector address of another storage device connected to the target device. Therefore, the computer device can only identify the existence of the specific file (i.e., only display the specific file to the user on the computer device), and thus can only read and write to the specific file. Naturally, the specific file needs to be interpreted in an extended way. The specific file may be a file at the minimum level (for example, a text file named A.txt), or may be a folder.
[0119] Optionally, the specific file can be pre-selected. For example, the user can select a file through a computer device with global permissions, or the target device can automatically create a specific file. In some embodiments, when the storage device is connected to a computer device with global permissions through the target device, the specific file can be placed in a temporary sector area created by the target device to complete the file selection, and the specific file can be mapped to the storage device.
[0120] The specific file read / write mode includes at least one of a read-only mode, a write-only mode, and a read / write mode for a specific file. Exemplarily, when the specific file read / write mode is read-only for a specific file, the target device filters the command type of the data interaction command sent from the computer device, executes only the data read command, and for other types of commands other than the read command included in the data interaction command, does not execute the other type of command and feeds back information on completion of execution to the computer device. When the specific file read / write mode is a read / write mode for a specific file, the target device responds to both the read command and the write command in the data interaction command sent from the computer device.
[0121] Exemplarily, in the specific file read / write mode, in the preparation stage, the target device reads in advance the sector address interval of the root directory of the storage device (including from the first address to the last address of the sector, and the arrangement of the address positions may be non-consecutive) and the data sector address interval of the specific file. In the data interaction stage, when receiving a data interaction command, if the protection module analyzes that the sector address read / written in the data interaction command is within the address interval of the root directory, read / write is performed within the address interval corresponding to the specific file, and the data of the original root directory cannot be accessed.
[0122] Optionally, the read / write of a specific file can be realized through read / write restrictions as follows. The target device prohibits reading and writing to the data area of non-specific files by establishing a read / write restricted area, and only permits writing to blank data areas other than specific files.
[0123] Note that in this embodiment, by selecting a specific file and mapping it to the target device, the computer device can identify only the existence of the specific file, and the computer device is prevented from directly reading or writing data of non-specific files in the storage device, thereby protecting the data security of the storage device.
[0124] That is, when the current protection mode is the specific file mode, the method provided by this embodiment further Step 31: When the current protection mode is the specific file mode, determining at least one specific file or folder in the storage device; Step 32: Obtaining address information of the at least one specific file or folder; Step 33: Establishing a mapping relationship between the address information of the at least one specific file or folder and the address of the root directory.
[0125] When set for specific file reading and writing, first, the user creates it in the storage device, or the protection module automatically creates a fixed specific folder in the storage device, so that the computer device can pre-save the folder or file data that needs to be read. Therefore, the computer device can read data, change data, or copy files, and can also be set to read-only mode. When set for reading and writing of an empty folder, the protection module automatically creates a new folder in the storage device and makes it a specific folder. Therefore, when the computer device reads the root directory, it obtains the data of the "blank disk". The computer device can read and write only specific files or folders permitted by the user, or create a new empty folder to prevent the computer device from writing only new files and not reading existing files. The free space is the free space of the actual storage device.
[0126] Referring to Comparative Figure 8, it shows that a storage device not connected to the intermediate device or a storage device without an integrated protection module is directly connected to the computer device, and all files in the root directory of the storage device are first displayed. Next, after clicking and opening the "root directory / SAFEDIR.NEW / HEDIR.NEW" folder, the files THEFILE_1.txt and THEFILE_2.txt in the folder are displayed. Assuming that the technical solution provided in the embodiment of the present application is adopted, the "root directory / SAFEDIR.NEW / HEDIR.NEW" folder is set to a specific folder. After the storage device is connected to the computer device via the protection module, only two files, THEFILE_1.txt and THEFILE_2.txt, in the "root directory / SAFEDIR.NEW / HEDIR.NEW" folder can be displayed on the computer device, and its parent directory and other files cannot be displayed.
[0127] Accordingly, the method provided by this embodiment further After the computer device establishes communication with the storage device, when the computer device receives a request to read the root directory address of the storage device, based on the mapping relationship, it determines the address information of at least one specific file or folder having a mapping relationship with the root directory address, and reads the data corresponding to the address information.
[0128] For the sake of understanding, here, the process by which the above protection module establishes a specific folder mapping will be described.
[0129] 1. The protection module reads the information of the storage device in advance and obtains the first sector address of the root directory and a collection of sector addresses.
[0130] 2. When in the specific folder mode, analyze the sector address of the root directory, and according to the file system protocol, find the first sector address and the collection of sector addresses of the specific folder based on file features such as the file name and file path of the specific folder.
[0131] 3. When in the blank specific folder mode, create a new folder according to the rules such as the preset file path and file name in accordance with the file system protocol, and use it as the first sector address and the collection of sector addresses of the specific folder.
[0132] 4. Establish the mapping relationship between the sector address of the specific folder (or the collection of addresses of the memory data area) and the sector address of the root directory (or the collection of addresses of the memory data area). When the computer device requests to read the sector address data of the root directory, the address data corresponding to the mapped specific folder sector is returned. For example, in the FAT file system, the collection of sector addresses is the collection of all sector addresses corresponding to the cluster chain of a specific folder or the root directory. Specifically,
[0133] 4.1. Based on the mapping between sector addresses. For example, the first sector address of the root directory of the storage device is sector 17348. If the first sector address of a specific folder is sector 17396, when the computer device sends a command to read sector 17348, the protection module reads and returns the data of sector 17396 of the storage device. For example, the second sector address of the root directory of the storage device is sector 17349. If the second sector address of a specific folder is sector 17397, when the computer device sends a command to read sector 17349, the protection module reads and returns the data of sector 17397 of the storage device.
[0134] 4.2. Replacement Based on the File Allocation Table. The file allocation table is a collection of all specific records of the sector addresses where the content data of a specific file is located (the specific records are clusters or blocks divided by the file system). Generally, it has a chain structure (the position of the cluster is fixed, and the cluster number of the next cluster is recorded in the previous cluster). The computer device reads and writes file data based on the sector addresses recorded in the file allocation table.
[0135] For example, the addresses recorded in the root directory data of the storage device are the 3rd cluster (recording cluster 4), the 4th cluster (recording cluster 5), and the 5th cluster (recording the end mark). The addresses recorded in the data of a specific folder are the 6th cluster (recording cluster 7), the 7th cluster (recording cluster 8), and the 8th cluster (recording the end mark). When the computer device sends a command to read the data of a sector of the file allocation table, the protection module reads the data of the file allocation table of the storage device, replaces it with the data in the 3rd cluster (recording cluster 7), and returns it. For example, when the computer reads the 2nd cluster of the cluster chain table of the root directory data (the data of the 1st cluster can be mapped between sector addresses), it directly jumps to the cluster chain of the specific folder data (the 2nd cluster of the specific folder) and further reads the sector address of the specific folder data.
[0136] 4.3. Replacement based on the boot information of the file system. Usually, the boot information of the file system stores the address (such as the cluster number) of the content data of the first directory. When the computer device sends a command to read the boot information sector data of the file system, the protection module reads the boot information sector data of the storage device and replaces the first directory address with the 6th cluster (recording the 7th cluster) and returns it. Therefore, the computer uses the data starting from the 6th cluster (the starting cluster of specific folder data) as the root directory data.
[0137] The address information of the at least one specific file or folder includes the first sector address of the at least one specific file or folder, or the cluster or block information in the file allocation table where the at least one specific file or folder is recorded.
[0138] The above boot information sector address and file allocation table sector address of the file system are based on the file system and are obtained by analyzing the data of the storage device pre-read by the protection module.
[0139] In some embodiments, the target file includes an existing specific file or preset file in the storage device, or a file automatically generated before the computer device establishes a communication connection with the storage device.
[0140] In this embodiment, the existing feature file is a file that fixedly exists in the storage device, and the preset file may be a blank file, that is, any existing data in the storage device is not displayed in the preset file. The preset file may be a preset file containing unimportant data. The preset file can be automatically created before the storage device is connected to the computer device, or can be the original blank folder of the storage device, or can be a temporary folder generated by the target device.
[0141] In one possible embodiment, when the preset file is a blank file, since there is no readable file data, the corresponding file data cannot be read. When a write command is received, data is written to the blank file (i.e., the corresponding sector address) according to the write command, and the data that has been normally written to the blank file by the computer device in this data interaction can be identified and read by the computer device. In this embodiment, by creating a mapping between the blank file and the target device, the computer device cannot read the file data in the original data area in the storage device, and by performing reading and writing on the blank file, the read and write permissions of the computer device are restricted, and the data security of the storage device is protected.
[0142] Optionally, when writing data to the preset file, there may be cases where the written data is displayed to the computer device and cases where it is not.
[0143] As described above, when set for specific file reading and writing, the user first creates a specific folder in the storage device, or the protection module automatically creates a fixed specific folder in the storage device. Here, the case where the user creates it first will not be described. Here, the method by which the protection module automatically creates a fixed specific folder in the storage device will be described. That is, the protection module, which is the execution subject of the method provided in the embodiments of the present application, also has the function of automatically creating a specific folder. Specifically, the method provided by this embodiment further Step 21, when the current protection mode is the specific file mode, outputting prompt information on whether to set up a blank file or folder; Step 22, in response to the user's confirmation command for the prompt information on setting up a blank file or folder, creating one file or folder in the storage device as the specific file or folder corresponding to the specific file mode; Step 23 includes: in response to a negative command of the user for the prompt information of installing a blank file or folder, acquiring at least one file or folder specified by the user, and using the at least one file or folder specified by the user as a specific file or folder corresponding to the specific file mode.
[0144] Taking one specific scenario as an example, after the specific file mode is selected, for example, the carrier of the protection module, which is a device equipped with an interaction module such as a storage device, an intermediate device, a computer device, a reliable device, etc., outputs prompt information on whether to install a blank file or folder. If the user gives a confirmation instruction for the prompt information of installing a blank file or folder, one file or folder is created in the storage device as the specific file or folder corresponding to the specific file mode. If the user triggers a negative command for the prompt information of installing a blank file or folder, the user is waited for to specify at least one file or folder in the storage area as the specific file or folder corresponding to the specific file mode.
[0145] That is, after a specific file mode is selected, the protection module provides the user with an opportunity to choose whether to create a blank file as a specific file or folder, or to specify a file or folder as a specific file or folder, and the protection module determines a specific file or folder corresponding to the specific file mode in the storage area according to the user's command. Of course, the protection module can also randomly determine an existing file or folder as a specific file or folder corresponding to the specific file mode. For example, based on a preset selection policy or algorithm, the protection module selects at least one file or folder conforming to the policy or algorithm from the storage area as a specific file or folder corresponding to the specific file mode. Also, based on a preset policy (such as a file path or file name), specific files or folders can be automatically created without human intervention. Here, in this embodiment, the specific implementation of the selection policy or algorithm is not limited.
[0146] Figures 9b and 9c show schematic diagrams corresponding to specific folders in a specific file mode. Figures 9a and 9d show the situation as seen in global permissions (i.e., without specific folder mapping and with the specific folder mode not enabled) to produce a comparison effect and reflect the differences in the technical solution of this application. Referring to Figure 9a, in the case of global permissions (i.e., without specific folder mapping and with the specific folder mode not enabled), there is a SAFEDIR.NEW folder (a specific folder) in the root directory, and it can be seen that this folder contains a NEWDIR.NEW (the root directory of an empty folder) and a THEDIR.EW folder (a fixed specific folder). This folder may be created by the user or automatically generated by the protection module. There are two files in the THEDIR.NEW folder. As shown in Figure 9b, in the specific file mode, after being mapped to a fixed specific folder and a storage device with a protection module is connected to the computer device or the storage device is connected to the computer device via an intermediate device, only two files (THEDIR.NEW) can be displayed in the root directory of the computer device, and reading, writing, or read-write operations are possible, but the SAFEDIR.NEW folder and the NEWDIR.NEW root directory within the folder cannot be displayed, nor can other files including other files under the root directory of the USB flash drive be displayed. Figure 9c shows an example of continuously creating a new file THEFILE_3_NEW.txt in the specific file mode (mapped to a fixed specific file). Figure 9d shows the situation of the newly created file THEFILE_3_NEW.txt in the folder THEDIR.NEW in global permissions (i.e., without specific folder mapping and with the specific folder mode not enabled).
[0147] Figures 10a, 10b, 10c, and 10d show examples where a blank file corresponds to a specific file in a specific file mode. As shown in the figures, when the specific file in the specific file mode is a blank folder, as shown in Figure 10a, the USB flash drive displayed on the interface of the computer device is empty. Of course, there is data on the USB flash drive, but the specific folder is a blank folder and is mapped to it, so what the user of the computer device sees is that the USB flash drive is empty and there is no data. Figure 10b shows the state of the NEWFILE_1 file automatically created or created by the user when the current protection mode is a blank folder in the specific file mode. Figure 10b shows the situation corresponding to the first operation of the USB flash drive, and the user can see the newly created blank file. Figure 10c shows that when the current protection mode is a blank folder in the specific file mode, the USB flash drive operates for the second time (that is, the USB flash drive with a protection module or the USB flash drive connected to an intermediate device is reconnected to the computer device), and the file NEWFILE_1 in Figure 10b above cannot be seen. Figure 10d shows the state of the file NEWFILE_2 automatically created or created by the user when the current protection mode is a blank folder in the specific file mode. Since it is newly created this time, the user can see the file NEWFILE_2.
[0148] Figures 11a and 11b show viewing file NEWFILE_1 and file NEWFILE_2 with global permissions, and the directories corresponding to these two files. Referring to the example shown in Figure 11a, sub-directory 1.NEW is automatically created in directory NEWDIR.NEW of the USB flash drive, and there is file NEWFILE_1 created in the first operation of the "blank folder mode". Referring to the example shown in Figure 11b, sub-directory 2.NEW is automatically created in directory NEWDIR.NEW of the USB flash drive, and there is file NEWFILE_2 created in the second operation of the "blank folder mode".
[0149] Also, note that in the specific folder mode, only the folder is mapped to the root directory and does not affect the original storage area, which is different from the logical split disk mode described below. In the logical split disk mode, the storage area (such as free space) of the storage device is split in the split disk.
[0150] In some embodiments, when the protection mode is the location-limited read / write mode, step S601 includes: verifying a target sector address corresponding to the data interaction command based on a preset sector address interval according to the data interaction command; performing a read / write operation on the target sector address of the storage device when the target sector address is within the preset sector address interval, where the target sector address is the sector address when the storage device performs a read / write operation based on the data interaction command.
[0151] In the sector-restricted read / write mode, the user of the storage device can protect data in specific sector intervals of the storage device from being read, modified, or written (based on sector intervals). Preventing the user of the computer device from being able to read specific sector data can protect the computer device from malicious data.
[0152] Specific embodiments are as follows.
[0153] When the computer device sends an interaction command for reading sector data or writing sector data to the protection module, the protection module determines whether the sector address operated by the interaction command conforms to the rules of a specific sector interval with a preset, and if it conforms, it executes; if it does not conform, it does not execute.
[0154] Also, when it does not conform, it is necessary to respond to the failure state of writing or reading. The computer device recognizes that there is a problem with the storage device and repeatedly executes invalid operations. Therefore, the protection module returns a response of successful execution, responds with blank data, and responds with other non-existent data, making the computer recognize that the execution was successful. In fact, since the protection module does not actually operate on the data of the storage device, it prevents the computer device from recognizing that the operation has failed and continuously trying the operation.
[0155] Setting the rules for the above specific sector intervals. One possible technical solution is to manually preset specific sector intervals, such as setting the sector interval from 0 to 9999 as read-only, the sector interval from 50000 to 69999 as write-only, and the sector interval from 80000 to 99999 as unreadable and unwritable. Another possible technical solution is to automatically set specific sector intervals by the protection module or an external device. For example, when further protecting the read / write permissions of specific file data (such as in the preparation stage), 1. Establish the protection sector address intervals for the boot area of the memory device and the boot area of the file system. The protection module reads the memory device in advance, searches for the interval between the boot area of the memory device and the boot sector of the file system, establishes a collection of corresponding sector intervals, and sets the read-only permission for the said sector intervals. This prevents the computer from damaging its data due to malicious writing and makes it impossible for file data to be read normally. 2. Establish the protection sector address intervals for specific folders and files. The protection module reads the memory device in advance, determines using the file data characteristics or file attribute (such as file type) characteristics of a specific file or folder, searches for the sector address data corresponding to the specific file or folder according to the rules of the file system, and establishes a collection of corresponding specific file data sector interval data. Also, set the read and write permissions for the said collection of sectors. Sector addresses in the data area of the file system (excluding the boot area of the file system) are not allowed to have read and write permissions. Sector scanning (from sector 0 to the end sector) is used to prevent non-specific folder data from being read. III. Set the protection range for read and write access to unused sector addresses. The protection module reads the storage device in advance and analyzes the unallocated sector address intervals according to the rules of the file system. For example, in the FAT file system (including FAT32, exFAT, etc.), the unallocated cluster numbers in the file allocation table can be read to further convert the collection of unallocated sector address intervals. Also, read and write permissions can be set, and in a specific folder mode, the computer can be made to create files and write data. It can also be set to write-only permission, preventing the reading of old data (such as deleted file data) in the unallocated sector addresses. Here, the principle of file deletion is roughly as follows: The computer device usually only marks the deleted file as deleted and marks the storage area of the data as unallocated (such as emptying the cluster chain), but the data in the storage area still exists, and the data of the deleted file can be read without being overwritten.
[0156] In this embodiment, the position-limited read and write mode includes a read-only mode, a write-only mode, and a read-write mode for files in the preset sector address intervals. The preset sector address intervals include all sector addresses permitted for reading and writing by the computer device and can be set in advance.
[0157] Optionally, the protection module identifies the target sector address to be read and written by the data interaction instruction, and executes the read and write operation when the target sector address is within the preset sector address interval, so as to control the sector address where the computer device can read and write data and protect the data security of the storage device. For example, when the target sector address of the file to be read and written by the data interaction instruction is sectors 0 to 499 of the storage device, and the current position-limited read and write mode permits reading and writing only to sectors 500 to 999 of the storage device, the target sector address is not within the preset sector address interval; when the current position-limited read and write mode permits reading and writing to sectors 0 to 499 of the storage device, the target sector address is within the preset sector address interval.
[0158] Note that in this embodiment, through the position-limited read and write mode, the permitted read and write range of the storage device can be limited to the preset sector address interval, meeting the specific scenarios required by the position-limited read and write.
[0159] In some embodiments, when the protection mode is the file-limited read and write mode, step S601 includes verifying the target file feature corresponding to the data interaction instruction based on the preset file feature according to the data interaction instruction; and when the target file feature matches the preset file feature, executing a read and write operation on the target file in the storage device, where the target file feature is the file feature corresponding when the storage device executes the read and write operation based on the data interaction instruction.
[0160] In the file restricted read / write mode, the computer device is restricted from reading and writing files that conform to preset rules to the storage device. The preset rules of the files include file names, file types (such as file name naming rules, file extensions, characteristic values at specific positions corresponding to the content of the file, etc.).
[0161] For the user of the storage device, it can be protected so that file data of a specific file type in the storage device cannot be read (for example, only read DOC documents or prohibit reading PDF files), cannot be modified (for example, only modify DOC documents or prohibit reading PDF files), cannot be deleted (for example, prohibit deleting DOC documents or only delete PDF files), and cannot be created (for example, prohibit writing files of the EXE executable file type or only create DOC documents). For the user of the computer device, it can protect the computer device from attacks by malicious programs. For example, in daily work scenarios, it is only necessary to copy PDF and DOC files, only permit reading or writing of PDF and DOC format files in the storage device, and prohibit reading of other file types (such as EXE executable files), thus preventing highly sophisticated Trojan virus files from attacking the computer device by avoiding the restrictions of security software.
[0162] The specific implementation method is as follows. 1. When restricting the reading (including copying) or modification of file content data by the computer device: 1.1. Search for files that require control. The protection module searches in the storage device for files whose access is prohibited or permitted, and the sector address interval corresponding to the file content data (such as the first sector, etc.). 1.2. Determine the read / write data interaction command. If the computer's interaction command is to read or write the sector address of the control file, make a determination based on the readable or writable permission. 1.3. Respond according to the set permissions. If there is a read or write permission for the sector address, the data of the corresponding sector of the storage device is read or written and returned. If the sector address is prohibited from being read or written, return a response in an error state, a response indicating successful execution, a response with blank data, or a response with other non-existent data, so that the computer is made to recognize that the execution was successful, and the protection module does not actually operate on the data of the storage device, preventing the computer device from recognizing that the operation failed and continuously attempting the operation.
[0163] That is, the above process can be summarized as follows: The data interaction command meets the permission requirements corresponding to the current protection mode. When the data interaction command is to read or modify the file content data, determine the sector address, read or write the data of the corresponding sector of the storage device, and return. When the data interaction command does not meet the permission requirements corresponding to the current protection mode, return a response in an error state, a response indicating successful execution, a response with blank data, or a response with preset data as feedback data.
[0164] 2. When restricting the creation of a new file, deletion of a file, or modification of file attributes by a computer device: 2.1. Search for a collection of data sector addresses of folders (e.g., during the preparation stage). If the storage device is in the protection module, first search for the root directory, read the sub - directory and file information under the root directory, and continue to read the sub - directory and file information based on the sub - directory until finding the folders that require control (all folders including at least one specific file, a specific collection of folders, or the root directory), and the sector address interval corresponding to the folder data (e.g., the first sector, etc.). 2.2. Determine the read - write data interaction command. If the sector address written by the computer device is the folder data address, compare and read the data of the corresponding sector address of the storage device, and determine the operation of the computer device (file creation, file attribute change, file deletion) and the file type (file name rule, file extension, specific data of the file, etc.). For example, If the data written by the computer device are three data, A.txt, B.txt, and C.txt, which contain file information, but the existing data at the corresponding sector address of the storage device are A.tx and tB.txt, it is determined that the computer device attempts to create the file C.txt.
[0165] If the data written by the computer device are A.txt and B.txt (marked as deleted) that contain file information, or the written data is only A.txt that contains file information, it is determined that the computer device attempts to delete the file B.txt.
[0166] If the data written by the computer device are A.txt and C.txt (other attributes of the file remain unchanged) that contain file information, or the written data are A.txt, B.txt (deleted state), and C.txt (other file attributes are the same as B.txt), it is determined that the computer device attempts to change the file name of file B.txt to C.txt.
[0167] The data written by the computer device is A.txt and B.txt which contain file information (the data such as the file creation time does not match the existing data in the storage device), and the computer device is determined to attempt to change the file attribute information.
[0168] Specifically, Tables 3 to 6 show examples of file creation, file deletion, file name change, and file attribute change. For example, the protection module first pre-records a collection of sector addresses (at least one sector address) of the folder showdir (which may include the root directory, etc., and may be at least one or a plurality or all of the folders). When the data interaction command sent from the computer matches the collection of sector addresses of the showdir folder, the protection module reads the corresponding sector data, performs comparison and determination before executing the write operation, and executes the next operation according to the preset of the protection mode. JPEG2025517181000004.jpg241170JPEG2025517181000005.jpg255168JPEG2025517181000006.jpg102170JPEG2025517181000007.jpg231170JPEG2025517181000008.jpg231170
[0169] That is, the above process can be summarized as follows: When the data interaction command meets the permission requirements corresponding to the current protection mode and the data interaction command is for file creation, file deletion, or file change, Determine the sector address, When the data interaction command includes information on a plurality of files and the sector address corresponding to the storage device includes some of the plurality of files, the computer device determines that it attempts to create at least one file at the sector address, where at least one file to be created is the remaining files other than the existing partial files among the plurality of files. When the data interaction command includes information on a plurality of files and at least some of the plurality of files are marked for deletion, search for at least one temporary deletion file related to the part of the plurality of files marked for deletion among the sector addresses corresponding to the storage device, and the computer device determines that it attempts to delete the at least one temporary deletion file. When the data interaction command includes a first file collection, the sector address corresponding to the storage device includes a second file collection, and the first file collection is a sub-collection of the second file collection, the computer device determines that it attempts to delete at least one file within the second file collection that does not belong to the first file collection. When the attribute information other than the file name of the first file included in the data interaction command is the same as the attribute information other than the file name of the second file within the sector address corresponding to the storage device, the computer device determines that it attempts to change the file name of the second file within the sector address to the file name of the first file. When the file name of the first file included in the data interaction command is the same as the file name of the second file within the sector address corresponding to the storage device, and the attribute information other than the file name of the first file is different from the attribute information other than the file name of the second file, the computer device determines that it attempts to change the attribute information other than the file name of the second file to the attribute information other than the file name of the first file.
[0170] What needs to be added here is that the attributes to be changed may be attributes such as file size and time, and there may also be a case where the file data needs to be changed. That is, specifically, the step of "when the file name of the first file included in the data interaction command is the same as the file name of the second file in the sector address corresponding to the storage device, and the attribute information other than the file name of the first file is different from the attribute information other than the file name of the second file, determining that the computer device attempts to change the attribute information other than the file name of the second file to the attribute information other than the file name of the first file" is as follows: When the file name of the first file included in the data interaction command is the same as the file name of the second file in the sector address corresponding to the storage device, and the attribute information other than the file name of the first file is different from the attribute information other than the file name of the second file, determine that the computer device attempts to change the attribute information other than the file name of the second file to the attribute information other than the file name of the first file, When the attribute information that the computer device attempts to change includes file size and time, determine that the computer device changes the file data of the second file.
[0171] 3. Respond according to the preset permissions. That is, the method provided by this embodiment further includes performing a permission determination on the operation that the computer device attempts to execute based on the current protection mode, or triggering another protection mode.
[0172] For example, when it is determined that the computer device attempts to create at least one file at the sector address, the protection module determines whether to permit the creation or trigger another protection mode based on the current protection mode.
[0173] When the computer device determines to delete the at least one temporarily deleted file, or when the computer device determines to delete at least one file in the second file collection that does not belong to the first file collection, the protection module determines whether to permit the deletion based on the current protection mode, or triggers another protection mode.
[0174] When the computer device determines to change the file name of the second file at the sector address to the file name of the first file, the protection module determines whether to permit the change of the file name or trigger another protection mode based on the current protection mode.
[0175] When the computer device determines to change the attribute information other than the file name of the second file to the attribute information other than the file name of the first file, and / or determine to change the file data of the second file, the protection module determines whether to permit the change of the attribute information and / or the change of the file data or trigger another protection mode based on the current protection mode.
[0176] Here, the other triggered protection mode may be at least one protection mode combined with the current protection mode, such as an encrypted writing mode, a manual confirmation mode, etc.
[0177] When there are restrictions on the file type to be written, such as file creation, file attribute modification, file deletion, etc.: First, it is possible to return a response in an error state, a response for successful execution, a response with blank data, or a response with other non-existent data (for example, in the case of further read verification by the computer, the protection module returns the written data), so that the computer recognizes that the execution was successful. However, in reality, since the protection module does not actually operate on the data in the storage device, it can prevent the computer device from recognizing that the operation has failed and continuously attempting the operation. Second, when there is no permission to create a file, it is usually written to the folder data. However, since the written file content data is non-existent data, it makes the computer device recognize that the execution was successful, and the storage device also actually creates the file. However, since the content data of the file is non-existent, it can avoid the execution of malicious code and prevent the computer device from recognizing that the operation has failed and continuously attempting the operation. The response can also include the determination of at least one protection mode, such as the manual confirmation mode, the encryption and decryption mode, the file anomaly mode, etc.
[0178] Here, when the computer device restricts reading the file attribute data in the folder, the data interaction command is judged according to the file reading rules. When the file in the storage device does not conform to the file reading rules, it responds to the computer device with non-existent data and makes the file invisible on the computer device. For example, the first is to replace the file attribute with the deleted state and return it to the computer device, so that the computer device recognizes that the file has been deleted and is no longer displayed. The second is to replace the first sector address (or the first cluster or the first block in the file system) in the file attribute with 0x00 and replace the file size with 0 bytes, so that the computer device cannot directly read the data of the file. The third is to replace the corresponding data of the file with non-existent data such as blank data, so that the computer device cannot read the actual data, and it can be recognized that the operation of the computer device has failed, and the computer device can be prevented from constantly trying the operation. The computer device is made unable to read the correct attributes of the file, the file is made not to be displayed on the computer, and further operations such as reading the data of the content of the file are made impossible to execute.
[0179] In this embodiment, the file restricted read / write mode includes a read-only mode, a write-only mode, and a read / write mode for files with preset file characteristics. The preset file characteristics refer to preset characteristic parameters of a file that enable a computer device to perform reading and writing, including file name, file extension, file type, file size, hash value corresponding to preset sector data in the file content data, and preset byte values corresponding to specific positions in the preset sector data within the file (similar to keyword comparison hits, for example, determining whether the 10th character on the 5th page is 0x88, which is equivalent to determining whether the 10th byte in the 5th sector is 0x88), etc., but are not limited thereto. Optionally, blacklist file characteristics or whitelist characteristics can be preset to prohibit or permit reading and writing of corresponding files. For example, when the file read / write mode is a read-only mode for PDF file types, only PDF files in the storage device can be read during the execution of the read operation, and other file types cannot be read.
[0180] Exemplarily, when the storage device establishes communication with the computer device, the target device automatically crawls the attributes (such as file names and start sector addresses) of all files that are permitted to be accessed by the computer device according to the preset rules of the corresponding file system, and establishes a correspondence between the unique identifier of the file and the start sector address. For the read operation: If the sector address read by the computer device is the start address of a certain file, it is recognized that an attempt is made to read and write the file, and it is queried whether the preset file features exist in the file. For the read operation: When the computer device writes a certain file, first, the attributes of the file (such as file name, start sector address, etc.) are updated and written to the corresponding folder data, compared with the written folder data to determine the attributes of the file to be written, and then it is determined whether the file has preset file features.
[0181] Note that in this embodiment, in order to meet the user's scenario requirement that the computer device can only read files with preset file features in the file restricted read / write mode, attention should be paid to improving the data security of the storage device.
[0182] In some embodiments, the preset file feature includes a first hash value corresponding to preset sector data in the file. Based on the preset file feature, verifying the target file feature corresponding to the data interaction command includes: calculating a second hash value of the preset sector data in the target file; when the second hash value matches the first hash value, determining that the target file feature conforms to the preset file feature; when the second hash value does not match the first hash value, determining that the target file feature does not conform to the feature of the preset file.
[0183] In this embodiment, the preset sector data is data within a preselected sector. For example, if the preset sector is the first sector, the computer device calculates the second hash value of the data in the first sector part where the target file to be read and written is located. When the second hash value matches the first hash value, it is determined that the target file feature conforms to the preset file feature. Exemplarily, the first hash value of the preset sector data B in file A is 533c3057ec5801aa39e9257066890928. When it is necessary to read and write the preset sector data B in file A, calculate the second hash value of the sector data in the read and written file A, and determine whether the second hash value is 533c3057ec5801aa39e9257066890928. If so, it means that the read and written data is the preset sector data B of file A. Otherwise, it means that the read and written data is not the preset sector data B of file A and does not conform to the preset file characteristics. In this embodiment, by verifying the file feature through the comparison of hash values, more accurate read control of a certain file data can be performed.
[0184] In some embodiments, after verifying the target file feature corresponding to the data interaction instruction, if the target file feature does not conform to the preset file feature, it further includes hiding the target file.
[0185] In this embodiment, hiding a file means making it impossible for a computer device to identify the file. The method of hiding a target file is to change the actual sector address of the target file (including the start sector address, cluster (block) chain data, etc.) and the file size in the process of returning data packets, so that the computer device identifies it as a null file with a file size of 0 bytes and cannot directly read the content data of the target file. Also, in the process of returning data packets, it is also possible to replace the content data of the target file with non-existent data such as blank data. Further, the target file can be changed to a deleted state so that the computer device identifies it as a deleted file without displaying the file. It can be understood that the replacement or modification in this embodiment is merely a camouflage and is only a replacement or modification of the data displayed on the computer device, not an actual modification of the data.
[0186] After the computer device establishes communication with the storage device, since the computer device needs to read the file data of the storage device for display on the computer device, in this embodiment, the file is hidden by identifying the preset file characteristics of the file before displaying it on the computer device. This is compatible with all protection modes of this application, that is, the file can be hidden in all protection modes, and all protection modes can be set in the storage device after the file is hidden. It should be noted that only the unhidden files in the storage device can be read and written, so as to protect the security of the private data of the storage device.
[0187] In some embodiments, when the protection mode is the encrypted writing mode, step S601 is as follows: responding to the data interaction command, encrypting the data to be written carried by the data interaction command to obtain first target data; writing the first target data to the target file in the storage device.
[0188] In this embodiment, the protection module stores a key for data encryption. In a scenario where the computer device needs to write data to the storage device, the computer device sends a write command carrying the data to be written, encrypts the data to be written via the protection module, obtains second target data, and writes the second target data to the storage device.
[0189] Optionally, when the target device is an intermediate device, the intermediate device encrypts the data to be written via the protection module according to the write command to obtain second target data, transfers the second target data and the write command to the storage device, and the storage device writes the second target data according to the write command. When the target device is a storage device equipped with a protection module, the protection module verifies the identity of the user before the data is written (it should be understood that verification may not be necessary in other embodiments). For example, the user inputs the unlock password of the protection module so that the protection module can call its pre-stored encryption key during the write operation. When the storage device receives the write command, the storage device encrypts the data written by the protection module according to the write command to obtain second target data, and performs a write operation on the second target data.
[0190] It should be noted that this embodiment encrypts the data written through the protection module to independently protect the data security of the storage device, and stores the encryption key in the protection module to realize the separate storage of the key and the data. Even if the storage device is lost, the data is difficult to decrypt, further improving the data security.
[0191] In some embodiments, when the protection mode is the decryption read mode, performing a read and write operation on the storage device according to the data interaction command is In response to the data interaction instruction, feeding back second target data to the computer device, where the second target data is the data after decrypting the data returned by the storage device according to the data interaction instruction.
[0192] In this embodiment, the protection module stores a key for data decryption. In a scenario where the computer device needs to read data from the storage device, the computer device sends a read instruction, obtains the target data in the storage device according to the read instruction, and decrypts the target data through the protection module to obtain third target data.
[0193] It can be seen that the technical solution provided in the embodiment of the present application can also implement the encryption or decryption of specific sector address data of the storage device through encrypted writing or decrypted reading.
[0194] The specific implementation method is as follows. 1. To encrypt or decrypt specific sector address data, similar to the flow of the sector-restricted read / write mode, a collection of specific sector intervals that need to be encrypted or decrypted is set in advance (manually or automatically). 2. When the read or write operation of the data interaction instruction sent from the computer complies with specific encryption and decryption sector intervals, the protection module encrypts or decrypts: 1) When reading data from a specific encryption sector interval, the protection module reads the data of the storage device and then decrypts it to respond to the computer. 2) When writing data to a specific encryption sector interval, the protection module encrypts the data written by the computer and writes it to the storage device.
[0195] Specific application scenarios: 1. Manually set the encrypted sector interval. For example, set the sector interval from 0 to 9999 as the encrypted sector interval. When the said sector interval is read, the protection module makes a decryption response. When written to the said sector, the protection module performs encrypted writing. 2. Automatic encryption and decryption during the read and write processes of the computer device. For example, pre-set the file types that need to be encrypted or decrypted, and the protection module reads in advance the first sector address and the collection of sector addresses of specific file data that need to be encrypted or decrypted. 3. Pre-automatic encryption of the protection module, and automatic encryption and decryption during the read and write processes of the computer. For example, the boot sector is automatically encrypted by the protection module. Similar to the flow of the sector-restricted read and write mode, the protection module reads in advance the collection of sector addresses of the boot sector such as the MBR and GPT of the storage device, the boot sector of the file system, the protocol or rules between the boot sector of the storage device and the file system, reads the data and encrypts it, and writes the encrypted data according to the original sector address, so that the storage device stores the encrypted boot sector and file system-related data. 4. The protection module combines encryption and decryption in the process of reading and writing specific files. For example, encrypt and decrypt the read and write operations of files in a specified specific folder. For example, when writing the file test.txt to the folder safedir, perform automatic encryption and automatically decrypt it when reading. Other folders are not encrypted or decrypted. Encrypt and decrypt a specified specific file type for reading and writing. For example, encrypt and decrypt the txt file type, automatically encrypt it when writing the test.txt file, and automatically decrypt it when reading.
[0196] The advantages are that the key data for encryption or decryption is stored in the protection module, and the encryption or decryption operations are also executed by the protection module. First, the protection module and the storage device can be physically separated and stored. When the storage device is lost, malicious reverse engineering cannot obtain the key data (in the prior art, for example, in a USB flash drive with an encryption function, the key and the storage device are designed to be physically integrated, and the key data can be easily extracted by reverse engineering). Second, the key is not encrypted or decrypted by the computer, and the computer cannot obtain the key data, so it cannot prevent the computer from being stolen after being maliciously controlled (in the prior art, the key is stored in the computer, and the computer needs to execute the encryption or decryption operation of the USB flash drive and install the encryption or decryption software of the USB flash drive on the computer). Third, the specific encryption sector address interval is only known to the protection module. When the computer directly reads through the storage device, it is difficult to analyze, so it is difficult to find the existence of the encrypted data. Fourth, the computer device does not need to participate in the encryption and decryption processes, and the computer cannot recognize or control the encryption and decryption processes.
[0197] Optionally, if the target device is an intermediate device, the computer device sends a read command, the intermediate device transfers the read command to the storage device, the storage device acquires target data according to the read command and transfers it to the intermediate device, and the protection module of the intermediate device decrypts the target data to obtain third target data and transfers the third target data to the computer device. If the target device is a storage device equipped with a protection module, the protection module verifies the identity of the user before the data is read (it should be understood that verification may not be necessary in other embodiments). For example, the user inputs the unlock password of the protection module so that the protection module can call its pre-stored decryption key during the read operation. After the computer device sends a read command, the storage device acquires the target data according to the read command, decrypts the target data by the protection module to obtain third target data, and returns the third target data to the computer device.
[0198] It should be noted that in this embodiment, the data acquired by the storage device through the protection module is decrypted to independently protect the data security of the storage device, and by storing the decryption key in the protection module, it is realized to store the key and data separately. Even if the storage device is lost, the data is difficult to decrypt, and the data security is further improved.
[0199] Naturally, the decryption read mode and the encryption write mode are compatible with other protection modes. For example, currently the protection mode may be the specific file read / write mode, the decryption read mode, and the encryption write mode at the same time.
[0200] In some embodiments, when the protection mode is the manual confirmation mode, step S601 is prompting the user to confirm whether to execute the data interaction command according to the data interaction command; When receiving an execution confirmation command for the data interaction command, continue to perform read and write operations on the target file in the storage device.
[0201] Based on the preset rules, manually check the data interaction commands sent from the computer, such as reading and writing specific sector addresses. If confirmed, continue to execute the data interaction commands in the storage device; if not confirmed, do not execute.
[0202] The specific implementation method is as follows. Based on the preset rules of the data interaction command, the protection module needs to determine whether it is necessary to manually check the interaction instruction. The preset rules of the data interaction command include, but are not limited to, the following. 1. Manual confirmation during read and write operations based on sector addresses. For example, one is to establish a collection of sectors in the boot area of the storage device and the boot area of the file system in the same flow as the sector limit read and write mode, or to establish a collection of sector intervals of specific file data. These are the sector intervals that need to be manually checked. 2. Manual confirmation during operations based on file attributes. For example, similar to the process of file restricted read / write mode, first, establish the rules for creating, deleting, modifying file content data, and reading / writing file content data for specific file types (according to file extensions, file content data characteristics, etc.). Second, establish the rules for creating files, modifying file attributes, and deleting files for non-specific files. For example, if it is set that confirmation is required for reading and writing an exe executable program, when the computer reads and writes a file named abc.exe to the storage device, the intermediate device or protection module monitors this operation and does not respond immediately, but requests manual confirmation of this operation in a way such as lighting up or displaying on the screen. After manual confirmation, the intermediate device or protection module responds and continues with the file reading and writing. 3. Manual confirmation during operations based on device access. For example, the protection module detects that the computer device enumerates the storage device and starts to connect to the storage device (reads device descriptors, configuration descriptors, interface descriptors, endpoint descriptors, string descriptors, device capacity information, etc.), and manually confirms the connection. The protection module detects that the computer device sends a specific command (descriptor request with a tag, password, key, etc.), and after confirming compliance with the agreement, manually confirms the connection.
[0203] The advantages of this are that the user of the storage device can recognize the transfer process of writing or reading data or specific files, and furthermore has fine-grained control over sector data or specific file transfers in the storage device (which could not be achieved in the prior art and could only be controlled by read-only), preventing the computer device from performing operations that the user is unaware of, such as maliciously formatting the storage device, stealing and copying confidential files, maliciously modifying confidential files, writing malicious program files, etc. At the same time, it clearly informs the user of the computer device about the content of file data transmission, avoiding the unreliability of computer or computer control software and anti-virus software without the need for computer software control or anti-virus software.
[0204] In this embodiment, the manual confirmation mode is a mode that requires the user to participate in the confirmation in the data interaction process. That is, for the data interaction command sent from the computer device, it is necessary to manually confirm in the intermediate device or storage device equipped with a protection module. For example, in the case of an exe executable program, when the computer device needs to read and write the abc.exe file in the storage device, when the protection module monitors the read and write operation, it prompts the user to confirm the read and write operation in a way such as lighting up or displaying on the screen. After manual confirmation, the corresponding read and write operation is executed. Naturally, the manual confirmation mode is compatible with other protection modes.
[0205] Exemplarily, taking the intermediate device as an example, when the computer device needs to write data to the abc.exe file in the storage device, as shown in the schematic diagram of the intermediate device shown in FIG. 12, the intermediate device displays the corresponding operation information, indicating that when the user clicks the confirmation option, the confirmation of the execution command is triggered, and the computer device can write data to the abc.exe file in the storage device, and when the cancel option is clicked, the operation is interrupted.
[0206] In addition, in the present embodiment, since the manual confirmation mode can monitor unauthorized behavior in some scenarios, it is possible to avoid data leakage and security risks caused by the computer device illegally reading and writing the storage device without the user's knowledge, thereby improving the security of the storage device and the computer device.
[0207] That is, when the current protection mode is the manual confirmation mode, the above-mentioned "the data source targeted by the data interaction command is one of at least one data source specified in the current protection mode, and when the operation type for the data in the data source of the data interaction command matches the operation type specified in the current protection mode, the step of responding to the data interaction command" is specifically, the data source targeted by the data interaction command is at least one of the data sources specified in the manual confirmation mode, and when the operation type of the data interaction command for the data source is the read / write type, display the relevant information of the pre-written data or the read data, and according to the user triggering a confirmation operation on the relevant information, write the data to the storage device or read it from the storage device based on the data interaction command.
[0208] The read-only mode described in this specification includes, but is not limited to, the full disk read-only mode, the partial disk read-only mode, etc. In the next embodiment, the full disk read-only mode is taken as an example. That is, in some embodiments, when the protection mode is the full disk read-only mode, the step S601 is, including feeding back third target data to the computer device in response to the data interaction command, where the first target data is the data returned by the storage device in response to the read command.
[0209] In this embodiment, the full disk read-only mode is a mode that enables a computer device to read all file data in a storage device. When the computer device attempts to perform data interaction with the storage device, it sends a data interaction command. However, in the full disk read-only mode, only read commands meet the permission requirements, and the target device responds only to read commands and feeds back first target data, which is the data read from the storage device, to the computer device.
[0210] Exemplarily, the target device identifies the command type of the data interaction command, verifies it according to read / write permissions. In the full disk read-only mode, when the data interaction command is a read command, the target device acquires the first target data in the storage device according to the read command and sends the first target data to the computer device.
[0211] In the read-only mode, when the data interaction command is a read command, the target device retrieves the first target data in the storage device according to the read command and sends the first target data to the computer device. When the data interaction command is not a read command, such as a write command (such as SCSI command 2A representing writing) or other types of commands, the data interaction command is not transferred to the target device. Optionally, when the data interaction command is not a read command, the protection module does not transfer the data interaction command, but sends the executed feedback information to the computer to implement the restriction on the read / write permissions of the computer.
[0212] In this embodiment, by controlling the data interaction between the storage device and the computer device through the full disk read-only mode and avoiding the computer device from modifying or deleting the data of the storage device, the data security of the storage device is protected.
[0213] In some embodiments, based on the embodiment shown in FIG. 1, FIG. 12 shows a flowchart of a data security protection method provided by the fourth embodiment. The same steps as in FIG. 1 are not repeated. As shown in FIG. 12, for the execution process of the read / write operation, the method further includes step S701 of performing anomaly verification on the read / write operation based on preset read / write rules; and step S702 of determining that the read / write operation is abnormal if the read / write operation does not comply with the preset read / write rules.
[0214] Automatically verify the data interaction commands (such as reading and writing sector addresses) sent from the computer based on the preset read / write rules. If the rules are not met, do not execute or enter the manual confirmation mode for judgment.
[0215] The specific implementation method mainly involves establishing rules, and the rules mainly include, but are not limited to, the following. 1. Rules based on the normal enumeration of the computer and the reading and writing of the file system. For example, the read / write rules of the computer are to first read the 0th sector address (analyze the boot sector data and read the boot sector address of the file system) -> read the boot sector address of the file system (analyze the file allocation table of the file system and the first directory sector address) -> read the sector address data of the file allocation table -> read the first directory sector address data. The above rules are regular and jump-style, starting from the 0th sector address, non-continuous, and generally jumping. When read maliciously, it is read continuously from one sector to the address of a specific sector area. If there is no normal reading and writing of the file system rules by the computer, it is regarded as abnormal. 2. Context rules based on normal reading and writing of files by a computer. For example, when a computer reads the content data of a file, it first reads the record of the folder data where the file is located (obtains the start sector address of the file (or what is called the first cluster, the first block, etc.)), and when writing file data, it first writes the record of the folder data where the file is located (records the first sector address of the file (or what is called the first cluster, the first block, etc.)). If there is no such context operation, it is regarded as abnormal. 3. Rules based on data management of the file system. For example, the file system usually divides a plurality of sector addresses into one-sector intervals for management (the "cluster" of the FAT file system, or the "block" of another file system). When a computer operates the file system normally, it should perform reading or writing from the first sector address of the cluster or block. If reading or writing is not performed from the first sector address of the cluster or block and the sector address to be operated is at another position in the cluster, it is regarded as abnormal. 4. Rules based on business habits. For example, when a computer reads a plurality of files (exceeding the preset number) from the storage device within a preset time (or within one access), it is regarded as abnormal.
[0216] Measures for dealing with abnormalities include, but are not limited to, the following. When the operation is prohibited, the protection module returns a response indicating normal execution, or responds with blank data, or responds with other non-existent data, so that the computer is made to recognize that the execution has been successful, and in fact, the protection module does not actually operate on the data of the storage device, preventing the computer from recognizing that the operation has failed and continuously attempting the operation. The second is the process of transitioning to the manual confirmation mode.
[0217] In this embodiment, the preset read / write rules include, but are not limited to, general read / write rules for sector addresses and the number of files to be read / written. Exemplarily, regarding the general read / write rules for sector addresses, usually, reading / writing starts from the first sector address. However, if the current read / write operation does not start from the first sector address of the file and starts reading / writing from another sector, such as continuously reading / writing from sector 100 to sector 9999 in the data area, the read / write operation is regarded as abnormal. Regarding the number of files to be read / written, since the crawler-style reading scans all files in the storage device and reads them in batches, the number of files to be read is set to 10, for example. If the number exceeds 10, the read / write operation is regarded as abnormal.
[0218] Furthermore, in the method provided in this embodiment, the step of "responding to the data interaction command" includes step 41 of sending the data interaction command to the storage device so that the storage device reads and / or writes data based on the data interaction command; step 42 of obtaining process information on the process by which the storage device reads and / or writes data based on the data interaction command; step 43 of determining whether there is an abnormality based on the process information; and step 44 of sending a stop command to the storage device if there is an abnormality.
[0219] Based on the corresponding content of the rule for the above computer device to normally read files, the step of "determining whether there is an abnormality based on the process information" in step 43 above includes determining that there is an abnormality if the process by which the storage device reads data based on the data interaction command does not conform to the set process law. When the process of the memory device reading and / or writing data based on a data interaction command does not specify a context operation, it is determined that there is an abnormality. Here, when reading data, the specified context operation is an operation of reading the folder where the data is located. However, when writing data, the specified context operation is an operation of obtaining the folder where the data is located, and When the process of the memory device reading and / or writing data based on the data interaction command does not start the read or write operation from the first address of the sector of the cluster or block where the data is located, it is determined that there is an abnormality, and At least one of the following may be included: when the memory device reads more files than a set quantity within a preset time based on the data interaction command, it is determined that there is an abnormality.
[0220] Optionally, when there is an abnormality in the read / write operation, a manual confirmation mode may be combined to manually confirm or provide information feedback to the computer device. For example, the method provided in the embodiments of the present application Step 51, when there is an abnormality, a step of sending feedback information including false information simulating successful writing or preset data as data successfully read from the memory device to the computer device, and / or Step 52, when there is an abnormality, a step of outputting manual confirmation prompt information so that the user can confirm whether to continue the execution based on the manual confirmation prompt information, may be included.
[0221] In some embodiments, based on the embodiment shown in FIG. 1, FIG. 13 shows a flowchart of the data security protection method of the fifth embodiment. The same steps as in FIG. 1 are not repeated. As shown in FIG. 13, the method further Step S801: Connect the target sector interval to the computer device as a memory data source. The target sector interval is obtained by partitioning the storage area of the storage device, and the memory data source includes the target file.
[0222] In this embodiment, when the protection mode is the logical split disk mode, the storage device is logically divided. The logical division is a process of partitioning the storage area of the storage device based on the sector addresses of the storage device. This only displays multiple partitions on the computer device at present, which is different from the system disk partition that actually stores files at the same sector interval. For example, the sector address interval of hard disk 1 is from 0 to 999, and hard disk 1 is system partitioned so that disk 1 and disk 2 are displayed on the computer device. However, the data of disk 1 and disk 2 are actually stored in the address interval from sector 0 to 999 of hard disk 1, and the data of disk 1 or disk 2 can also be accessed simultaneously. The logical split disk mode of this embodiment divides the sector address interval of hard disk 1 into two sector address intervals from 0 to 499 and from 500 to 999, corresponding to disk A and disk B respectively. The data of disk A is stored in the sector address interval from 0 to 499, and the data of disk B is stored in the sector address interval from 500 to 999, so that the data of disk A and the data of disk B do not affect each other in terms of the underlying logic, and for example, they can be formatted with different file systems respectively. Optionally, for the multiple sector intervals after partitioning, they can be connected to the computer device in the form of independent split disks or in the form of files.
[0223] That is, when the current protection mode is the logical split disk mode, correspondingly, the method provided by this embodiment further Step 61, when the current protection mode selected by the user is the logical split disk mode, partitioning a specific storage area of the storage device and obtaining at least one split disk; Step 62, including selecting one split disk from the at least one split disk as the target split disk and connecting it to the computer device.
[0224] Furthermore, the method provided by the embodiment of the present application further includes Step a, determining the specific storage area, which may be all or part of the area of the storage device, according to the user's settings; Step b, including at least one of determining the specific storage area based on the selection rule of the specific storage area in the logical split disk mode.
[0225] Here, in step 61 above, the step of "partitioning the storage device and obtaining at least one split disk" includes reading the sector information of the specific storage area according to the user's partitioning command and partitioning the specific storage area based on the sector information, or reading the sector information of the specific storage area, using a preset partitioning policy based on the sector information, and partitioning the specific storage area, or in the file system of the storage device, generating at least one image file, and partitioning a specific storage area of the storage device at address intervals corresponding to the at least one image file respectively.
[0226] Specifically, the "preset split disk policy" can be obtained locally or from the server side on the network side.
[0227] It should be noted that the server side in the present application is a terminal that uses a network connection (such as TCP / IP connection) or a non-network connection (such as point-to-point connection using Bluetooth, LoRA, etc.). For example, when two terminals establish a data interaction relationship and the first terminal provides a data source that can be used for read and write operations to the second terminal, the first terminal can be understood as the server side. Of course, the server side can also be understood as a server, virtual server, cloud, server cluster, etc. installed on the network side. In addition, the sector of the present application should be understood as a general memory area address, that is, an area that divides the memory area of the storage device. The sector information includes, but is not limited to, the total number of sectors (sector address interval) and the number of bytes of each sector. The logical split disk mode is compatible with all protection modes. That is, other protection modes target the target split disk connected to the computer device after being logically split. For other split disks not connected to the computer device, the computer device cannot identify other split disks. Therefore, the data interaction command sent from the computer device is only directed to the target split disk.
[0228] Through the logical split disk mode, the same effect as the "dual hard disk dual system of the computer" of the computer is realized. The hard disk is switched to select the internal network system or the external network system by two hard disk physical separation cards, and the storage area and the system are independent. The split disk here is to partition a storage device with only one physical storage area or logically one physical storage area into two or more storage areas with arbitrary numbers and capacities logically.
[0229] The specific implementation method is as follows. 1. Pre-divide the split disk and select the split disk. Divide multiple sector intervals in the storage device in advance and select the corresponding sector intervals. For example, assume that the total number of available sectors in the storage device is 2,000, which is divided into two split disks, and the total number of available sectors for each split disk is 1,000. Furthermore, hardware feature parameters such as Vendor ID, Product ID, and string information can be automatically or manually assigned to each split disk. 2. Respond to the computer's requirements for hardware feature parameters. The first is to respond with the capacity parameter of the split disk. When the computer device sends a command to request the capacity parameter, it responds with the relevant total number of the capacity of the selected split disk. For example, if the SCSI or UFI command code sent by the computer is 0x25 (READCAPACITY), the protection module responds with the address of the last logical block of the logical split disk. If the SCSI or UFI command code sent by the computer is 0x23 (SCSI_READ_FORMAT_CAPACITIES), the protection module responds with the number of available sectors (or available blocks) and the number of bytes in one sector (or block). Thereby, the computer regards the capacity value of the storage device as the capacity value of the logical split disk. The second is to respond with hardware parameters such as the Vendor ID and Product ID of the split disk. When the computer sends a command to request the hardware feature parameters, it responds with the hardware feature parameters corresponding to the split disk. For example, if the computer sends a request for a device descriptor (0x80 0x06 0x00 0x01 0x00 0x00 0x12 0x00) of the USB protocol, the protection module responds with the corresponding Vendor ID and Product ID parameters of the device descriptor. The third is to respond with the string information parameter of the split disk. When the computer sends a command to request the string descriptor, it responds with the string information parameter of the split disk. For example, if the computer sends a request for string descriptors (0x8006010309040200, 0x8006020309041200, 0x8006030309042800) of the USB protocol, the protection module responds with the corresponding string information of the string descriptor. 3. Read-Write Mapping. When the computer sends a data interaction command, the protection module offsets and maps it to the corresponding sector interval. When Disk 1 is selected, the computer reads Sector 0, reads Sector 0 of the removable storage device, returns, and when the computer reads Sector 1, it reads Sector 1 of the storage device, returns, and similarly, the maximum readable sector is Sector 999. When Disk 2 is selected, the computer reads Sector 0, offsets by 1000 sectors, reads Sector 1000 of the removable storage device, returns, and when the computer reads Sector 1, it reads Sector 1001 of the storage device, returns, and similarly, the maximum readable sector is Sector 1999, and the storage device cannot read the data from Sector 0 to Sector 999. The computer writes to the 0th sector address, and the 1st sector address also coincides with the sector position mapped by the above-mentioned read offset. If the sector address read or written by the computer is outside the range of the split disk, a read or write error state is returned.
[0230] Assume that when the capacity of the storage device is 2,000 kbytes, there are two split disks, Split Disk 1 and Split Disk 2, in the storage device. The capacities of Split Disk 1 and Split Disk 2 are the same, for example, both are 1000 kbytes. When Disk 2 is selected, a total capacity of 1000 kbytes is displayed to the computer. Performing operations such as formatting or copying data for Disk 2 does not affect all the data on Disk 1. It should be added here that the above examples of sector intervals and total capacity data are for easy understanding, and in actual scenarios, the numbers will be much larger.
[0231] Logical split disks are different from specific folder read / write operations. The concept of implementing logical split disks is almost the same as that of specific file read / write and empty folders, mainly mapping the sector addresses of computer read / write interaction commands to the relevant sector addresses of the storage device. Specific folder read / write and empty folders mainly map the sector addresses of one file to the sector addresses of another file, and the total capacity and free space of the file system and storage are consistent with the original disk, and the file system cannot be formatted. In split disk mode, regardless of the specific file, the sector address interval is directly mapped, the total storage capacity and free space are independent, and the file system can be formatted individually.
[0232] Specific scenarios of split disks in storage devices: The first is to automatically split external storage into logical split disks (split disks of storage media). In the form of an intermediate device or card reader, the connected storage device is split into disks. The protection module reads in advance the basic information of the storage device (connected USB flash drive, SD card, TF card) (total number of sectors, number of bytes per sector, vendor and product ID, string information). For example, when the capacity of a storage device (such as a USB flash drive) is 16GB, if the storage device is averaged into two split disks by default, it is automatically split into two 8G split disks. If the storage device is split into three split disks by default, it is split into one 8G disk and two 4G disks, split into 2*8G for 32G 16G, and split into 2*16G for 64G 32G, etc. The second is to automatically divide the internal memory area (memory media split disk). In the form integrated with a removable storage device, one or more physical memory areas of the internal memory (FLASH) can be logically divided. Since the memory media is fixed inside the device and the physical capacity of the storage device is known and fixed at the time of manufacture, the above step of reading the basic information of the storage device in advance is omitted. Preset the basic information of the memory media device (total number of sectors, number of bytes per sector, vendor ID and product ID, string descriptor). The third is to divide the split disk in the form of file mirroring. In the file system of the memory media, an image file is generated, and the content data of the image file is divided as the sector interval of the split disk. Map all sectors of the split disk directly to the content data of a specific file. The size of the split disk can be preset by file placeholder. For example, assume that a blank "1.dd" file with a size of 16G is generated and the size of the split disk is 16G. Also, regardless of the pre-set placeholder, when reading and writing are required, it can also be written by adding to the file data. The size of the split disk is the sum of the size of the existing data on the split disk and the total free space of the USB flash drive (also called the blank data area), and the data space of the storage device can be fully utilized. More specifically, for example, the path of the image file of the split disk is "My USB flash drive\My folder\Split disk 1.dd". The basic information corresponding to the split disk (total number of sectors, number of bytes per sector, vendor ID and product ID, string information, etc.) is preset.
[0233] When using the split disk 1, the protection module returns the basic information of the split disk when enumerated by the computer. When the computer reads and writes data, the protection module reads and writes the file content data of "split disk 1.dd" so as to actually map. For example, when the computer reads sector 0, the first sector address of the content data of the file "split disk 1.dd" is returned. When the computer reads the data at the 100th sector address, the address data of the 100th sector of the "split disk 1.dd" file is returned. When the computer writes data to sectors from 200 to 300, the data is written to the address data of sectors from the 200th to the 300th of the "split disk 1.dd" file.
[0234] The fourth is to split it into split disks through network services (actually, a network data source is connected). In the same format as the file image, the basic information corresponding to the split disk (total number of sectors, number of bytes per sector, vendor ID and product ID, string information) is preset either locally on the storage device or on the server. The difference is that the generated and used image files are stored on the server. The network protection module (network USB flash drive) itself can store data, store a small amount of data (such as optimizing the startup mode or connecting to the network configuration of the network server), and the network USB flash drive is connected to the network server in a wired or wireless way and transmits the identification information of the network USB flash drive. The backend server associates the corresponding image file (for example, "split disk 1.dd") according to the identification information of the network-connected USB flash drive. When the computer sends an interaction command to the USB flash drive (such as reading a sector), the read / write requirements of the interaction command are transferred to the server (the main information of the command is the read or write operation, the address of the start sector, and the length of the continuous read or write sectors). After receiving the request from the USB flash drive, the server returns the sector address data corresponding to the corresponding image file (for example, "split disk 1.dd" corresponds to disk A). Also, identification numbers can be associated with the three files of "split disk 1.dd" corresponding to disk A, "split disk 2.dd" corresponding to disk B, and "split disk 3.dd" corresponding to disk C, and the data source can be switched as needed.
[0235] Also, in the above-mentioned logical split disk mode (which splits the storage device to be accessed (such as a USB flash drive), internal storage medium, image file saved as a file, network image file), it is necessary to be able to customize the parameters of the descriptor so that the computer can distinguish different storage devices (such as different USB flash drives). The method to achieve this is "configuration information" + "data source". The configuration information includes a descriptor collection and basic information. The descriptor collection includes a device descriptor, configuration descriptor, interface descriptor, endpoint descriptor, etc. The basic information includes capacity information such as the total number of sectors and the number of bytes per sector, and parameters of the mass storage device such as read-only or read-write status. Furthermore, the "configuration information" can be saved in a non-display location of the data source. For example, it cannot be accessed from the computer as data of the USB flash drive in the last sector. It can also be stored in the server-side database. It may also be a specific sector or file stored in the built-in storage of the protection module.
[0236] This advantage is as follows. One storage device or memory chip can meet various needs, such as formatting different file systems in split disk mode to enable use in various scenarios, because it can effectively reduce hardware costs compared to the case of maximizing the use of the storage area of a storage device and achieving isolation using multiple storage devices or memory chips. Furthermore, more secure protection can be achieved. Each split disk is directly independent of each other (the data sources are independent and may have different hardware characteristics), the control is performed at the data communication layer, and the computer only considers that the connected storage device has the capacity of the split disk and does not exceed the read range of the sector. If the read value of the sector is forced to exceed the range of the split disk, the protection module will not execute the command. In addition, the embodiments of the present application provide a scheme that does not depend on the type, kind, and formatted file system of the storage device, and can realize a logical split disk as long as it can establish a communication connection and read / write control with the protection module.
[0237] Data is stored on the server side, and the protection module can switch data sources at any time according to various scenarios. Both reading and writing of data are stored on the server side, and the protection module is essentially just a front-end device. Even if the protection module is lost, the data continues to be stored on the server. Furthermore, the computer device cannot know the data source, and the protection module can use its own mobile cellular network or the Wi-Fi of the protection module user without connecting to the network via the computer, and network traffic does not pass through the computer. Also, for the computer, it is impossible to intuitively control whether the data of the storage device is stored on the server side or on the local storage medium of the protection module. Moreover, the protection module of the embodiment of the present application is different from the existing network USB flash drive. The prior art is to first download the server-side file to the network USB flash drive storage device, and then read and download the file of the file system of the storage device via the computer. Or the computer writes the file to the file system of the USB flash drive storage device and uploads it to the server from the network USB flash drive. In this case, a 16G network USB flash drive cannot send a 32G file, or a network USB flash drive less than 4G cannot send a file larger than 4G, etc., and it is necessary to occupy the capacity of the storage area of the network USB flash drive itself. Since the present invention is based on data transfer, there is no problem of file limitation. On the other hand, it is not possible to switch all the data of the storage split disk. In the present invention, it is based on the reading and writing of sector addresses. Disk A can be formatted as a FAT32 file system, with files A.txt and B.txt, and disk B can be formatted as an ExFAT file system, with files C.txt and D.txt, and can be directly connected to the computer for display. However, the existing network USB flash drive can only select and copy specific files.In addition, the image files mapped on the server side, such as "split disk 1.dd", may be database data based on distributed storage technology, optimized storage, and CDN network acceleration, or may be a combination, splicing, and mapping of multiple files.
[0238] Selection method of data source: 1. Selection by physical button. Switch through the physical button of the protection module (the physical switching button corresponding to the selection of the split disk data source in FIGS. 2b and 2c) to select the corresponding split disk data source (such as a memory medium split disk, an image file split disk, a network image file split disk, etc.). 2. Selection by short-range wireless communication. A command to select the data source of the split disk is sent through a communication module such as Bluetooth, WiFi, or serial port interface of the protection module. Upon receiving the command, the protection module selects the corresponding disk data source. 3. Selection by remote communication. Use the network mode of the protection module to obtain the command of the split disk data source on the server side and select the corresponding disk data source. The command on the server side is set by the user connecting to the server side through programs such as APP, applet, and web page. 4. A key (or selection by feature value) sent from a computer. When a split disk is created, its basic information includes corresponding key information. After the protection module is connected to the computer, the computer sends an interaction command with key (or feature value) information, and the protection module matches it with the basic information set of the split disk according to the key. If a match is found, the corresponding split disk data source is selected. For example, split disk 1 corresponds to key A, split disk 2 corresponds to key B, and at the same time, the key to connect to all split disks is C. If the confirmation command contains key A, it is confirmed that split disk 1 is connected to the computer device. If the authentication command contains key B, it is confirmed that split disk 2 is connected to the computer device. If the authentication command contains key C, it is confirmed that split disk 1 and split disk 2 are simultaneously connected to the computer device. When the computer device is connected, it is confirmed by the key sent from the computer, the access to the selected target storage data source is determined, and the security of the storage data source is improved.
[0239] Based on the above method of selecting a data source, in the method provided by the embodiment of the present application, the step of "selecting one split disk from the at least one split disk as the target split disk" responding to the user's selection operation of the at least one split disk through an interactive device, and setting the split disk selected by the user as the target split disk, or receiving a split disk selection command sent from a designated device different from the computer device that communicates with the protection module through short-range wireless communication or remote communication, and obtaining the split disk indicated by the split disk selection command as the split disk, and or Receiving information carrying a disk key transmitted from a computer device, verifying the disk key, and after passing the verification, selecting a split disk having the disk key as a target split disk among the at least one split disk.
[0240] Optionally, the access mode of the target split disk can be set by a toggle switch, a remote control, or computer settings. Exemplarily, in one possible implementation form, the target device is provided with a physical switch for selecting a split disk, and the target split disk is selected by toggling the physical switch. In another possible implementation form, the target device includes a communication unit such as a wireless LAN, Bluetooth, infrared, or ultra-wideband for connection to a remote control device, and the target split disk is selected through the remote control device. In another possible implementation form, it communicates with a computer device and the target split disk is selected through the computer device.
[0241] Optionally, when the computer device reads the total number of sectors of the storage device, the total number of sectors of the selected split disk is returned to the computer device. The computer device maps at the actual sector position of the split disk sector when transmitting a data interaction command for reading and writing sectors.
[0242] What needs to be added here is that the "partitioning" in the statement "the target sector interval is obtained by partitioning the storage area of the storage device" mentioned above means that the "partitioning" of the "division of a specific storage area of the storage device" described above can be understood as a mapping policy in terms of actual technology. This mapping policy may be preset. For the storage medium (or storage device), there is actually no change, nor is there any change in the reading and writing of disk capacity information and sector addresses. In the protection module, based on this mapping policy, it only shows the user the effect of a split disk on the computer device side. In other words, the division of a specific storage area of the storage medium by the protection module is a virtual and conceptual division of the split disk, presenting the effect of the split disk to the user on the computer device side, and there is no change in the storage medium.
[0243] In some embodiments, based on the embodiment shown in FIG. 13, before step S801, a step of reading sector information of the storage device; a step of partitioning the storage area of the storage device based on the sector information and obtaining a plurality of sector intervals corresponding to the storage device, wherein the target sector interval is at least one of the plurality of sector intervals.
[0244] In this embodiment, the sector address interval of the storage device is divided based on the preset number of split disks, and the sector address interval of each storage area is obtained. The number of split disks can be a preset value or the quantity selected by the user in real time before logical partitioning. The method of interval partitioning can be to divide the sector addresses of the storage device based on a preset interval size or based on the interval size selected by the user in real time.
[0245] Optionally, when the preset split disk quantity is a preset value, when the computer device communicatively connects to the storage device, and when the target device is in the logical split disk mode, the sector information of the storage device is divided according to the default value to achieve plug and play.
[0246] For example, when the preset split disk quantity is the number selected in real time, when the computer device communicates and connects to the storage device, and when the target device is in the logical split disk mode, the computer device displays an option for providing the user with the number of split disks and the size of each split disk, and based on the number of split disks and the split size selected by the user, the computer device performs real-time distribution of the logical split disks on the storage device. For example, if the sector address range of the storage device is from 0 to 1999, the number of split disks and the size of the split disks are displayed on the computer device, the number of split disks is 2, and the size of each split disk is the same, then a split disk corresponding to the sector address interval from 0 to 999 and a split disk corresponding to the sector address interval from 1000 to 1999 are obtained.
[0247] It can be understood that when the target device is an intermediate device and the intermediate device is simultaneously connected to a plurality of storage devices, it is possible to logically divide the plurality of storage devices, physically divide them based on each storage device, and obtain the same number of split disks as the number of storage devices.
[0248] FIG. 14a, FIG. 14c, FIG. 14e, and FIG. 14g are schematic diagrams of examples corresponding to the logical split disk mode. FIG. 14a shows the free space of a storage medium (e.g., a USB flash drive with a protection module or a USB flash drive connected to an intermediate device) with a display value of 14.9 GB (theoretically about 16 GB of free space). FIG. 14b is a schematic diagram physically showing the storage area before the free area is logically divided. For example, from the position of the 0x00 sector to the position of the end sector (the number of sectors corresponding to the free space or the last logical block address of the free space + 1) can be used. Suppose it is divided into one 8 GB (theoretical value) split disk and two 4 GB (theoretical value) split disks, for a total of three logical split disks. For information related to the first logical split disk, such as capacity, file system, unit size of the split disk, remarks, etc., refer to FIG. 14c. It is also possible to control operations such as checking the quick format in the formatting options or triggering the reset of default values by using "restore to default values of the device". The example shown in FIG. 14c shows that the first logical split disk has a capacity of 7.47 GB (theoretically 8 GB) with a file system of FAT32 (default) and an allocation unit size of 4096 bytes. The window shown in FIG. 14c is the formatting page displayed after selecting the first logical split disk. The formatting page shows that the capacity of the first logical split disk is 7.47 GB (theoretical value is 8G), and after the user clicks the "Start" control, the first logical split disk can be reformatted. FIG. 14d is a schematic diagram physically showing the 8 GB storage area corresponding to the first split disk. FIGS. 14e and 14g show the attribute information of the second logical split disk (i.e., two 4 GB logical split disks, disk_02 and disk_03). FIG. 14f is a schematic diagram physically showing the 4 GB storage area corresponding to the second split disk. FIG. 14h is a schematic diagram physically showing the 4 GB storage area corresponding to the third split disk.
[0249] After the disk is split, the corresponding sector intervals of each disk are independent of each other, do not interfere with each other, and the data are separated from each other. For example, the file directories of the above three logical split disks are completely different and cannot access each other.
[0250] FIG. 14i is a schematic diagram showing the response of the protection module to read and write to the computer's storage area in a specific folder mode when the protection module is not logically split. As shown in FIG. 14i, the dotted line indicates that the computer device wants to read and write root sector data. Actually, after the protection module receives the data interaction command of the root sector data sent from the computer, it reads and writes the sector data of a specific folder directory and returns it.
[0251] FIG. 14j is a schematic diagram showing the response to a computer that performs reading and writing of a storage device when the current protection mode of the protection module is a combined mode of a logical split disk mode and a blank folder mode, and the storage space is split into three logical split disks in the combined mode of the logical split disk and the blank folder mode. As shown in FIG. 14j, the dotted line indicates that the computer device wants to read and write root sector data, and the sector position of the root directory can be offset to the sector position corresponding to the second logical split disk. After the computer device sends a data interaction command for reading and writing the data of the root directory sector, the protection module selects split disk 2, and the protection module reads and returns the directory sector data of a specific folder in split disk 2.
[0252] In some embodiments, based on the embodiment shown in FIG. 1, FIG. 15 shows a flowchart of the data security protection method of the sixth embodiment. The same steps as in FIG. 1 are not repeated. As shown in FIG. 15, the method further includes connecting an image file to a computer device as a storage data source and generating an image file based on a preset mirroring policy in step S901.
[0253] In this embodiment, the preset mirroring policy can be obtained by creating a blank image file. It can also be obtained by copying an existing image file or by mirroring the data intervals of the storage device.
[0254] For example, regarding the method of creating a blank image file, a preset storage image file (it can be a blank file of "split disk 1.dd" with a size of 16 GB) is generated in the storage device to obtain the image file. Regarding the method of copying an existing image file, the data of all sectors of hard disk A of another storage device is saved as a storage file of "disk image file A.dd", and "disk image file A.dd" is called the image file of hard disk A, and "disk image file A.dd" is copied to a storage device with a storage area capacity. Through the protection module, the above "split disk 1.dd" or "hard disk image file A.dd" can be connected to the computer device as a data source.
[0255] Optionally, regarding the mode of mirroring the data intervals of the storage device, the size of the data intervals can be preset by file placeholder holding. For example, a blank "split disk 1.dd" file with a size of 16G is generated, and the size of the data intervals is 16G. The size of the data intervals is the sum of the size of the existing data within the data intervals and the total of the free space (or blank data area) of the storage device, and the data space of the storage device can be fully utilized.
[0256] For example, the computer device reads and writes data sources stored in file format: the file path corresponding to the data interval is "E:\My Folder\Split Disk 1.dd" on the USB flash drive. When Split Disk 1 is read and written, the target device actually reads and writes the file data of Split Disk 1.dd for mapping. When the computer device reads the 0th data block, 512 bytes of data are returned from the first address of the file data of "Split Disk 1.dd" (the size of one sector is 512 bytes), that is, the data of file data block 0 is returned, and the file data is read and written as an offset by the operation of the computer device (sector address × 512). When the computer can directly read and write the data of the corresponding sector of the file, it directly reads and writes the corresponding sector of the file.
[0257] It should be noted that for the file split disk in this embodiment and the network split disk in the following embodiments, it is necessary to expand so that the sector address is interpreted as a "file data block", that is, one file data block corresponds to one sector. For example, when the size of one sector is 512 bytes, reading sector 0 corresponds to file data block 0, that is, a total of 512 bytes from the first address of the file to the next 511 bytes. Writing to sector 1 corresponds to file data block 1, which is equivalent to writing a total of 512 bytes of data from the 512-byte offset of the file to the next 511 bytes. The subsequent steps are not repeated.
[0258] In some embodiments, based on the embodiment shown in FIG. 1, FIG. 16 shows a flowchart of the data security protection method of the seventh embodiment. The same steps as in FIG. 1 are not repeated. The storage device is a network storage device, the network storage device is connected to the server side, and the server side, as shown in FIG. 16, the server includes a plurality of network image files, and the method further includes Connect the target network image file to the computer device as a storage data source, where the target network image file is at least one of a plurality of network image files, and the storage data source includes step S1001 that includes the target file.
[0259] In this embodiment, the storage device is a network storage device. The network storage device does not necessarily store data, may store data, is connected to the server side through a wired mode or a wireless mode, and the service side is provided with a plurality of network image files. Optionally, based on distributed storage technology, optimized storage, and CDN network acceleration, the network image file can be made into the data of the database, or a plurality of files can be combined to apply a patch and perform mapping.
[0260] Optionally, the network storage device connects to the server side and sends identification information to the server side. The server side associates the corresponding network image file according to the identification information of the network storage device, and a computer device that transfers the read / write requirements of the data interaction command (such as read or write operations, the sector address where the operation starts, and the length of the continuously read sectors, etc.) to the server side sends the data interaction command. After the server side receives the read / write requirements sent by the network storage device, it returns the corresponding sector file data block address of the network image file to realize the expansion of the data space of the network storage device.
[0261] Optionally, the target networked image file corresponding to the storage device on the network is switched on the server side according to the identification information of the network storage device, and the target network image file is connected to the computer device. For example, based on the identification number of the network storage device (or the identification information of the user associated with the account login), when binding three network image files of "split disk 1.dd", "split disk 2.dd", and "split disk 3.dd", the data sources connected to the computer device in the three network image files can be switched.
[0262] For example, the target device is connected to the server side, the network image file of "split disk 1.dd" stored on the server is connected to the computer device, and the computer device sends a data interaction command in the form of a single sector size of 512 bytes. When using the data interaction command to read the data at the address of the 0th sector and write the data to the address of the 1st sector, the protection module sends a request to the server side, and the server side converts the 0th sector to the first address of "split disk 1.dd", and converts the 1st sector to the 512-byte offset address of "split disk 1.dd". Based on the converted address, the server side returns 511 bytes of data from the first address of "split disk 1.dd" in the image file. When writing the data to the next 511 bytes of data with the 512th byte of "split disk 1.dd" as the offset address, the network storage device returns the result returned from the server side to the computer device.
[0263] The network storage device of this embodiment can freely switch different storage data sources without installing software tools on a computer device. The actual address of the data source is invisible to the computer, the data source is stored in the cloud, and when the network storage device is lost, the data source can be remotely canceled, improving the data security of the data storage device. At the same time, this embodiment directly reads and writes the specific offset address data (or sector address data corresponding to the file) of the server-side related file, and transfers the data directly to the server side or the computer device, so as not to be limited by the storage area of the storage device itself, improving efficiency and increasing applicable scenarios.
[0264] In some embodiments, the descriptor collection (and related configuration files) is used to distinguish data sources in different forms, such as independent split disks, files, and networking forms. As a result, the computer device can distinguish different storage devices. The "descriptor collection" can be stored in a non-display location of the data source. For example, the last sector can be made inaccessible to the computer as a storage device, stored on the server side, or can be a sector or file stored in the internal storage of the protection module.
[0265] When the protection module is arranged in the intermediate device, the intermediate device has a network function for connecting to the cloud-side or server-side storage module. Correspondingly, the steps of the scheme provided in the embodiments of the present application, the step of "responding to the data interaction command" is including the step of sending the data interaction command to the storage module on the network side so that the storage module reads and / or writes corresponding data based on the data interaction command.
[0266] In some embodiments, based on any of the embodiments shown in FIGS. 13, 15, and 16, the method further comprises In response to an authentication command input by a user, a target memory data source corresponding to the command type of the authentication command is connected to the computer device, and the target memory data source is at least one of a sector interval, an image file, and a network image file.
[0267] In this embodiment, the authentication command is a command for determining that a selected target memory data source is connected to the computer device, and may carry encryption information corresponding to the target memory data source. For example, when the target memory data source is connected to the computer device in the form of a split disk, split disk 1 corresponds to password A, split disk 2 corresponds to password B, and the password for connecting all split disks simultaneously is C. If password A is included in the authentication command, it is confirmed that split disk 1 is connected to the computer device. If password B is included in the authentication command, it is confirmed that split disk 2 is connected to the computer device. If password C is included in the authentication command, it is confirmed that split disk 1 and split disk 2 are simultaneously connected to the computer device. In this embodiment, in order to determine access to the selected target memory data source, when accessing the target sector interval, the identity of the user is confirmed through the password, thereby improving the security of the memory data source.
[0268] In some embodiments, based on the embodiment shown in FIG. 1, FIG. 17 shows a flowchart of a data security protection method according to an eighth embodiment. The same steps as in FIG. 1 are not repeated. As shown in FIG. 17, the method further comprises a step S1101 of reading power demand information of the storage device, and a step S1102 of setting a circuit current limit protection policy for the storage device according to the power demand information, wherein the circuit protection policy is for controlling the power consumption state of the storage device.
[0269] In this embodiment, the power demand information includes, but is not limited to, the current consumption, the applied voltage, and the circuit state. The circuit protection policy includes a protection policy for the storage device and a protection policy for the computer device.
[0270] Optionally, to prevent the storage device from being burned out due to an input of a large current from the computer device, a protection policy is set based on the current of the storage device. For example, whether the path current between the second interface connected to the computer device and the first interface connected to the storage device by the intermediate device exceeds the current consumption, or exceeds a preset allowable upper limit (e.g., 10%) of the power demand, or exceeds a preset fixed value (e.g., 500 mA). To prevent the computer device from being burned out due to a short circuit of the storage device, a protection policy is set based on the circuit state of the storage device. For example, when the circuit state of the storage device is short-circuited or a momentary high current is generated, the intermediate device disconnects the connection path to the first interface connected to the storage device or increases the resistance to the first interface.
[0271] In some embodiments, the method further includes generating an interaction log for recording a processing record of a data interaction command transmitted by a computer.
[0272] In this embodiment, by storing the processing record (recording of transfer status, related data of execution, etc.) of the data interaction command transmitted from the computer device in the interaction log, subsequent audits can be facilitated. Optionally, by setting the read-only mode when the interaction log is read, the reliability of the recording of the interaction log can be ensured without the interaction log being tampered with.
[0273] In some embodiments, when the current protection mode is the backup mode, correspondingly, in the step of "responding to the data interaction command", when the data interaction command is a write command, synchronously write the data written by the computer device to the specified backup storage area, and / or when the data interaction command is a write command, before executing the write command, the protection module reads the sector address data written by the computer device and writes it to the specified backup storage area.
[0274] The advantage of "synchronously writing the data written from the computer device to the specified backup storage area" is that when it is found that important data is damaged by another computer device when copying important data from the computer device, the data can be restored by backup and restoration.
[0275] There is the above-mentioned advantage of "before executing the write command, the protection module reads the sector address data written by the computer device and writes it to the specified backup storage area", which is equivalent to holding the original data before writing, and after being maliciously deleted or modified by the computer, it can be restored from the backup storage area. For example, before the computer writes data, it backs up data such as the boot sector, FAT table, and file item information. If it is found that the computer has been maliciously written and damaged, the storage device cannot be accessed normally (for example, reformatting is required), or the file cannot be displayed, read, or written. The data can be restored from the backup.
[0276] Furthermore, when the current protection mode is the backup mode, the data protection method provided by this embodiment further Backing up and storing the data of important data sectors of the connected storage device in a specified backup storage area; When restoration is triggered, including the step of reading the data in the specified backup storage area and writing it to the original data sectors of the storage device.
[0277] Here, the important data sectors can be set artificially. For example, the user can specify them via an interactive device, and the data sectors specified by the user can be marked as important sectors. Or, the important data sectors are set by a protection module. Or, the important data sectors are selected based on a preset importance evaluation policy, etc. This embodiment is not particularly limited thereto.
[0278] Refer to an example of a structural form of the intermediate device shown in FIG. 18a. Alternatively, it is a storage device integrated with a protection module having functions corresponding to the protection methods provided by each embodiment of the present application shown in FIG. 18b. The intermediate devices shown in FIGS. 18a and 18b can display information that needs to be manually confirmed, such as file name, file type, file size, operation, etc., in a manual confirmation mode. The user can confirm the operation with the "Confirm" control or cancel the operation with the "Cancel" control. Depending on the usage scenario, as shown in FIGS. 18a or 18b, the user can manually operate the panel of the intermediate device or the storage device. First, select a protection mode. Select a protection switch corresponding to a protection mode such as full disk read-only, write-only for a specific folder (empty folder), read-only for a specific folder, etc., to complete the setting of the current protection mode of the intermediate device. Second, select a physical data source. Select the data source as a USB storage device, SD card, built-in memory chip, external network storage device, etc. III. Select a logical split disk data source. Further, the sector addresses of the physical data source are segmented to form multiple data sources for selection, and one of the split disks is selected as the data source. For example, a 16G USB flash drive can be divided into three data sources of 8G, 4G, and 4G. IV. Connect the intermediate device to the computer device. Insert the USB male connector of the storage device into the USB female connector of the intermediate device, insert the USB male connector of the intermediate device into the USB female connector of the computer device, and use the USB port of the computer device to supply power to the intermediate device and the storage device.
[0279] Figure 19 shows several scenarios. Scenario 1: The computer device is connected to the storage device via an intermediate device that isolates the computer device from the storage device. The product form of the intermediate device in Scenario 1 is a hardware device similar to an interface converter, as shown in Figures 2a, 2b, or 18a. Scenario 2: The product form of the intermediate device is a card reader used to connect a card and a chip storage device (such as an SD card). The card reader has control and protection functions and can be integrated into one chip in a pure software form or made into two independent chips in the card reader. Scenario 3: The memory device has a protection module, at least one or more internal memory chips (or storage chips), and an interface for connecting at least one or more external storage devices (for example, the TFCard interface is used to access SD cards and TF cards, and the USB interface is used to access USB flash drives). The protection module may be in the form of an independent chip (such as in Scenario 4), or may be configured on the control chip of the memory device in a pure software form similar to Scenario 5, or may be configured on the memory chip in a pure software form in Scenario 6, etc. This embodiment does not limit this. When the memory device is connected to an external storage interface, the protection module can switch the physical data source as needed, such as the selection of an external storage device or a memory chip (or storage chip). Scenario 4: The protection module is part of the hardware of the mobile memory device, but exists independently in the form of a protection chip within the hardware. For example, a normal removable memory device can be converted into a device to which the present invention is applied through hardware upgrade. Scenario 5: The protection function of the data security protection method is integrated into the control chip in the form of software, that is, the protection module is in the form of software. For example, a normal mobile memory device can be changed into a device according to the present invention by upgrading the software (firmware) of the control chip and installing an external button switch. Scenario 6: The protection module is directly used as part of the memory chip, and the protection can be performed by the software and hardware methods of Scenarios 4 and 5. Now, there is a memory chip with a protection function such as an SD card set to read-only. Scenario 7: The protection function of the data security protection method is integrated into the control chip in the form of software, that is, the protection module is in the form of software. Different from Scenario 5, the data storage device has no control chip, and all read and write operations are directly completed by the control chip.
[0280] What needs to be added here is that in the above, the logical split disk mode is mentioned. In the logical split disk mode, the protection module determines the logical split disk (i.e., the data source in a logical sense) connected to the computer device based on the current protection mode. In the aforementioned scenario 3, the protection module is arranged on the first storage device. The first storage device is provided with an interface for connecting at least one or more memory chips and at least one or more external second storage devices, and an external second storage device is connected to at least a part of the interface of the first storage device. Correspondingly, at least one data source specified by the current protection mode of the protection module includes the at least one or more memory chips, at least one physical data source in the external second storage device connected by at least a part of the interface of the first storage device, and / or at least one logical split disk among the at least one or more memory chips, and / or at least one logical split disk among the external second storage devices connected to the first storage device, but is not limited thereto.
[0281] As described above, the interaction process between the computer device and the protection module in the technical solution provided by the embodiments of the present application can include, but is not limited to, a preparation stage, an enumeration stage, and a data interaction stage. As shown in FIGS. 20a and 20b, the basic operation logic of the protection module can be summarized as follows.
[0282] The first stage is the connection stage of the physical memory data source (memory device). According to "selection of physical data source", a physical connection is established. When the protection module is an intermediate device, a communication connection to the memory device is established. When the memory device is an SD card, TF card, built-in memory chip, etc., a communication connection is established according to its interface (e.g., SDI0, SPI, HSPI, etc.). When the memory device is a USB flash drive, the protection module establishes a communication connection based on the USB interface. When the memory device is a hard disk, etc., the protection module establishes a connection according to its SATA, M.2, and other interfaces.
[0283] The second stage is the stage where the protection module reads the physical memory data source (memory device), which is the above-mentioned preparation stage. In the preparation stage, the memory device can be analyzed in advance. One case is that there is a protection module in the intermediate device, and the computer device is connected to the memory device through the intermediate device. In this case, the protection module reads and analyzes the data from the memory device. In another case, since the memory device is integrated with the protection module, there is no need to read, and the data of the memory device can be directly analyzed. The data information of the memory device is analyzed in the same way as the corresponding embodiments described above. Specifically, one is to read the descriptor. For example, when the protection module is an intermediate device and the physical data source is a memory device with a USB interface, read the device descriptor, configuration descriptor, interface descriptor, port descriptor, and string descriptor of the memory device, and determine whether it is a legitimate device type (such as the hardware type of a mass storage device). The second is to read the parameters related to the memory information of the memory device. For example, when the physical data source is a USB device, SD card, TF card, built-in memory chip, etc., the memory area capacity (or the size of the available sectors) and the read / write permission can be read. The third is to establish the sector offset relationship according to the memory area when the protection mode is the logical split disk mode. Fourthly, when the file system is related to the protection mode, further read the relevant memory area data, such as the first sector address of the root directory or the first sector address of a specific folder. For example, when the protection mode is set to a specific file mode, based on the rules of the file system, search for the mapping data, such as the address of the first sector of a specific folder on the memory device (or create a new empty folder) or the address of the root directory (the first directory).
[0284] When the first stage and the second stage are completed and the device type of the device connected to the protection module is a device type with access permitted, the preparation step is successful, and the interface sends an enumeration signal to the computer device to enter the enumeration stage. As shown in FIG. 20a, the device type of the storage device is determined based on the data information of the storage device, which is specific to the intermediate device with a protection module between the computer device and the storage device.
[0285] That is, in one specific embodiment of the present application, when the target device is an intermediate device, the protection method provided by the present application may further include, in the preparation stage, the target device reads and analyzes the data information of the storage device. When the target device is a storage device, the method may further include, in the preparation stage, the protection module analyzes the data information of the storage device.
[0286] As shown in FIG. 20a, when the computer device supplies a power supply signal to the protection module or when the protection module starts, the preparation stage can be entered. When the target device is an intermediate device, the step of "the target device reads data information from the storage device" In the preparation stage, the protection module simulates the computer device and sends a control command to the storage device, and receives the data information of the storage device fed back from the storage device.
[0287] In a specific implementable technical solution, "analyzing the data information" includes determining whether the storage device is the device type specified in the current protection mode based on the data information, and if so, sending an enumerable signal to the computer device and entering the enumeration stage.
[0288] The third stage is the enumeration stage. 3.1. In the enumeration stage, based on the current protection mode, process the data information of the memory device and obtain the processed information; 3.2. Transmit the processed information to the computer device and establish a communication connection between the computer device and the memory device.
[0289] Here, "process the data information of the memory device based on the current protection mode and obtain the processed information" in 3.1 specifically 3.1.1. Generate a second feature parameter for simulating the memory device by processing the data information according to the current protection mode, and / or 3.1.2. Generate a second memory information related parameter for simulating the memory device by processing the data information according to the current protection mode, and 3.1.3. It may include transmitting the second feature parameter and / or the second memory information related parameter to the computer device and establishing a communication connection between the computer device and the memory device.
[0290] The above 3.1.1 includes, in a specific implementation, obtaining a preset parameter template corresponding to the current protection mode, and according to the device type of the memory device reflected by the first feature parameter in the data information, obtaining at least one parameter item that can characterize the device of the device type from the preset parameter template to obtain the second feature parameter, or using the screening policy corresponding to the current protection mode to screen the parameter items in the first feature parameter, and obtaining the second feature parameter based on at least one screened parameter item.
[0291] Here, the first feature parameter can include, but is not limited to, descriptor data, and the descriptor data includes at least one of hardware descriptors, interface descriptors, port descriptors, endpoint descriptors, and string descriptors.
[0292] Furthermore, the data information includes first memory information related parameters, and the first memory information related parameters include, but are not limited to, the read / write enable state of the storage device, the total number of formatable blocks, the last logical block address, the number of bytes per single sector, the maximum number of logical units, and device information.
[0293] When specifically implemented in the above 3.1.2, 3.1.2a, it may include changing the read / write state parameter in the first memory information related parameters according to the operation type specified in the current protection mode.
[0294] As shown in the example of FIG. 21, 2) is a data packet returned from the protection module to the computer device, and 3) is a status packet returned from the protection module to the computer device. Here, in the data packet, the protection module changes the read / write state parameter of the storage device, such as changing the read / write state 0x00 parameter to 0x80 (indicating read-only). Alternatively, the protection module directly returns a read-only (i.e., write-prohibited) status to the computer device.
[0295] It should be noted here that the protection module changes the read / write state parameter during the data interaction process. This change is in the memory of the protection module, and the original read / write state parameter of the storage device is not changed, and no read / write permission for the storage device is required (for example, it is difficult to change the read / write state of a normal USB flash drive).
[0296] When the read / write state parameter is changed to the read-only (write-protected) state, the computer device "recognizes" that the storage device (such as a USB flash drive) is in the read-only (write-protected) state, so the write operation in the human-computer interaction interface is prohibited.
[0297] 3.1.2b. When the current protection mode is the logical split disk mode, according to the parameters of the target split disk that can be accessed by the computer device specified in the current protection mode, change the total number of formatable blocks and / or the last logical block address in the first storage information related parameters.
[0298] As shown in the example of FIG. 22, 2) is a data packet returned from the protection module to the computer device, and 3) is a status packet returned from the protection module to the computer device. Among them, in the data packet, the protection module changes the total number of formatable blocks of the storage device, such as changing 0x01 DE 20 00 to 0x00 EF 10 00. The example shown in FIG. 22 is the change of the disk capacity parameter of the storage device by the protection module in the logical split disk mode. Similarly, without making changes, the protection module can feedback a data packet including 0x00 EF 10 00 to the computer device.
[0299] Here, the total number of formatable blocks can be used to calculate the maximum formatable capacity. For example, the maximum formatable capacity = the total number of formatable blocks * the byte length of each block.
[0300] What needs to be added here is that the example shown in FIG. 22 can be referred to corresponding to FIG. 14d. FIG. 22 explains the situation of split disk 1 from the perspective of the data processing process, and FIG. 14d explains the situation of split disk 1 from the physical perspective. In the case of split disk 1, since the total number of formatable blocks of the original 16G storage area is changed and returned to the computer, it can be seen that the computer "thinks" that there is only 8G in the storage device. Similarly, the protection module makes changes during the data interaction process. The changed data is only in the memory of the protection module, and the original data of the storage device is not changed. There is no need for the permission to change the capacity information (for example, a normal USB flash drive is difficult to change the capacity information).
[0301] Also, FIG. 23 shows an example of changing the last logical block address. As shown in the example of FIG. 23, 2) is a data packet returned from the protection module to the computer device, and 3) is a status packet returned from the protection module to the computer device. Here, in the data packet, the protection module changes the last logical block address of the storage device, for example, changing 0x01 DE 1F FF to 0x00 EF 0F FF. The example shown in FIG. 22 is the change of the disk capacity parameter of the storage device by the protection module in the logical disk split disk mode. Similarly, without making any changes, the protection module can feedback a data packet containing 0x00 EF 0F FF to the computer device.
[0302] 3.1.2c, according to the current protection mode, in order to protect the privacy information of the storage device, change the device information of the first storage information related parameter.
[0303] FIG. 24 shows an example of changing the privacy information of the device. As shown in the example of FIG. 24, 2) is a data packet returned from the protection module to the computer device, and 3) is a status packet returned from the protection module to the computer device. Here, in the device privacy protection mode, all relevant manufacturer information strings, product information strings, product version information strings, etc. in the data packet can be changed to 00...00. Similarly, without making any changes, the protection module can feedback a data packet in which the manufacturer information string, product information string, product version information string, etc. are 00…00 to the computer device.
[0304] Referring to the enumeration steps shown in FIGS. 20a and 20b, the computer device sends a data interaction command and requests the protection module to obtain hardware feature parameters (i.e., corresponding to the first feature parameters of the storage device described above). Specifically, the hardware function parameters include, but are not limited to, hardware descriptors, interface descriptors, port descriptors, endpoint descriptors, string descriptors, etc. Based on the data information obtained in the preparation stage, the protection module executes data processing on the first feature parameters in the data information in combination with the current protection mode, obtains the second feature parameters, and returns them to the computer device. Furthermore, the computer device continues to send a data interaction command requesting the protection module to obtain the storage information related parameters of the storage device. Here, the parameters related to the storage information include, but are not limited to, the read / writeable state of the device, the maximum formatable capacity and / or the total number of formatable blocks (not shown), the last sector address, the number of bytes per single sector, the maximum number of logical units, device information (not shown), etc. Based on the data information obtained in the preparation stage, the protection module executes data processing on the first storage information related parameters in the data information in combination with the current protection mode, obtains the second storage information related parameters, and returns them to the computer device.
[0305] As shown in FIG. 20b, the enumeration stage can be further classified into a sub-stage for establishing an interface connection and a sub-stage for reading storage device information. In the sub-stage for establishing an interface connection: 1. Access control: Read the descriptor data of the storage device (i.e., the first characteristic parameter described above) according to the preset access control rules, and determine whether the preset requirements are met. If the preset requirements are met, the computer device is permitted to establish a connection with the storage device; otherwise, the computer device is prohibited from establishing a connection with the storage device. 2. Content modification: Return the modified or replaced descriptor data to the computer device according to the content modification rules (such as 3.1.1 above). In the sub-stage for reading storage device information: 1. Access control: Read the storage information data of the storage device (i.e., the storage information-related parameter described above) according to the preset access control rules, and determine whether it is satisfied. Content modification: Return the modified or replaced descriptor data to the computer device according to the content modification rules (such as 3.1.2a - 3.1.2c above). 2. Content modification: Return the modified or replaced stored information data to the computer device according to the content modification rules (such as 3.1.2a - 3.1.2c above).
[0306] Fourth stage: Data interaction stage. As shown in FIG. 20a, the computer device sends a data interaction command (such as a read command) to the protection module. The data interaction command may include a read instruction and a sector address. If the reading of the sector address is prohibited, the protection module does not send the data interaction command to the storage device. If the sector address complies with the rule (i.e., it is readable), the sector address is changed to a sector address pre-set by the rule (such as logical split disk, reading of a specific folder, etc.). The storage device returns the data (data read + status read) corresponding to the changed sector address. The protection module sends the data returned from the storage device to the computer device. Continuing to refer to FIG. 20a, the computer device sends a data interaction command (such as a write command) to the protection module. The data interaction command may include a write instruction, a sector address, and write data. If the writing of the sector address is prohibited, the protection module does not send the data interaction command to the storage device. If the sector address complies with the rule (i.e., it is writable), the sector address is changed to a sector address pre-set by the rule (such as logical split disk, writing of a specific folder, etc.). When the current protection module is in the encrypted writing mode, the data to be written needs to be encrypted and then written to the location corresponding to the changed sector address. The storage device returns a write status. The protection module sends the write status returned from the storage device to the computer device.
[0307] Figure 20b shows the data interaction stage from three aspects. Referring to the embodiment shown in Figure 2b, in the data interaction stage, in order to execute access control, it is determined whether the read / write sector address of the computer meets the pre-set requirements (such as whether the above-mentioned writing is prohibited or reading is prohibited). If the access control rule is satisfied, the computer device is permitted to read / write the sector address; otherwise, the computer device is prohibited from reading / writing the sector address. Subsequently, address mapping is executed, and according to the address mapping rule, that is, the above-mentioned sector address change rule, data of the corresponding mapped sector address of the storage device is read and written, and the read data or writing state is directly returned to the computer device. Alternatively, content change can also be executed. That is, the data of the corresponding sector address of the read / write storage device is changed according to the content change rule, and the read data or writing state is returned to the computer device.
[0308] The following shows specific examples. After the computer device establishes a connection with the storage device, the process of the computer enumerating and reading the storage device includes, but is not limited to, the following. 1. The computer device reads sector 0 of the storage device, analyzes the data of the MBR or GPT sector or the file system boot sector, and obtains the sector address of the file system partition information. 2. Read the sector address of the file system partition information and analyze the first sector address of the root directory (or called the home directory) according to the protocol of the file system. 3. Read the sector address data of the root directory according to the file system protocol. 4. Analyze the file and folder information of the sector address data of the root directory. 5. Display the list of files and folders in the root directory of the computer device.
[0309] Refer to FIGS. 28a to 28d, which respectively show examples of the access control process. FIG. 28a is a schematic diagram for controlling a "read command (single-sector read)", a sector address, a data packet, or a state as seen in the data processing process. FIG. 28b is a schematic diagram for controlling a "read command (multi-sector continuous read)", a sector address, a data packet, or a state as seen in the data processing process. FIG. 28c shows controlling a "write command (single-sector write)", a sector address, a data packet, or a state as seen in the data processing. FIG. 28d shows controlling a "write command (multi-sector continuous write)", a sector address, a data packet, or a state as seen in the data processing.
[0310] Specifically, refer to FIG. 28a. Taking the SCSI protocol as an example, a command (or command packet, CBW packet) transmitted by a computer device, where 0x28 represents a READ(10) command, indicating a request to read sector address data. The command also includes an operation sector address 00 00 00 00 and an operation sector quantity 00 01. The protection module combines the operation sector address 00 00 00 00 and the operation sector quantity 00 01. If it is determined that the read permission corresponding to the sector address in the current protection mode is read prohibited, the actual read operation is not executed, for example, in the sector restriction mode, logical split disk mode, etc. When the current protection mode of the protection module is the logical split disk mode, specific file mode, blank file mode, etc., the actual operation sector address (such as the above mapping method) is adjusted. When the current protection mode of the protection module is combined with other modes or judgments, other modes such as the decrypted read mode and abnormal judgment are triggered. As shown in FIG. 28a, when the protection module responds to a command transmitted by a computer device, it determines whether the data in the sector read by the command meets the requirements of the current protection mode, such as the file type restricted by the file type restriction mode. The protection module can be changed block by block or word by word based on the current protection mode. In this change, it is not necessary to change the original data of the sector, such as the decrypted read mode and the file type restriction mode. Furthermore, the protection module can also perform auxiliary changes to the data (or data packet, DATA packet) returned to the computer device based on other modes, such as changing the root directory address in the specific file mode. The protection module not only returns the data to the computer device but also returns a status packet (or CSW packet). Specifically, when there is no operation permission for the operation sector address, it is not necessary to return a true data packet, and the byte can be set to non-0x00 and the status packet can be directly returned. Or, return a non-true data packet, directly return the 0x00 status packet of the byte, and make the computer device recognize that the read is successful.Referring to FIG. 28b, taking the SCSI protocol as an example, the command (or command packet, CBW packet) transmitted by the computer device, 0x28 represents a READ(10) command, requesting to read sector address data. The command also includes the operation sector address 00 00 00 00 and the operation sector quantity 00 02. That is, FIG. 28b shows the control corresponding to the multi-sector continuous read command. The control process of the protection module is the same as that in FIG. 28a described above. The only difference is that in FIG. 28b, operations for each sector can be executed during the multi-sector continuous read process.
[0311] Referring to FIG. 28c, taking the SCSI protocol as an example, the command (or command packet, CBW packet) transmitted by the computer device, 0x2A represents a WRITE(10) command, requesting the reading of sector address data. In the full disk read-only mode, this command is not executed (i.e., the command becomes invalid). This command contains the operation sector address 00 00 08 D8 and the operation sector quantity 00 01. The protection module combines the operation sector address 00 00 08 D8 and the operation sector quantity 00 01. If it is determined that the write permission corresponding to the sector address in the current protection mode is write-prohibited, the actual write operation is not executed, for example, in the sector restriction mode, logical split disk mode, etc. When the current protection mode of the protection module is the logical split disk mode, specific file mode, blank file mode, etc., the actual operation sector address (such as the above mapping method) is adjusted. When the current protection mode of the protection module is combined with other modes or judgments, other modes such as the decryption read mode and abnormal judgment are triggered. As shown in FIG. 28c, when the protection module responds to the data packet (or DATA packet) transmitted by the computer device, it determines whether the data in the sector to be written meets the requirements of the current protection mode, such as the file type restricted by the file type restriction mode. The protection module can be changed block by block or word by word based on the current protection mode such as the encrypted write mode, file type restriction mode, etc. The protection module also returns a status packet (or CSW packet) to the computer device. Specifically, when there is no write operation permission for the operation sector address, there is no need to return the actual data packet. Set the byte to non-0x00 and directly return the status packet, or directly return the 0x00 status packet of the byte to make the computer recognize that the write is successful. Referring to FIG. 28d, taking the SCSI protocol as an example, the command (or command packet, CBW packet) transmitted by the computer device, 0x2A represents a WRITE(10) command, requesting the reading of sector address data.This command also includes the operation sector address 00 00 08 D8 and the number of operation sectors 00 02. That is, FIG. 28d shows the control corresponding to the multi-sector continuous write command. The control process of the protection module is the same as that in FIG. 28c described above. The only difference is that in FIG. 28d, operations for each sector can be executed during the multi-sector continuous write process.
[0312] In summary, the advantages of the technical solutions provided by each embodiment of this application are as follows. Advantage 1, regarding application scenarios It has strong versatility and can protect common removable storage devices in the market, such as USB flash drives, USB optical drives, SD adapters, SD cards, etc. The protected devices have high compatibility. It is highly feasible. For storage devices, the computer device can be protected without installing special software. It has a wide range of applications and can be widely used in devices in various scenarios, such as intranet environments, industrial control devices, printer devices, IoT devices, etc. There is no need to upgrade existing systems, software, or existing embedded devices. Many computer device scenarios can be protected using existing embedded devices or drivers attached to the operating system.
[0313] Advantage 2, regarding security The protection module adopts the hardware parameter characteristics of the access device according to the settings, and malicious programs on the computer device cannot detect the existence of the protection module and cannot restrict access to the protection module. The software of the protection module is a method that does not use the operating system or firmware, and the protection module has been elevated and cannot be tampered with or deleted. The protection method lies at the root of communication between devices, and malicious programs cannot avoid the protection measures. The protection process can be audited by logs, and all operation commands and data packets of computer devices and storage devices can be saved in the built-in storage of the protection module, enabling subsequent audits. The protection function is durable and stable. The protection is controlled based on the underlying communication protocol and is completed after the protection module is shipped, so there is no need for virus database upgrades or post-maintenance work.
[0314] Advantage 3, regarding the protection mode The protection covers a wide range including the physical layer, communication layer, and file system layer. There are multiple protection methods, which can be classified into read-only mode, write-only mode, or custom mode. The protection granularity is fine, and it can be limited to protect specific files, folders, or sector address ranges. Specific implementation methods of the protection mode: Specific implementation method: basic protection, determination of the type of access device.
[0315] After the storage device is connected to the protection module and the protection module is connected to the computer device and powered on, the protection module simulates the control transmission command of the computer device via the USB0 interface and reads the device descriptor, configuration descriptor, interface descriptor, and endpoint descriptor of the storage device. When the acquisition of the above descriptors is successful, it is judged according to the characteristics of a normal mass storage device (standard device types of storage devices such as USB flash drives and mobile optical drives). For example, the following are judged (the judgment is made based on a single condition or a combination of conditions): 1.1. Determine whether the interface type of the device is "Mass Storage Class" (USB standard protocol, mass storage device type). Specifically, determine whether the 6th byte of the interface descriptor is 0x08 (mass storage device). 1.2. Determine whether the interface subclass of the device is "SCSI transparent command set" (SCSI transfer protocol, which varies depending on the storage device). Specifically, determine whether the seventh byte of the interface descriptor is 0x06 (SCSI communication subclass). 1.3. Determine whether the interface protocol of the device is "Bulk Only Transport" (USB standard protocol, bulk transfer protocol). Specifically, determine whether the eighth byte of the interface descriptor is 0x05 (bulk transfer). 1.4. Determine whether all endpoints of the device are "Bulk" (bulk transfer protocol of the USB standard protocol). Specifically, determine whether the fourth byte of the interface descriptor is 0x02 (bulk transfer).
[0316] If the device descriptor characteristics of the mass storage device are not met, the connected "storage device" may actually be a single-function input device such as a mouse button, or a device with both mouse button functions and mass storage functions. In this case, the intermediate device terminates further communication with the storage device.
[0317] At the same time, by generating a virtual "virtual mobile disk" device in the subsequent procedure, the string drive letter name of the "abnormal device" is displayed on the OS, and the text file of the raw hardware parameter data of the read "storage device" is saved on the OS and used for analysis.
[0318] By simulating the hardware parameters and characteristics of the mobile storage device according to the device descriptor of a normal mass storage device, the data of the computer device read protection module is exactly the same as the original mobile storage device, and the computer device, due to the existence of the intermediate device, prevents malicious programs from intercepting the intermediate device.
[0319] For example, as shown in FIG. 25, when a device is connected to USB0 of the intermediate device, it is determined whether the characteristics of a normal mass storage device are satisfied. If satisfied, the hardware characteristic parameters corresponding to Scenarios 3 to 6 are directly obtained. Corresponding to Scenarios 1 to 2 of FIG. 19 above, the hardware characteristic parameters of the mass storage device are obtained. Subsequently, the USB0 device configuration descriptor template (i.e., the storage medium) incorporated in the device descriptor, the built-in manufacturer ID, device ID, string, etc. are replaced and filled. Finally, the computer device is then connected to the USB1 end. The hardware characteristic parameters for simulating the USB0 input device (i.e., the storage medium). If they do not match, the communication with the storage device or storage medium ends, and the drive letter is displayed on the computer device at the USB1 port through the disk name of "virtual disk", indicating that it is an abnormal device. The text document of the original hardware parameter data of the read "removable storage device" is saved in the root directory of the "virtual disk". The initialization of the hardware has failed.
[0320] FIG. 26a is a collation diagram of related technical points of the technical solution provided by each embodiment of the present application. FIG. 26b shows some effects brought about by adopting the technical solution provided by each embodiment of the present application.
[0321] Figure 27 shows another specific example corresponding to the split disk scenario of the storage medium. The computer device sends a data interaction command to the intermediate device. For example, it reads and sends the data at address 0, the length of the read data is 512 bytes, writes data to address 1, which is 0x1212... (512 bytes). The length of the written data is 512 bytes. The intermediate device that receives this converts the operation sector address of the data interaction command, for example, converts from address 0 to 1000, from address 1 to 1001, and operates on the sector corresponding to the converted address, such as returning the data at address 1000 to the intermediate device. Writing data to address 1001... (512 bytes). When the computer device in Scenario 1 is connected to a storage device with a protection module, the central box in Figure 27 may correspond to the protection module of the storage device. Storage device (such as USB flash drive, TF card, SD card, etc.) or storage medium (such as memory chip, storage particle, etc.).
[0322] Scenario 2 corresponds to the scenario of splitting the memory medium file. The computer device sends a data interaction command to the intermediate device. For example, read data from address 0, the size of the data to be read is 512 bytes, write data to address 1, the data to be written is (512 bytes), and the size of the data to be written is 512 bytes. The intermediate device that receives it calculates with reference to the address, the number of bytes per sector (for example, 512 bytes), and the data size, and converts the operation sector address of the data interaction command into an address corresponding to the file data. For example, it is converted into a read / write operation of the file data to U.dd. For example, address 0 is converted into the 0th sector address of the U.dd file data, address 1 is converted into the 1st sector address of the U.dd file data. After the conversion, for example, return the data of sector 0 of the U.dd file address, and write the data 0x1212... (512 bytes) to the address 1 of the U.dd file data sector, and perform operations on the U.dd file data. Similarly, when the computer device in Scenario 2 is connected to a storage device with a protection module, the central box in Figure 27 may correspond to the protection module of the storage device. Storage device (such as USB flash drive, TF card, SD card, etc.) or storage medium (such as memory chip, storage particle, etc.).
[0323] Scenario 3 corresponds to the scenario of splitting a storage medium file (network). The computer device sends read / write interaction commands to the intermediate device. For example, read data from address 0, the size of the data to be read is 512 bytes, write data to address 1, the data to be written is (512 bytes), and the size of the data to be written is 512 bytes. The intermediate device that receives this calculates with reference to the address, the number of bytes per sector (e.g., 512 bytes), and the data size, and converts the operation sector address of the data interaction command to the address corresponding to the cyber-side data (or the server side converts according to the pre-set rules according to the transferred data interaction command), for example, converts it to read / write operations on the file data of cyber-side U.dd. For example, address 0 is converted to the 0th sector address of the server-side U.dd file data, address 1 is converted to the 1st sector address of the server-side U.dd file data. After conversion, for example, return the data at address 0 of the server-side U.dd file data, and perform operations on the server-side U.dd file data such as writing data 0x1212... (512 bytes) to address 1 of the server-side U.dd file data sector. Similarly, when the computer device in Scenario 3 is connected to a storage device equipped with a protection module, the central block may correspond to a storage device with network functions.
[0324] In addition, the embodiments of the present application provide a security control framework. Through the read / write control of FIGS. 20a, 20b, 21 to 24, 28a to 28d, according to the business scenario, permission and prohibition control, editing and modification are performed on the data interaction commands, data, and states in the preparation stage, enumeration stage, and data exchange stage to achieve the purpose of control.
[0325] The security control framework is a protection module located between a computer device and a storage device, which can set various protection methods according to the needs of protection scenarios (or business scenarios) and switch them according to the actual situation. In the preparation stage, the enumeration stage, and the data interaction stage, information security protection of the computer device, the storage device, or the computer device and the storage device is realized. At the same time, the protection scenarios of the security control framework can be used alone or in combination based on the protection mode of the present invention, and new protection scenarios (protection modes) can also be created according to actual needs. Multiple protection scenarios can be used in combination at the same time, or another protection scenario can be started by a protection scenario.
[0326] It should be noted that the protection method, protection mode, and related embodiments of this application can be set and created based on the security control framework, or can exist independently according to the protection method.
[0327] In one embodiment, the security control framework includes a setting module configured to set a protection scenario, and a generation module configured to generate setting information of the protection scenario or software having the protection scenario, where one protection scenario corresponds to at least one protection mode, and by arranging the setting information or the software having the protection scenario in a hardware device, the hardware device has functions corresponding to the steps of the data security protection method described in this specification.
[0328] Furthermore, when setting a protection scenario, the setting module specifically is used to set protection scenario identification information and set a policy for protection operations corresponding to the protection scenario.
[0329] "Setting the policy of the protection operation corresponding to the protection scenario" includes setting the policy of the protection operation in the preparation stage in the protection scenario, setting the policy of the protection operation in the enumeration stage in the protection scenario, including, but not limited to, at least one or more of setting the policy of the protection operation in the data interaction stage in the protection scenario.
[0330] Furthermore, the security control framework provided by this embodiment includes a compilation module configured to execute the corresponding software compilation policy according to the setting information and obtain security control software. Here, the hardware device executes the security control software so as to have the functions corresponding to the steps of the data security protection method according to any one of the foregoing claims 1 to 44. Of course, the security control framework may not have a compilation module. The setting information of the protection scenario can be imported into a hardware device (such as a new type USB flash drive or an intermediate device shown in FIG. 2a), and the hardware device has a compilation function, executes the corresponding software compilation policy based on the setting information to generate security control software (or may generate a security control program), and implements the functions corresponding to the protection module described in the above embodiment.
[0331] Specifically, I. Setting a protection scenario The setting of the protection scenario includes the following. (1) Protection scenario information such as a name, number, binary value, etc. that is a unique identifier of the selected protection scenario; annotation information, string information, etc. used for scenario data management, etc. (2) Setting the policy of the protection operation. It includes at least one or more of the following combinations. 1. Policy in the preparation stage. The protection module reads the storage device and obtains the data required for the protection scenario by means such as extraction, analysis, and modification.
[0332] Set a data interaction command to the connected storage device in the preparation stage (equivalent to which data interaction command the protection module sends to the storage device), and it is used for data request to the storage device or data writing to the storage device. Set a judgment, modification, or response plan for matching the data returned from the storage device (corresponding to subsequent processing when the data returned from the storage device matches).
[0333] The policies in the preparation stage include, but are not limited to, data interaction command transmission policies, data interaction command execution result policies, etc. (1) Set the data interaction command transmission policy. Set at least one or more data interaction commands for simulating the control of a computer-controlled storage device. The data interaction commands include, but are not limited to, USB standard requests (acquisition of device descriptors, configuration descriptors, interface descriptors, port descriptors, string descriptor requests, etc.), class-specific requests (Bulk-Only Mass Storage Reset, Get Max LUN requests, etc.), Max LUN requests, etc., SCSI command sets and UFI command set requests (INQUIRY requests, READ FORMAT CAPACITIES requests, READ CAPACITY requests, READ(10) commands, WRITE(10) commands, etc.), and custom requests and commands, etc. (2) Set a policy that matches the execution result of the data interaction instruction. Set a byte value for identifying at least one or more specific data positions of the data returned by the execution result of the data interaction instruction, and bind the matching processing policy. The execution result data of the data interaction instruction includes, but is not limited to, the return data of USB standard requests (device descriptor, configuration descriptor, interface descriptor, port descriptor, string descriptor, etc.), the return results of class-specific requests (such as the maximum number of LUNs), SCSI command sets and UFI command set requests (total number of formatable blocks, last logical block address, number of bytes per single sector, data and status read from the sector position, status of data written to the sector position, etc.), and custom requests and commands, etc.
[0334] The processing policies are as follows. 1) Determine whether the data is valid or not. Preset the data interaction instruction rule and send it, determine the data (such as the byte value at a specific position) at at least one or more specific positions of the preset return data, execute operation A if the preset is satisfied, and execute operation B otherwise. For example, in the hardware type access protection mode (protection scenario), it can be determined by reading data such as descriptors whether the access requirements are met. If the access requirements are not met, the communication with the storage device is disconnected. When the requirements are met, an enumerable signal is sent to the computer device. 2) Data modification and storage. The preset data interaction instruction rule enables the modification and storage of data at at least one or more specific positions (such as the byte value at a specific position) of the preset return data. For example, in the data information protection mode or device privacy protection mode (protection scenario) of the storage device, descriptors and other data can be read, modified, and stored in the protection module. 3) Data extraction and analysis. Set and send data interaction instruction rules in advance, realize the context analysis of the data returned by at least one or more data interaction instructions, and extract or calculate the final value. For example, in modes (protection scenarios) such as specific file mode, file type restriction mode, manual confirmation mode, etc., by reading the data of the file system, the sector address range of the root directory or related files can be analyzed. 4) Data writing. Preset and send data interaction instruction rules, combine the results of data extraction and analysis, and write the preset data to a specific sector address. For example, in the blank file mode, in order to achieve the purpose of automatically creating a folder, the data related to the file item is written to a specific sector address space.
[0335] 2. Policy at the access stage. The computer device establishes a communication connection (computer host enumeration) with the protection module to prepare for data exchange. Set the data interaction instruction used in the match at the access stage (equivalent to which interaction instruction needs to respond), and set the judgment, change or response plan when the match result is satisfied (equivalent to how to execute the interaction instruction further when the data matches). (1) Set the matching policy of the data interaction instruction sent by the computer device. Set at least one or more byte values at specific data positions used to identify the data interaction instruction, and bind the matching processing policy. The data interaction instruction includes instruction data and data packet data, such as instruction requests and response data packets. When the data interaction instruction data is read, the byte values at at least one or more data positions are judged. When the data interaction instruction matches the matching item, the bound processing policy is executed. The determined data interaction instruction is to set a request to be sent by the computer device to establish a connection. For example, it is a USB standard request, and a data interaction instruction for obtaining a device descriptor, a configuration descriptor, an interface descriptor, a port descriptor, a string descriptor, or other custom descriptors. Specifically, for example, USB standard request data is a total of 8 bytes and is divided into five parts. JPEG2025517181000009.jpg27170According to the provisions of the USB standard request, when Request (the position of the first byte) is 0x06, the device descriptor is obtained. Therefore, it is possible to determine whether the position of the first byte is 0x06. If there is a match, a processing policy for bundling the requested device descriptor is executed. The same applies to USB standard requests (such as obtaining a device descriptor, a configuration descriptor, an interface descriptor, a port descriptor, a string descriptor) or non-standard requests (such as obtaining a customized descriptor). (2) Set the execution policy when matching the data interaction instruction, which mainly includes the following. 1) Determine whether to execute the instruction. The data interaction instruction rules are set in advance to achieve the selection of operation A or operation B. For example, when the data interaction instruction requests a device descriptor, the device descriptor data is returned, but when the data interaction instruction does not conform, no data is returned. 2) The data returns unchanged, modified, or replaced. Preset the data interaction command rules to realize the reply with the original data in the storage device, the reply with the data modified according to the preset rules, or the reply with the preset fixed replacement data. For example, in modes such as the data information protection mode (protection scenario) of the storage device, the data information protection mode, or the device privacy protection mode (protection scenario), reply with the modified or replaced descriptors and other data. In modes such as the read-only mode (protection scenario), change the read / write status information (as shown in Figure 21). In modes such as the logical split disk mode (protection scenario), change the capacity-related information (as shown in Figures 22 and 23). 4) Perform read / write operations on the storage device and storage medium. Preset the data interaction command rules to realize the preset read / write operations on the storage device. For example, when receiving a preset data interaction command (a potentially dangerous data interaction command), prioritize and execute the read / write process on the sector data of the storage device to protect the data in advance. 5) Execute the operation of triggering and starting the protection mode. Preset the data interaction command rules to realize the operation of starting the protection mode. For example, when receiving a preset data interaction command (a potentially dangerous data interaction command), start the backup mode to prevent data damage, start logging, and save the log information of the data interaction command. 6) Execute the disconnection operation of the computer device. Preset the data interaction command rules to realize the disconnection operation of the computer device. For example, when receiving a preset data interaction command (a potentially dangerous data interaction command), disconnect the connection of the computer device. 7) Operate the virtual memory medium. Set the data interaction instruction rules in advance to achieve connecting to the virtual memory medium at the data exchange stage. For example, when receiving a preset data interaction instruction (a data interaction instruction with a potential risk or a device type with prohibited connection), connect to the virtual memory medium (a memory medium for non-actual data) and respond at the subsequent data exchange stage. Here, the virtual memory medium can be a "virtual disk" equipped with relevant reminder information or a "virtual disk" in the form of an ordinary memory medium. 8) Execute triggering the selection of the data source. Set the data interaction instruction rules in advance to achieve the selection of a storage device, a storage medium, or a logical split disk. For example, when receiving a preset data interaction instruction, preset storage devices, storage media, and logical split disks are selected as the access data sources.
[0336] 3. Policies at the data interaction stage. The computer device and the protection module exchange data mainly by the computer device sending a data interaction instruction related to reading / writing to the sector address to the protection device. Set the data interaction instructions used in the matching at the data exchange stage (equivalent to responding to the interaction instructions for data reading / writing or other data exchange stages), and set the judgment, change, or response plan when the match result is satisfied (equivalent to what to do further when the data exchange instruction matches).
[0337] (1) Set the matching policy for the data interaction instructions sent by the computer device. Set the byte values of at least one or more data-specific positions (or parameters) used to identify the data interaction instructions, and bind the matching processing policy. The data interaction instruction includes instruction data such as a read instruction, a returned data packet, a returned status packet, etc., a data packet, and a status packet, a write instruction, a write data packet, and a returned data packet. The determined data interaction instruction mainly corresponds to the byte values of at least one or more specific data positions (or parameters). For example, all the data of 1) 2) 3) or 1) 2) 3) 4) in FIGS. 28a to 28d. In the case of instruction 1) (the computer device sends an instruction (instruction packet) (CBW packet)), different scenarios mainly determine the total number of transfer bytes, the transfer direction, the LUN of the operation, the command block length, the operation command code, the operation LUN, the operation sector address, and the number of operation sectors. For one or more data packets, according to different scenarios, the byte values at specific positions, or the multiple byte values or hash values in a specific data interval are determined. For the status packet, mainly the remaining number of bytes and the error code executed are determined. Referring to FIGS. 28a to 28d, FIG. 28a is a schematic diagram for controlling a "read instruction (single-sector read)", a sector address, a data packet, or a status as seen in the data processing process. FIG. 28b is a schematic diagram for controlling a "read instruction (multi-sector continuous read)", a sector address, a data packet, or a status as seen in the data processing process. FIG. 28c shows controlling a "write instruction (single-sector write)", a sector address, a data packet, or a status as seen in the data processing. FIG. 28d shows controlling a "write instruction (multi-sector continuous write)", a sector address, a data packet, or a status as seen in the data processing. The CBW, DATA, CSW, and operation instruction codes involved in the data processing process shown in FIGS. 28a to 28d above all belong to the SCSI protocol. FIG. 29 is a schematic diagram of the connection of a computer device, a protection module, and a storage device (such as a USB flash drive, a memory card, a memory chip, etc.). Regarding the connection between the protection module and the storage device, except that the interface and protocol are different, it is essentially the same as the principle of an "intermediate device or card reader". Existing devices such as USB flash drives and removable hard disks are actually just card readers with built-in memory chips. Its technical logic is to convert the SCSI commands received by the control chip into SDIO or SPI commands that can read / write the storage medium and also operate on the data of the storage medium. However, when control and storage are separated, as in the case of a USB flash drive or a card reader, the intermediate device needs to obtain the stored information in advance during the preparation stage. In the case of a USB split disk with a USB interface, it is necessary to further determine the descriptor, determine the device type of the USB split disk (a simple large-capacity storage device type), and confirm that no HID or other functions are installed. In the case of the new USB split disk of the present invention, where control + storage is integrated and the stored information is fixed in advance and does not need to be obtained during the preparation stage, in the case of the logical split disk mode, it is necessary to change the capacity information, and in the case of the specific folder read / write mode, it is necessary to read the file address.
[0338] (2) Set the execution policy when matching the data interaction instruction, mainly including the following. 1) Determine whether to execute the instruction data. Data interaction instruction rules are set in advance to realize judgments such as selecting operation A or operation B. For example, in a mode such as read-only mode (protection scenario), when the computer device sends a data interaction instruction (such as the operation instruction code being 0x2A (data write)) to write data, the protection module does not execute the write operation. For example, in a mode such as sector limit mode (protection scenario), when the sector address of the data interaction instruction sent by the computer device (calculated in combination with the number of operation sectors and can comprehensively judge multiple groups of data) is within the preset read-only / write-only limit, the protection module does not execute the corresponding operation. 2) Modify and replace the instruction data. Set the data interaction instruction rules in advance to modify or replace the instruction data and send the instruction data to the storage device. For example, in the logical split disk mode, specific file mode, and blank file mode, the operation sector address is modified according to the preset, and the sector address of the corresponding storage device is read and written. 3) Determine whether to transfer the data packet. Set the data packet rules in advance to realize judgments such as selecting operation A or operation B. For example, in file read / write restrictions, set the keyword comparison rules in advance, and the content of the data packet that matches the comparison rules can be transferred or not transferred to the computer device or storage device. 4) Modify and replace the data packet data. Set the data packet rules in advance to realize modifying or replacing the data packet data and send the data packet to the computer device or storage device. For example, in the encrypted write mode or decrypted read mode, the packet data is modified according to the preset rules and transferred to the computer device or storage device. For example, in the sector limit read / write mode, when the sector address read by the computer device does not meet the preset rules, directly return the preset replacement data packet (such as a blank data packet). 5) Determine whether to transfer the status packet. The data packet rules are set in advance to realize judgments such as selecting operation A or operation B. For example, when the status error code is not 0x00, it is determined whether to transfer the status packet to the computer device. 6) Modify or replace the status packet data. The data packet rules are set in advance to realize modifying or replacing the status packet data and sending the status packet to the computer device or the storage device. For example, in the sector restriction read / write mode, when the sector address read by the computer device does not meet the pre-set rules, the pre-set replacement status packet (such as a non-0x00 error status packet) is directly returned. 7) Read and write data to the storage device or storage medium. The judgment rules for the data interaction command are preset to realize the preset read / write operations on the storage device. For example, when a pre-set data interaction command (such as a potentially dangerous command, a data packet, or a status packet) is received, the read / write process for the sector data of the storage device is preferentially executed to protect the data in advance. 8) Execute to trigger and start the protection mode. The judgment rules for the data interaction command are set in advance to realize the operation of starting the protection mode. For example, when a pre-set data interaction command (such as a potentially dangerous command, a data packet, or a status packet) is received, the backup mode is started to prevent data damage, the log recording is started, and the log information of the data interaction command is saved. 9) Execute the disconnection operation of the computer device. The judgment rules for the data interaction command are set in advance to realize the disconnection operation of the computer device. For example, when a pre-set data interaction command (such as a potentially dangerous command, a data packet, or a status packet) is received, the connection of the computer device is disconnected. 10) Execute the operation of triggering the selection of the data source. Set in advance the determination rules for data interaction commands to realize the re-selection of the storage device, storage medium, or logical split disk. For example, when receiving a preset data interaction command (such as a potentially dangerous command, data packet, or status packet), a preset storage device, storage medium, logical split disk, or virtual storage medium (a storage medium for non-actual data) is re-selected, the device is disconnected, and re-listed as the access data source.
[0339] II. Generate the setting information for the protection scenario or the software having the protection scenario The protection scenario information and protection operation policy for the above settings: On the one hand, the setting information can be generated. Generate and export the setting information, and share it through data transmission (network transmission, point-to-point transmission, copy-to-copy, etc.). The setting information can be further changed according to different usage scenarios. The setting information can be imported into the security control framework software or the hardware device of the security control framework, and the security control framework executes the corresponding security control policy.
[0340] On the other hand, the software (or firmware) can be generated. In the security control framework software or hardware device, based on the setting information created by itself or imported from the outside, the corresponding software compilation policy is executed, and the protection scenario in the setting information is generated in the security control software (or firmware). By executing the security control software (or firmware) on the operating system or hardware device, the corresponding security control policy is executed.
[0341] III. Execute the security control of the protection scenario Security control software (or firmware) or security control framework software (or firmware) becomes a protection module that runs on an operating system, a hardware device, a control chip, a memory chip, or other devices.
[0342] In the preparation stage, data interaction commands are sent to the storage device according to the settings of the protection scenario.
[0343] In the enumeration stage and the data interaction stage, according to the current protection scenario (protection mode) of the protection module, rights control is executed for the data interaction commands for the data interaction between the computer device and the storage device sent by the computer device.
[0344] If the data interaction command meets the permission requirements corresponding to the current protection mode, respond to the data interaction command.
[0345] Another embodiment of the present application provides an intermediate device. The intermediate device a first port for connecting to a computer device, a second port for connecting to a storage device, a touch screen, a voice interaction device, a plurality of buttons, a slide switch, and a dialogue module equipped with at least one of the interactive controls having at least two options, a protection module connected between the first port and the second port and configured to implement the steps of the data security protection method provided by the above embodiment.
[0346] Another embodiment of the present application provides a device system including a computer device, a storage device, and the intermediate device provided by the above embodiment.
[0347] Another embodiment of the present application provides a storage device, and the storage device A first port for connecting to a computer device, A protection chip configured to perform the steps of the data security protection method provided by the above embodiment, A control chip connected to the first port via the protection chip, A memory chip connected to the control chip and configured to perform memory management on the data in the memory area under the control of the control chip.
[0348] Another embodiment of the present application provides a storage device, and the storage device includes: A first port for connecting to a computer device, A control chip in which a protection module is arranged and configured to perform the steps of the data security protection method provided by the above embodiment, A memory chip connected to the first port via the control chip and configured to perform memory management on the data in the memory area under the control of the control chip.
[0349] Still another embodiment of the present application provides a storage device. The storage device includes: A first port for connecting to a computer device, A control chip connected to the first port and configured to generate a corresponding control command based on a data interaction command transmitted by a computer device, A memory chip connected to the control chip, A protection module is arranged in the memory chip, and is configured to process the control command transmitted by the control chip by adopting the steps of the data security protection method described in the above embodiment.
[0350] Execute a data security protection method corresponding to the embodiment of the above method, and achieve the corresponding functions and technical effects. Refer to FIG. 30. FIG. 30 is a schematic diagram of the structure of the data security protection module shown in the embodiment of the present application. For the convenience of explanation, only the parts related to this embodiment are shown. The data security protection module in the embodiment of the present application is applied to a target device, and a protection module is installed in the target device. The protection module has at least one protection mode, and the protection mode is for controlling the read and write permissions to the storage device of the computer device. The device is a control unit 1301 that executes permission control on a data interaction command for data interaction between the computer device and the storage device transmitted by the computer device according to the current protection mode of the target device, and a response unit 1302 configured to respond to the data interaction command when the data interaction command meets the permission requirements corresponding to the current protection mode.
[0351] In some embodiments, the device is an identification unit that identifies the device type of the first interface when a communication connection request between the computer device and the storage device is detected, and an establishment unit that establishes a communication connection between the computer device and the storage device when the device type is a preset communication permission type.
[0352] In some embodiments, when the target device is an intermediate device equipped with a protection module, and the intermediate device is equipped with a first interface for connecting a storage device and a second interface for connecting a computer device, the device further includes a first detection unit that detects a communication connection request between the computer device and the storage device when the storage device is connected to the first interface and the computer device is connected to the second interface.
[0353] In some embodiments, the apparatus further comprises an interruption unit configured to interrupt a communication connection request when the apparatus type is a preset communication prohibited type.
[0354] In some embodiments, the establishment unit comprises a transmission subunit configured to send the target hardware feature parameters of the storage device to a computer device, where the target hardware feature parameters are for establishing a communication connection between the computer device and the storage device.
[0355] In some embodiments, specifically, the transmission subunit obtains the target hardware feature parameters corresponding to the apparatus type from a preset parameter template according to the apparatus type of the storage device, for the purpose of sending the target hardware feature parameters to the computer device.
[0356] In some embodiments, more specifically, the transmission subunit obtains the hardware feature parameters of the storage device, screens the hardware feature parameters according to a preset parameter type, determines the target hardware feature parameters corresponding to the parameter type, for the purpose of sending the target hardware feature parameters to the computer.
[0357] In some embodiments, the control unit 1301 comprises an identification subunit configured to identify the command type of the data interaction command, and a determination subunit configured to determine that the data interaction command meets the permission requirements corresponding to the current protection mode when the command type is a preset command type corresponding to the permission requirements.
[0358] In some embodiments, the protection mode is a read-only mode, and the apparatus further comprises a return unit that returns read-only parameters to the computer device in response to a parameter reading request sent from the computer device, so that the computer device can identify the storage device as a read-only device.
[0359] In some embodiments, the response unit 1302 comprises a response subunit that performs a read and write operation on a target file in the storage device in response to the data interaction command, and the read and write operation includes at least one of a read operation and a write operation.
[0360] In some embodiments, when the protection mode is full disk read-only, the response subunit is specifically to feedback third target data to the computer device in response to the data interaction command, and the first target data is the data returned by the storage device in response to the read command.
[0361] In some embodiments, when the protection mode is a specific file read-write mode, the response subunit is specifically to map the sector address of the target file, which is a file displayed on the computer device, to a target address in response to the data interaction command, and to perform a read and write operation on the target file based on the target address.
[0362] In some embodiments, the target file includes an existing specific file or preset file in the storage device, or a file automatically generated before the computer device establishes a communication connection with the storage device.
[0363] In some embodiments, when the protection mode is the position-limited read / write mode, the response subunit specifically verifies a target sector address corresponding to the data interaction command based on a preset sector address interval according to the data interaction command, and executes a read / write operation at the target sector address of the storage device when the target sector address is within the preset sector address interval.
[0364] In some embodiments, when the protection mode is the file-limited read / write mode, the response subunit specifically verifies a target file feature corresponding to the data interaction command based on preset file features according to the data interaction command, and executes a read / write operation on the target file in the storage device when the target file feature matches the preset file feature.
[0365] In some embodiments, the response subunit specifically hides the target file when the target file feature does not match the preset file feature.
[0366] In some embodiments, the preset file feature includes a first hash value corresponding to preset sector data in the file, and the response subunit specifically calculates a second hash value of the preset sector data in the target file, determines that the target file feature conforms to the preset file feature when the second hash value matches the first hash value, and determines that the target file feature does not conform to the features of the preset file when the second hash value does not match the first hash value.
[0367] In some embodiments, when the protection mode is the encrypted writing mode, specifically, the response subunit in response to the data interaction instruction, encrypts the data to be written carried by the data interaction instruction to obtain first target data, and includes the step of writing the first target data to the target file in the storage device.
[0368] In some embodiments, when the protection mode is the encrypted writing mode, specifically, the response subunit includes, in response to the data interaction instruction, feeding back second target data to the computer device, where the second target data is the data after decrypting the data returned by the storage device in response to the data interaction instruction.
[0369] In some embodiments, when the protection mode is the manual confirmation mode, specifically, the response subunit in response to the data interaction instruction, prompts the user to confirm whether to execute the data interaction instruction, and is for continuously performing read and write operations on the target file in the storage device when a confirmation instruction for executing the data interaction instruction is received.
[0370] In some embodiments, specifically, the response subunit performs anomaly verification on the read and write operation based on a preset read and write rule, and is for determining that the read and write operation is abnormal when the read and write operation does not conform to the preset read and write rule.
[0371] In some embodiments, the device further A first connection unit that connects the target sector interval to the computer device as a storage data source, the target sector interval being obtained by partitioning the storage area of the storage device, and the storage data source including the target file.
[0372] In some embodiments, the apparatus further A first reading unit that reads sector information of the storage device, and A partitioning unit that partitions the storage area of the storage device based on the sector information and obtains a plurality of sector intervals corresponding to the storage device, the target sector interval being at least one of the plurality of sector intervals.
[0373] In some embodiments, the apparatus further A second connection unit that connects an image file to the computer device as a storage data source, the image file being generated based on a preset mirroring policy.
[0374] In some embodiments, the storage device is a network storage device, the network storage device is connected to the server side, and the server side includes a plurality of network image files as shown in FIG. 16. The apparatus further A third connection unit that connects a target network image file to the computer device as a storage data source, the target network image file being at least one of the plurality of network image files, and the storage data source including the target file.
[0375] The apparatus further An authentication unit that connects a target storage data source corresponding to the command type of the authentication command to the computer device in response to an authentication command input by a user, the target storage data source being at least one of a sector interval, an image file, and a network image file.
[0376] In some embodiments, the apparatus further comprises a second reading unit configured to read power demand information of the memory device; a setting unit configured to set a circuit current limiting protection policy for the memory device according to the power demand information, wherein the circuit protection policy is for controlling the power consumption state of the memory device.
[0377] In some embodiments, the apparatus further comprises a generating unit configured to generate an interaction log for recording a processing record of a data interaction command transmitted by the computer.
[0378] The above data security protection module can implement the data security protection method of the above embodiments. The options in the embodiments of the above method are also applicable to this embodiment, and thus will not be described in detail herein. For other contents of the embodiments of the present application, reference may be made to the contents of the embodiments of the above method, and no further description will be given in this embodiment.
[0379] FIG. 31 is a schematic diagram of the structure of a target device shown in an embodiment of the present application. As shown in FIG. 31, the target device 14 in this embodiment includes at least one processor 140 (only one processor is shown in FIG. 14), a memory 141, and a computer program 142 stored in the memory 141 and executable by the at least one processor 140. When the processor 140 executes the computer program 142, any of the steps of the above method embodiments is implemented.
[0380] The target device 14 may be an intermediate device or a storage device equipped with a protection module. The target device includes a processor 140 and a memory 141, but is not limited thereto. Those skilled in the art will understand that FIG. 31 is merely an example of the target device 14 and does not constitute a limitation on the target device 14, and it may include more or fewer components than those shown in the figure, or a specific combination of components, or different components. For example, it may be equipped with input / output devices, network access devices, etc.
[0381] The processor 140 may be a central processing unit (CPU), or other general-purpose processors, digital signal processors (DSPs), application specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs) or other programmable logic devices, discrete gates or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor, or the processor may be any conventional processor, etc.
[0382] In some embodiments, the memory 141 may be an internal storage unit of the target device 14, such as the hard disk or memory of the target device 14. In other embodiments, the memory 141 may be an external storage device of the target device 14, such as a plug-in hard disk installed in the target device 14, a Smart Media (registered trademark) Card (SMC), a Secure Digital (SD) card, a Flash Card, etc. Further, the memory 141 may include both the internal storage unit and the external storage device of the target device 14. The memory 141 is used to store an operating system, application programs, a BootLoader, data, and other programs such as the program code of the computer program. The memory 141 is also for temporarily storing the output or to-be-output data.
[0383] Also, an embodiment of the present application also provides a computer-readable storage medium storing a computer program, and when the computer program is executed by a processor, the steps of any of the above method embodiments are implemented.
[0384] The present application provides a computer program product, and when the computer program product is executed on a target device, the target device is caused to execute the steps of the data security protection method of each of the above embodiments.
[0385] In some embodiments provided by the present application, each box in the flowchart or block diagram can represent a module, a program segment, or a part of code, and it can be understood that the module, the program segment, or the part of code includes executable instructions for implementing one or more specified logical functions. Also, it should be noted that in some alternative implementations, the functions shown within the blocks may be executed in an order different from the order shown in the figures. For example, two consecutive blocks may actually be executed substantially in parallel in some cases, or in the reverse order depending on the relevant functions.
[0386] When the functions are implemented in the form of software functional modules and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of the present disclosure, in essence, or the part that contributes to the prior art or the part of the technical solution can be embodied in the form of a software product. The computer software product includes several instructions stored in the storage medium for causing the target device to execute the methods described in each embodiment of the present disclosure. The aforementioned storage medium includes flash disks, mobile hard disks, read-only memories (ROM), random access memories (RAM), magnetic disks (such as hard disks, SD cards, TF cards) or optical disks, and other media capable of storing program code.
[0387] The above specific embodiments further elaborate on the object, technical solution, and beneficial effects of the present application. However, it should be understood that the above are merely specific embodiments of the present application and are not intended to limit the protection scope of the present invention. It is particularly pointed out that for those skilled in the art, any modifications, equivalent substitutions, improvements, etc. made within the spirit and principle of the present application shall be included in the protection scope of the present application.
Claims
1. A data security protection method applied to a protection module, wherein the protection module is installed in a target device, the target device is a storage device or an intermediate device, and the intermediate device connects a computer device and the storage device, and the method is In response to a capacity read command from the computer device, the split disk capacity parameter of the target split disk in the storage device is transmitted to the computer device, causing the computer device to identify only the target split disk. In response to a data interaction command transmitted by the computer device, the operation address corresponding to the data interaction command is changed to the corresponding target sector address within the split disk capacity parameter of the target split disk. A data security protection method comprising reading and writing data according to the target sector address, wherein the target split disk is a split disk selected based on the target device, or a split disk selected based on another device communicating with the target device.
2. Before transmitting the split disk capacity parameter of the target split disk in the storage device to the computer device in response to a sector read command from the computer device, the method further The user selects one split disk as the target split disk in response to a selection operation via an interactive device in the target device, or In response to a split disk selection command transmitted by a designated device, which is a different device from the computer device, that communicates with the protection module via short-range wireless communication or telecommunications, the split disk indicated by the split disk selection command is designated as the target split disk, or In response to a split disk selection command transmitted by the computer device, the split disk indicated by the split disk selection command is designated as the target split disk, or The data security protection method according to claim 1, characterized in that, in response to a verification command transmitted by the computer device, the split disk corresponding to the password information in the verification command is set as the target split disk.
3. The data security protection method according to Claim 1, characterized in that the sector addresses of the target split disk and other split disks in the storage device do not overlap.
4. Before transmitting the split disk capacity parameter of the target split disk in the storage device to the computer device in response to a sector read command from the computer device, the method further The data security protection method according to claim 1, characterized in that, based on a preset split disk policy, the sector address interval of the storage device is divided to obtain a plurality of split disks, the split disk is one of the plurality of split disks, and the preset split disk policy includes a preset number of split disks or a preset split disk address.
5. Dividing the sector address interval of the storage device and obtaining multiple split disks based on a preset number of split disks is: Read basic information of the storage space of the storage device, including the total number of sectors and the number of bytes in each sector; partition the sector address interval based on the preset split disk policy and the basic information; obtain multiple split disks; or The data security protection method according to claim 4, comprising generating at least one image file in the storage space of the storage device, partitioning the storage space of the storage device at address intervals corresponding to each of the image files, and obtaining a plurality of split disks, wherein the storage space includes one or more of the local storage space based on the storage device and the storage space based on the storage space connected to the protection module via a network.
6. The data security protection method according to Claim 1, wherein the data interaction command is a command based on the SCSI transfer protocol or the UFI command block protocol, and the command parameters of the data interaction command include a command read / write type, or a command read / write address, or the read / write status of the storage device, or the total number of formattable blocks, or the last logical block address, or the number of bytes in a single sector, or the maximum number of logical units, or device information.
7. The method further The data security protection method according to claim 1, comprising transmitting target hardware feature parameters to the computer device in response to a hardware feature parameter request command transmitted by the computer device, wherein the hardware feature parameters include a vendor identifier or device identifier or device attribute or class used by an interface or endpoint attribute or transfer rate or power demand or other hardware feature parameters represented by a string other than the above hardware feature parameters, and different split disks have different hardware feature parameters.
8. The method further The data security protection method according to claim 1, characterized in that, in response to a sector read / write command corresponding to a target file transmitted by the computer device, the operation address corresponding to the sector read / write command is changed to a target sector address corresponding to the target file in the split disk capacity parameter, and data is read or written according to the target sector address.
9. Changing the operation address corresponding to the data interaction command in response to a data interaction command transmitted by the computer device to the corresponding target sector address in the split disk capacity parameter of the target split disk means: In response to a data interaction command transmitted by the computer device, it is determined whether the operation address corresponding to the data interaction command conforms to the access control rules. The data security protection method according to claim 1, characterized in that, if the operation address corresponding to the data interaction command conforms to an access control rule, the operation address is changed to a target sector address on the target split disk.
10. Reading and writing data according to the target sector address is: Transferring the data interaction command after changing the operation address to the target sector address to the storage device, receiving the data corresponding to the target sector address returned from the storage device, and returning the read data, read status, or write status to the computer device, or The data security protection method according to claim 1, characterized in that it includes transferring a data interaction command after changing the operation address to a target sector address to the storage device, receiving data corresponding to the target sector address returned from the storage device, modifying the data corresponding to the target sector address in accordance with the content modification rules, and returning the read data, read status, or write status to the computer device.
11. The method further In read-only mode, if the data interaction command is a parameter read request, the read-only status parameter of the storage device is returned to the computer device; however, if the data interaction command is a write command, the device does not respond to the data interaction command, or In a specific file mode, the data interaction command is a command for at least one specific file in the storage device, and the operation type of the command is read type, write type, or read-write type, or In blank file mode, the data interaction command is a command for at least one blank file that is automatically and / or manually created in the storage device, and the operation type of the command is write type or read-write type, or In sector-limited mode, the data interaction command is a command for at least one specific sector interval in the storage device, and the operation type of the command is read type, write type, or read-write type, or In file type restricted mode, the data interaction command is a command for at least one specific type of file in the storage device, and the operation type of the command is read type, write type, or read-write type, or In encrypted write mode, the data interaction command is a command for data in at least one first sector interval in the storage device, at least one first file, and / or at least one type of file, and the operation type of the command is a write type, or In decoded read mode, the data interaction command is a command for data in at least one second sector interval in the storage device, at least one second file, and / or at least one type of file, and the operation type of the command is read type, or In manual verification mode, the data interaction command is a command for data in at least one third sector interval in the storage device, at least one third file, and / or at least one type of file, and the operation type of the command is read / write, or The data security protection method according to claim 1, characterized in that, in logical split disk mode, the data interaction command is a command for at least one split disk in the storage device, and the operation type of the command is read type, write type, or read-write type.
12. A data security protection method applied to a server side, wherein the server side is communicatively connected to a target device on which a protection module is installed, the target device is a network storage device or an intermediate device, the intermediate device is communicatively connected to a computer device, and the method is In response to a capacity read request transmitted by the target device, the server transmits the split disk capacity parameter of the target split disk to the target device, the split disk capacity parameter is for the target device to return the split disk capacity parameter to the computer device in response to a capacity read command transmitted by the computer device, the target split disk is a split disk selected based on the target device or a split disk selected based on another device communicating with the target device, and is intended to cause the computer device to identify only the split disk, A data security protection method characterized by performing read and write operations to the target sector address in response to a data interaction command transferred by the target device, wherein the target sector address is obtained by the target device changing the operation address corresponding to the data interaction command, based on the data interaction command transmitted by the computer device, to the corresponding target sector address in the split disk capacity parameter of the target split disk.
13. Before transmitting the split disk capacity parameter of the target split disk on the server side to the target device, the method further The data security protection method according to claim 12, characterized in that all split disks corresponding to the target device are determined according to the identification information of the target device, and all of the split disks are for the target device or other device communicating with the target device to select the target split disk.
14. An intermediate device, A first port for connecting to a computer device, A second port for connecting to a storage device, An intermediate device comprising a protection module connected between the first port and the second port and configured to perform a step of the data security protection method described in any one of claims 1 to 11.
15. The intermediate device further The intermediate device according to claim 14, comprising a communication assembly, the communication assembly being connected to a protection module and used for networking, for connecting the protection module to a cloud-side or server-side storage module, and transmitting the data interaction command to the network-side storage module in response to the data interaction command, such that the storage module reads and / or writes the corresponding data based on the data interaction command.
16. A device system, Computer equipment and Memory device and An apparatus system characterized by comprising the intermediate device described in claim 14.
17. A storage device, A first port for connecting to a computer device, A protection chip configured to perform the steps of the data security protection method described in any one of claims 1 to 11, A control chip connected to the first port via the protection chip, A storage device characterized by comprising a memory chip connected to the control chip and configured to perform storage management for data in a storage area under the control of the control chip.
18. A storage device, A first port for connecting to a computer device, A control chip having a protection module positioned and configured to perform the steps of the data security protection method described in any one of claims 1 to 11, A storage device characterized by comprising a memory chip connected to the first port via the control chip and configured to perform storage management for data in the storage area under the control of the control chip.
19. A storage device, A first port for connecting to a computer device, A control chip connected to the first port and configured to generate corresponding control commands based on data interaction commands transmitted by a computer device, The control chip is connected to a memory chip, A storage device characterized in that a protection module is disposed on the memory chip and is configured to process control commands transmitted by the control chip by employing the steps of the data security protection method described in any one of claims 1 to 11.
20. A server device, A first port configured to connect to a target device which is a network storage device or intermediate device, A control chip connected to the first port and configured to generate corresponding control commands based on data interaction commands transmitted by the target device, The control chip is connected to a memory chip, The server device is characterized in that the memory chip is configured to process control commands transmitted by the control chip by employing the steps of the data security protection method described in claim 12 or 13.
21. A computer-readable storage medium in which a computer program is stored, wherein when the computer program is executed by a processor, the steps of the data security protection method described in any one of claims 1 to 13 are performed.