Quantum cryptography device-based method and system for file system stream encryption and decryption

The symmetric encryption key is generated through quantum cipher devices and the key and ciphertext separation is realized at the user's file system layer, which solves the ease of encryption and decryption of the file system layer in the linux operating system and improves the security and compatibility of the file system.

WO2025145558A1PCT designated stage expired Publication Date: 2025-07-10CHINA TELECOM QUANTUM TECH CO LTD
View PDF 7 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2024/107356
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-01-03
Filing Date
2024-07-24
Publication Date
2025-07-10

AI Technical Summary

Technical Problem

The file system layer in the Linux operating system lacks a high-security encryption and decryption solution, and its ease of use and compatibility are insufficient, and there is a risk of reverse cracking of key management. Traditional encryption and decryption are mostly implemented in the kernel layer and can easily lead to operating system crashes.

Method used

The file system stream encryption and decryption method based on quantum cryptographic devices is adopted to generate symmetric encryption keys through quantum cryptographic devices to realize the separation of keys and ciphertexts, and a key is generated using quantum random number entropy sources, which only operates at the user file system layer to avoid kernel dependence.

Benefits of technology

Improves the security strength and ease of use of file encryption, reduces the risk of reverse cracking, improves file system compatibility and performance, and reduces dependence on the operating system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2024107356_10072025_PF_FP_ABST
    Figure CN2024107356_10072025_PF_FP_ABST
Patent Text Reader

Abstract

Disclosed in the present application are a quantum cryptography device-based method and system for file system stream encryption and decryption. The method comprises: receiving a file access operation request; according to the inode value of a target file, obtaining an index number corresponding to the target file from a quantum cryptography device; transmitting the target file and the corresponding index number to the quantum cryptography device, so that the quantum cryptography device queries a stream key block table on the basis of the index number to obtain a keystream or queries key values on the basis of the index number to obtain an encryption key; and receiving a file operation result returned by the quantum cryptography device, wherein the file operation result is obtained by means of the quantum cryptography device performing an encryption operation or a decryption operation on the target file on the basis of the keystream or the encryption key. The present application implements stronger file encryption protection and improves anti-cracking capability.
Need to check novelty before this filing date? Find Prior Art

Description

File system stream encryption and decryption method and system based on quantum cryptography equipment

[0001] CROSS-REFERENCE TO RELATED APPLICATIONS

[0002] This application claims priority to Chinese patent application number 202410004791.9, filed with the Patent Office of China on January 3, 2024, entitled “File system stream encryption and decryption method and system based on quantum cryptographic equipment”, the entire contents of which are incorporated by reference into this application. Technical Field

[0003] The present application relates to the technical fields of cryptographic applications and computer file systems, and in particular to a file system stream encryption and decryption method and system based on quantum cryptographic equipment. Background Art

[0004] A file system is a method for storing and organizing computer data. It allows users to read and write data without having to physically manipulate storage devices or media. Data management is abstracted to "file" management. In Unix-like operating systems, the kernel identifies files by inode (index node) number rather than by file name. Each file has a unique inode number and is stored on a disk partition along with its contents.

[0005] An Encrypting File System (EFS) is a file system that encrypts file data before writing it to disk, preventing sensitive information from being leaked. Encryption and decryption are performed both when writing and reading data, ensuring that only authorized users can access the plaintext data. EFS technology is commonly used on enterprise computers and servers to prevent unauthorized access to sensitive data.

[0006] A stream cipher, also known as a stream encryption, is a symmetric encryption algorithm. Both encryption and decryption use the same random encrypted data stream as the key. Plaintext data is encrypted sequentially with the key data stream, resulting in a ciphertext data stream. In practice, data is typically encrypted bit by bit using the exclusive-or (XOR) operation. In cryptography, if the randomness of the stream key is guaranteed, a stream cipher can be considered a highly secure symmetric encryption algorithm.

[0007] In the related technology, the patent application document with publication number CN116361749A implements quantum cryptography application for executable files, and the patent application document with publication number CN115842654A implements storage encryption and transmission encryption for independent files, but neither of them is a quantum encryption and decryption application for the file system layer in the Linux operating system.

[0008] Traditional file system encryption technology focuses on encrypting and decrypting data on physical storage media, but lacks consideration for the secure design of key management. File system compatibility, usability, ease of use, and security strength also suffer from varying degrees of deficiencies, as summarized below:

[0009] (1) Encryption and decryption are mostly implemented in the kernel layer. Problems in the calling process can cause the operating system to crash and affect other user software.

[0010] (2) The protected file and the key are placed in the same piece of data, which increases the risk of reverse cracking.

[0011] (3) It relies solely on software implementation and does not introduce cryptographic components with higher security levels into the design of encryption, decryption, and key management.

[0012] (4) The encrypted storage area is protected only by the user password.

[0013] Summary of the Invention

[0014] The technical problem to be solved by this application is how to provide an easy-to-use and secure file data encryption solution.

[0015] This application solves the above technical problems through the following technical means:

[0016] In a first aspect, the present application proposes a file system stream encryption and decryption method based on a quantum cryptography device, which is applied to a user host. The method includes:

[0017] Receive a file access operation request, wherein the file access operation request carries an inode value of a target file;

[0018] Obtain the index number corresponding to the target file from the quantum cryptography device according to the inode value of the target file;

[0019] Passing the target file and the corresponding index number to the quantum cryptography device, so that the quantum cryptography device queries the stream key block table based on the index number to obtain the key stream or queries the key value based on the index number to obtain the encryption key;

[0020] Receive a file operation result returned by the quantum cryptography device, where the file operation result is obtained by the quantum cryptography device performing an encryption operation or a decryption operation on the target file based on the key stream or the encryption key.

[0021] In the second aspect, the present application proposes a file system stream encryption and decryption method based on a quantum cryptographic device, which receives the inode value of the target file sent by the user host;

[0022] Query the index number corresponding to the inode value of the target file in the index table area and return it to the user host;

[0023] Receiving the content and index number of the target file sent by the user host, and querying the stream key block table based on the index number to obtain the key stream or querying the key value based on the index number to obtain the encryption key;

[0024] The key stream or the encryption key is used to perform an encryption operation or a decryption operation on the content of the target file, and a file operation result is obtained and returned to the user host.

[0025] In a third aspect, the present application proposes a user host, in which a user file system runs. The user file system creates a daemon process, a file node query module, and a quantum encryption and decryption interface, wherein:

[0026] The daemon process is used to receive a file access operation request, wherein the file access operation request carries an inode value of a target file;

[0027] The file node query module is used to obtain the index number corresponding to the target file from the quantum cryptography device according to the inode value of the target file, and send the inode value, index number and file access operation request of the target file to the quantum encryption and decryption interface;

[0028] The quantum encryption and decryption interface is used to parse the file access operation request and pass the content of the target file and the corresponding index number to the quantum cryptography device, so that the quantum cryptography device queries the stream key block table based on the index number to obtain the key stream or queries the key value based on the index number to obtain the encryption key;

[0029] The daemon process is further configured to receive a file operation result returned by the quantum cryptography device, where the file operation result is obtained by the quantum cryptography device performing an encryption operation or a decryption operation on the target file based on the key stream or the encryption key.

[0030] In a fourth aspect, the present application proposes a quantum cryptography device, wherein a main controller and a secure storage area are provided in the quantum cryptography device, an index table area is provided in the secure storage, and the main controller includes:

[0031] An index number query module is used to receive the inode value of the target file sent by the user host, query the index number corresponding to the inode value of the target file in the index table area, and return it to the user host;

[0032] A key query module is configured to receive the content and index number of the target file sent by the user host, and query the stream key block table based on the index number to obtain the key stream or query the key value based on the index number to obtain the encryption key;

[0033] The encryption / decryption operation module is used to use the key stream or the encryption key to perform encryption operation or decryption operation on the content of the target file, obtain a file operation result and return it to the user host.

[0034] In a fifth aspect, the present application proposes a file system stream encryption and decryption system based on a quantum cryptographic device, the system comprising a user host and a quantum cryptographic device, wherein a user file system runs on the user host, the quantum cryptographic device and a storage device are connected to the user host, the user file system is created with a daemon process, a file node query module, and a quantum encryption and decryption interface, a main controller and a secure storage area are provided in the quantum cryptographic device, an index table area is provided in the secure storage, and the main controller comprises an index number query module, a key query module, and an encryption / decryption operation module;

[0035] The daemon process is used to receive a file access operation request triggered by a user, wherein the file access operation request carries an inode value of a target file;

[0036] The file node query module is used to obtain the index number corresponding to the target file from the index number query module according to the inode value of the target file, and send the inode value, index number and file access operation request of the target file to the quantum encryption and decryption interface;

[0037] The quantum encryption and decryption interface is used to parse the file access operation request and pass the content of the target file and the corresponding index number to the key query module;

[0038] The key query module is used to query the stream key block table based on the index number to obtain the key stream or query the key value based on the index number to obtain the encryption key;

[0039] The encryption / decryption operation module is used to perform encryption operation or decryption operation on the content of the target file using the key stream or the encryption key, obtain the file operation result and return it to the daemon process.

[0040] The advantages of this application are:

[0041] (1) This application is based on quantum cryptography equipment and adopts a stream key with symmetric encryption and perfect confidentiality to achieve higher-intensity file encryption protection, or adopts an encryption key to implement symmetric encryption protection on file data, and realizes the storage separation of ciphertext, key, and user password to enhance anti-cracking capabilities.

[0042] (2) This application creates a block table structure to realize the storage and extraction of stream keys. This structure is also associated with the inode indexing method, which improves the reading and writing efficiency of the security zone files. The block table structure is only generated and stored inside the quantum cryptography device, eliminating the security threat of sensitive files being restored and cracked.

[0043] (3) It adopts the user file system mode, which is independent of the operating system kernel and has no requirements for the form of non-volatile storage media, thus improving compatibility and ease of use.

[0044] (4) The binding of storage devices and cryptographic components is realized, which improves the security protection strength. The binding of users, file systems and cryptographic devices is realized, and the risk of leaking sensitive file information is greatly reduced.

[0045] (5) The true randomness and fast random number generation of the quantum random number entropy source are fully utilized to apply stream ciphers to the field of computer file system technology. The key is generated inside the quantum random number entropy source and does not leave the secure storage area of ​​the cryptographic device, while the ciphertext is stored on the disk, realizing the separation of the key and the ciphertext.

[0046] (6) Encryption and decryption are triggered only when a single file is operated. Compared with the full encryption of disk partitions, the performance overhead is lower.

[0047] Additional aspects and advantages of the present application will be given in part in the description below, and in part will become apparent from the description below, or will be learned through practice of the present application. BRIEF DESCRIPTION OF THE DRAWINGS

[0048] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, a brief introduction will be given below to the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.

[0049] FIG1 is a flowchart of a file system stream encryption and decryption method based on a quantum cryptography device proposed in the first embodiment of the present application;

[0050] FIG2 is a flow chart of a file system stream encryption and decryption method based on a quantum cryptography device proposed in the second embodiment of the present application;

[0051] FIG3 is a schematic diagram of the structure of a user file system proposed in the third embodiment of the present application;

[0052] FIG4 is a schematic structural diagram of a quantum cryptography device proposed in the fourth embodiment of the present application;

[0053] FIG5 is a schematic diagram of the structure of the secure storage area in this application;

[0054] FIG6 is a schematic diagram of the structure of the root directory index table in this application;

[0055] FIG7 is a schematic diagram of the structure of the file index handle in this application;

[0056] FIG8 is a schematic diagram of the structure of the stream key block table in this application. Specific embodiments

[0057] To make the purpose, technical solutions, and advantages of the embodiments of this application more clear, the technical solutions in the embodiments of this application will be clearly and completely described below in conjunction with the embodiments of this application. Obviously, the described embodiments are part of the embodiments of this application, not all of the embodiments. Based on the embodiments in this application, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of this application.

[0058] Example 1

[0059] As shown in FIG1 , the first embodiment of the present application discloses a file system stream encryption and decryption method based on a quantum cryptography device, which is applied to a user host. The method includes the following steps:

[0060] S101, receiving a file access operation request, wherein the file access operation request carries an inode value of a target file;

[0061] S102, obtaining an index number corresponding to the target file from a quantum cryptography device according to the inode value of the target file;

[0062] S103, delivering the target file and the corresponding index number to the quantum cryptography device, so that the quantum cryptography device queries the stream key block table based on the index number to obtain the key stream or queries the key value based on the index number to obtain the encryption key;

[0063] S104. Receive a file operation result returned by the quantum cryptography device, where the file operation result is obtained by the quantum cryptography device performing an encryption operation or a decryption operation on the target file based on the key stream or the encryption key.

[0064] It should be noted that this embodiment runs a user file system in the user host, uses the user file system to interact with the quantum cryptography device, and based on the quantum cryptography device, adopts a stream key with symmetric encryption and perfect confidentiality to achieve higher-intensity file encryption protection, or uses an encryption key to implement symmetric encryption protection on file data, and realizes the storage separation of ciphertext, key, and user password to enhance anti-cracking capabilities.

[0065] In one embodiment, before the step S101: receiving a file access operation request, the method further includes the following steps:

[0066] S111. When a quantum cryptography device uevent (User Space Event) event is detected, inquiring about the certificate status of the quantum cryptography device;

[0067] S112: Bind the storage device when the certificate status is "no device certificate" and verify the hard disk serial number of the storage device where the user input directory is located;

[0068] S113: When the certificate status indicates that the device certificate exists, verify the hard disk serial number of the storage device where the user input directory is located.

[0069] The user file system runs in the user host, and the user file system creates a daemon process for monitoring file operation requests transmitted by the kernel, monitoring uevents of the quantum cryptography device, and processing sending and receiving requests of the quantum cryptography device.

[0070] In one embodiment, in step S112, when the certificate status is "no device certificate", binding the storage device specifically includes the following steps:

[0071] Obtain the ID of the storage device to be bound input by the user;

[0072] Get the hard disk serial number of the storage device to be bound, calculate the hash value, and import it into a temporary file;

[0073] Passing the temporary file to the quantum cryptography device so that the quantum cryptography device signs the temporary file using the device private key and saves the signature certificate in the certificate area of ​​the quantum cryptography device;

[0074] Receive the device public key returned by the quantum cryptography device.

[0075] This embodiment implements the binding of the storage device and the password component, thereby improving the security protection strength.

[0076] In one embodiment, in step S112 or S113, verifying the hard disk serial number of the storage device where the user-entered directory is located includes:

[0077] Waiting for the user to enter the protection directory path;

[0078] Obtaining a hard disk serial number of the storage device where the protected directory path is located, and sending a hash value of the hard disk serial number to the quantum cryptography device, so that the quantum cryptography device checks whether the hash value of the hard disk serial number is a registered hard disk serial number;

[0079] Receive the hard disk serial number verification result returned by the quantum cryptography device.

[0080] It should be noted that, according to the characteristics of stream ciphers, this embodiment binds the cryptographic device and the storage device together for use, and verifies the hard disk serial number of the storage medium connected to the user host.

[0081] In one embodiment, after the hard disk serial number is verified, the method further includes:

[0082] Obtaining an inode value of the file with the passed-in directory name, and passing the inode value into the quantum cryptography device, so that the quantum cryptography device queries a corresponding root directory index table based on the inode value;

[0083] When the root directory index table corresponding to the inode value exists, obtaining the authentication password entered by the user;

[0084] Passing the authentication password to the quantum cryptography device so that the quantum cryptography device calculates a hash value 1 of the authentication password and compares the hash value 1 with a hash value 2 to generate an authentication result, wherein the hash value 2 is taken by the quantum cryptography device from the root directory index table corresponding to the inode value;

[0085] When the authentication result is successful, receiving a security mode value of the directory returned by the quantum cryptography device;

[0086] When the authentication result is authentication failure, exit the process.

[0087] In one embodiment, after the hard disk serial number is verified, the method further includes:

[0088] Obtaining an inode value of the file with the passed-in directory name, and passing the inode value into the quantum cryptography device, so that the quantum cryptography device queries a corresponding root directory index table based on the inode value;

[0089] When the root directory index table corresponding to the inode value does not exist, obtaining the authentication password and security mode value entered by the user;

[0090] Passing the inode value, the authentication password, and the security mode value to the quantum cryptography device so that the quantum cryptography device calculates a hash value of the authentication password and fills the inode value, the hash value of the authentication password, and the security mode field into the created root directory index table;

[0091] Sending a mount instruction to the quantum cryptography device so that the quantum cryptography device sets a mount root directory index table lock status field;

[0092] Execute the operating system's mount process and exit the process.

[0093] This embodiment performs mount directory authentication to implement user identity verification, and only the creator of the directory is allowed to complete the mount operation.

[0094] In one embodiment, the method further comprises:

[0095] Receive a new file creation operation request, wherein the new file creation operation request carries an inode value of a new file;

[0096] Sending the inode value of the newly created file to the quantum cryptography device, so that the quantum cryptography device retrieves the inode value of the newly created file in the root directory index table, adds the inode value of the newly created file to the end of the root directory index table, creates a file index handle corresponding to the inode value of the newly created file, and adds the index number to the end of the root directory index table;

[0097] Receive the file creation operation result returned by the quantum cryptography device.

[0098] In one embodiment, the method further comprises:

[0099] Receive a file deletion operation request, wherein the file deletion operation request carries an inode value of a file to be deleted;

[0100] Sending the inode value of the to-be-deleted file to the quantum cryptography device, so that the quantum cryptography device queries the root directory index file for the index number corresponding to the inode value of the to-be-deleted file, and deleting the file index handle of the to-be-deleted file and the field where the inode value of the to-be-deleted file and the field where the index number corresponding to the inode value are located in the root directory index table;

[0101] Receiving a file deletion operation result returned by the quantum cryptography device;

[0102] Execute the local directory node number and disk file deletion operations.

[0103] Example 2

[0104] As shown in FIG2 , the second embodiment of the present application discloses a file system stream encryption and decryption method based on a quantum cryptography device, which is applied to a quantum cryptography device. The method includes the following steps:

[0105] S201, receiving the inode value of the target file sent by the user host;

[0106] S202, querying the index number corresponding to the inode value of the target file in the index table area and returning it to the user host;

[0107] S203, receiving the content and index number of the target file sent by the user host, and querying the stream key block table based on the index number to obtain the key stream or querying the key value based on the index number to obtain the encryption key;

[0108] S203: Perform encryption or decryption operations on the content of the target file using the key stream or the encryption key, obtain a file operation result, and return it to the user host.

[0109] It should be noted that this embodiment is based on quantum cryptography equipment and adopts stream keys with symmetric encryption and perfect confidentiality to achieve higher-intensity file encryption protection, or uses encryption keys to implement symmetric encryption protection on file data, and realizes the storage separation of ciphertext, keys, and user passwords to enhance anti-cracking capabilities.

[0110] In one embodiment, the quantum cryptography device is provided with a secure storage area for physically protecting key data information such as index tables, handles, and block tables, preventing direct access by the computer's CPU (Central Processing Unit) to prevent illegal read and write operations. The secure storage area includes an index table area and a key storage area. The index table area includes a root directory index table, a file index handle, and a stream key block table. Each mounted root directory corresponds to a root directory index table. The root directory index table records the inode values ​​and index values ​​of all encrypted files in the mounted root directory. The file index handle records the mapping relationship between files and stream key block tables or group key values. The stream key block table records the row and column numbers of a group of key blocks.

[0111] The key storage area includes a stream key block array and a key value. The stream key is stored in the stream key block array. The key value stores the encryption key used by the SM4 algorithm in the form of a key-value pair. Both the stream key and the encryption key are generated by a quantum random number entropy source.

[0112] This embodiment realizes the storage separation of ciphertext, key, and user password, thereby improving anti-cracking capabilities.

[0113] In one embodiment, the secure storage area further includes a certificate area, wherein the certificate area is used to store a protection key and a device certificate. Before receiving the inode value of the target file sent by the user host, the method further includes:

[0114] When the self-check determines that the secure storage area is empty, creating an empty root directory index table, an empty stream key block table, and an empty stream key block array in the secure storage area;

[0115] Calling the random number entropy source to generate random numbers and filling the random numbers into the empty stream key block array;

[0116] Initializing the certificate area, generating a device public and private key pair as a protection key, and storing the protection key in the certificate area;

[0117] Switch to monitoring mode and respond to requests from external user hosts.

[0118] In one embodiment, after the quantum cryptography device performs self-test initialization, the method further includes:

[0119] Triggering the user host to generate a quantum cryptography device uevent event so that the user host can query the certificate status of the quantum cryptography device;

[0120] When there is no device certificate, trigger the user host to bind the storage device, and then trigger the user host to verify the hard disk serial number of the storage device where the user input directory is located;

[0121] When the device certificate exists, the user host is triggered to verify the hard disk serial number of the storage device where the user input directory is located.

[0122] In one embodiment, triggering the user host to bind the storage device when there is no device certificate includes:

[0123] Receiving a temporary file sent by the user host, wherein the temporary file includes a hash value calculated based on a hard disk serial number of a bound storage device;

[0124] Use the device private key to sign the temporary file and save the signature in the certificate area;

[0125] Return the device public key to the user host.

[0126] In one embodiment, triggering the user host to verify the hard disk serial number of the storage device where the user input directory is located includes:

[0127] Receive a hash value of a hard disk serial number sent by the user host, where the hard disk serial number is the hard disk serial number of the storage device where the user input protection directory is located;

[0128] Verify whether the hash value of the hard disk serial number is the registered hard disk serial number, and return the verification result to the user host so that the user host performs the mount directory authentication or continues to wait for the user to enter the protection directory.

[0129] In one embodiment, the process of authenticating the mount directory includes:

[0130] Receive the inode value of the directory name file sent by the user host;

[0131] When the root directory index table corresponding to the inode value of the directory name file is found to exist, receiving the authentication password sent by the user host and calculating the hash value of the authentication password;

[0132] Obtain the second hash value of the password from the root directory index table corresponding to the inode value of the directory name file;

[0133] When the hash value 1 is equal to the hash value 2, the security mode value of the directory is returned to the user host, and then the root directory index table corresponding to the inode value of the file with the directory name mounted is set to a locked state field;

[0134] When hash value 1 is not equal to hash value 2, the mount directory authentication process is exited.

[0135] In one embodiment, the process of authenticating the mount directory includes:

[0136] Receive the inode value of the directory name file sent by the user host;

[0137] When the root directory index table corresponding to the inode value of the directory name file does not exist, receiving the authentication password and the security mode value sent by the user host;

[0138] Calculating the hash value of the authentication password, creating a root directory index table in the secure storage area, and filling the created root directory index table with the inode value of the directory name file, the hash value of the authentication password, and the security mode value;

[0139] Set the newly created root directory index table to the locked state field.

[0140] In one embodiment, step S203: receiving the content and index number of the target file sent by the user host, and querying the stream key block table based on the index number to obtain the key stream or querying the key value based on the index number to obtain the encryption key, includes:

[0141] Receive the plaintext or ciphertext and index number of the target file sent by the user host, and query the security mode mounted in the root directory index table;

[0142] When the security mode is strong security mode, query the stream key block table number based on the index number and obtain the key stream on the corresponding stream key block table;

[0143] When the security mode is normal mode, the encryption key is obtained by querying the key value based on the index number;

[0144] Correspondingly, the encryption operation or decryption operation on the content of the target file using the key stream or the encryption key is specifically:

[0145] The key stream or the encryption key is used to perform an encryption operation on the plaintext of the target file or to perform a decryption operation on the ciphertext of the target file.

[0146] In one embodiment, when querying the stream key block table number based on the index number, if the number of stream key blocks is insufficient, a key block filling process is triggered, including:

[0147] Query the stream key block array, obtain a free block number and add it to the stream key block table;

[0148] The block number is transmitted to a quantum random number entropy source, so that the quantum random number entropy source generates a random number and injects the random number into the stream key block corresponding to the block number.

[0149] In one embodiment, when querying a key value based on an index number to obtain an encryption key, if the key value is empty, a key filling process is triggered, including:

[0150] A key value is allocated and the key value is passed to a quantum random number entropy source so that the quantum random number entropy source generates a random number and fills the random number and the key value into the key storage area.

[0151] In one embodiment, the method further comprises:

[0152] Receive the inode value of the newly created file sent by the user host;

[0153] Check the inode value of the newly created file in the root directory index table and add the inode value of the newly created file to the end of the root directory index table;

[0154] Create a file index handle and add the index number of the file index handle to the last field of the inode value of the newly created file in the root directory index table;

[0155] The result of the file creation operation is returned to the user host.

[0156] In one embodiment, the method further comprises:

[0157] Receive the inode value of the file to be deleted sent by the user host;

[0158] Query the inode value of the file to be deleted in the root directory index table to obtain the index number after the inode value position of the file to be deleted;

[0159] Delete the file index handle corresponding to the index number;

[0160] Delete the field containing the inode value of the file to be deleted and the field following it in the root directory index table;

[0161] The file deletion operation result is returned to the user host.

[0162] Example 3

[0163] As shown in FIG3 , the third embodiment of the present application discloses a user host, in which a user file system is run. The user file system creates a daemon process 11, a file node query module 12, and a quantum encryption and decryption interface 13, wherein:

[0164] The daemon process 11 is used to receive a file access operation request, wherein the file access operation request carries the inode value of the target file;

[0165] The file node query module 12 is used to obtain the index number corresponding to the target file from the quantum cryptography device according to the inode value of the target file, and send the inode value, index number and file access operation request of the target file to the quantum encryption and decryption interface;

[0166] The quantum encryption and decryption interface 13 is used to parse the file access operation request and transmit the content of the target file and the corresponding index number to the quantum cryptography device, so that the quantum cryptography device queries the stream key block table based on the index number to obtain the key stream or queries the key value based on the index number to obtain the encryption key;

[0167] The daemon process 11 is further configured to receive a file operation result returned by the quantum cryptography device, where the file operation result is obtained by the quantum cryptography device performing an encryption operation or a decryption operation on the target file based on the key stream or the encryption key.

[0168] This embodiment is based on quantum cryptography equipment and adopts stream keys with symmetric encryption and perfect confidentiality to achieve higher-intensity file encryption protection, or adopts encryption keys to implement symmetric encryption protection on file data, and realizes the storage separation of ciphertext, keys, and user passwords to enhance anti-cracking capabilities; and adopts a user file system mode, which is independent of the operating system kernel and has no requirements for the form of non-volatile storage media, thereby improving compatibility and ease of use.

[0169] In one embodiment, the user file system further creates a virtual file system event 14, wherein:

[0170] The virtual file system event 14 is used to obtain the quantum cryptography device uevent event transmitted by the kernel and transmit it to the daemon process, and the daemon process inquires about the certificate status of the quantum cryptography device;

[0171] The daemon process 11 is used to bind the storage device when the certificate status is no device certificate and verify the hard disk serial number of the storage device where the user input directory is located; and when the certificate status is device certificate exists, verify the hard disk serial number of the storage device where the user input directory is located.

[0172] In one embodiment, the user file system further creates a quantum cryptography device authentication module 15 for detecting the legitimacy of the bound quantum cryptography device and initializing the secure storage area of ​​the quantum cryptography device.

[0173] In one embodiment, the user file system further creates a mount directory authentication module 16 for triggering a directory lookup process or a directory mapping process, so that the quantum cryptography device sets a mount root directory index table lock status field.

[0174] Furthermore, the directory lookup process includes:

[0175] When the root directory index table corresponding to the inode value exists, obtaining the authentication password entered by the user;

[0176] Passing the authentication password to the quantum cryptography device so that the quantum cryptography device calculates a hash value 1 of the authentication password and compares the hash value 1 with a hash value 2 to generate an authentication result, wherein the hash value 2 is taken by the quantum cryptography device from the root directory index table corresponding to the inode value;

[0177] When the authentication result is successful, a security mode value of the directory returned by the quantum cryptography device is received.

[0178] Furthermore, the directory mapping process includes:

[0179] When the root directory index table corresponding to the inode value does not exist, obtaining the authentication password and security mode value entered by the user;

[0180] The inode value, the authentication password, and the security mode value are transmitted to the quantum cryptography device so that the quantum cryptography device calculates a hash value of the authentication password and fills the inode value, the hash value of the authentication password, and the security mode field into the created root directory index table.

[0181] It should be noted that if the index table area needs to be newly created, the authentication password is entered directly; if the index table area already exists, the authentication password must be hashed and compared with the password saved in the existing index table area to confirm whether the user identity is correct.

[0182] Specifically, the user file system (quantum-Ecryptfs) is used to provide user-state file system services, provide encryption and decryption services for user files through the quantum cryptography service interface, and protect disk files.

[0183] User file systems are created with:

[0184] File system daemon (QEncryptfs-daemon): used to initialize various functional modules, monitor file operation requests transmitted by the kernel, monitor uevents of quantum cryptographic devices, and process sending and receiving requests of quantum cryptographic devices.

[0185] Virtual file system event (VFS-notify): used to obtain file-event passed by the kernel and pass file node information internally.

[0186] Quantum cryptography device authentication (QDev-verify): used to bind quantum cryptography devices, detect device legitimacy, and initialize the device's secure storage area.

[0187] Mount directory authentication (Mount-verify): used to mount specified directory files, authenticate user identities, and set security mode.

[0188] File node query (inode-traversal): used to obtain the file handle index in the device through the target file inode number.

[0189] Quantum encryption and decryption interface (QEncrypt): used to provide an abstract interface for quantum cryptographic devices, providing stream encryption and national secret algorithms.

[0190] This embodiment adopts a user file system mode, is independent of the operating system kernel, has no requirements on the form of non-volatile storage media, and has improved compatibility and ease of use.

[0191] It should be noted that other embodiments or implementation methods of the user host described in this application can refer to the above-mentioned method embodiment 1, which will not be repeated here.

[0192] Example 4

[0193] As shown in FIG4 , the fourth embodiment of the present application discloses a quantum cryptography device, wherein a main controller 21 and a secure storage area 22 are provided in the quantum cryptography device. The secure storage 22 is provided with an index table area. The main controller 21 includes:

[0194] An index number query module is used to receive the inode value of the target file sent by the user host, query the index number corresponding to the inode value of the target file in the index table area, and return it to the user host;

[0195] A key query module is configured to receive the content and index number of the target file sent by the user host, and query the stream key block table based on the index number to obtain the key stream or query the key value based on the index number to obtain the encryption key;

[0196] The encryption / decryption operation module is used to use the key stream or the encryption key to perform encryption operation or decryption operation on the content of the target file, obtain a file operation result and return it to the user host.

[0197] In one embodiment, as shown in Figures 5, 6, 7, and 8, the secure storage area includes an index table area and a key storage area. The index table area includes a root directory index table, a file index handle, and a stream key block table. Each mounted root directory corresponds to a root directory index table. The root directory index table records the inode values ​​and index values ​​of all encrypted files in the mounted root directory. The file index handle records the mapping relationship between files and stream key block tables or group key values. The stream key block table records the row and column numbers of a group of key blocks.

[0198] The key storage area includes a stream key block array and a key value. The stream key is stored in the stream key block array, and the key value stores the encryption key used by the SM4 algorithm in the form of a key-value pair.

[0199] Specifically, a mounted root directory corresponds to a root directory index table, which records the node numbers and internal index values ​​of all encrypted files in the mounted directory. A maximum of 32 index tables can be created.

[0200] The file index handle records the address of the mapping relationship data between the file and the key. According to the security mode, it is divided into the stream key block table number (strong security mode) or the key value (normal mode).

[0201] When the stream key block table is in strong security mode, each file index is mapped to a block table, which records the row and column numbers of a group of key blocks and supports a maximum of 8192 block tables.

[0202] The key storage area stores the stream key block array. The block array is an internal storage space with continuous addresses. The unit is block, and the block size is 4096 bytes. The array size is adjusted according to the storage specifications of the cryptographic security device. The block table addresses each block in the array by row number and column number. The blocks in the array are used to store stream keys and can only be filled by the quantum random number entropy source.

[0203] The key value is stored in the form of a key-value pair to store the SM4 algorithm key. The key can only be generated by a quantum random number entropy source.

[0204] The secure storage area also includes a certificate area for storing protection keys and device certificates.

[0205] In one embodiment, the quantum cryptography device is further provided with a quantum random number entropy source, and the stream key and the encryption key are both generated by the quantum random number entropy source.

[0206] It should be noted that the key is generated internally by the quantum random number entropy source and does not leave the secure storage area of ​​the cryptographic device, while the ciphertext is stored on the disk, realizing the separation of the key and the ciphertext.

[0207] In one embodiment, the quantum cryptography device is further provided with a national secret algorithm generator for performing encryption or decryption operations on the content of the target file according to the encryption key.

[0208] Specifically, the quantum random number entropy source is a cryptographic device that provides a highly secure, high-performance true random number source with a fast random number generation rate and can directly write to a large-capacity secure storage area.

[0209] The national secret algorithm device can provide hardware algorithm devices for the national secret algorithm SM2 / SM3 / SM4. The national secret algorithm is the national commercial encryption algorithm, and the representative algorithms are SM2 / 3 / 4 / 9, etc.

[0210] The secure storage area (TRUST ZONE) is used to store the root directory data structure, file index table, stream key block array, etc.

[0211] The main controller runs the firmware code, controls and calls other sub-modules, and provides a cryptographic service interface to the outside world.

[0212] The built-in ROM (Read-Only Memory) stores the password device firmware in read-only mode.

[0213] In one embodiment, the main controller further includes an initialization module, configured to:

[0214] When the self-check determines that the secure storage area is empty, creating an empty root directory index table, an empty stream key block table, and an empty stream key block array in the secure storage area;

[0215] Calling the random number entropy source to generate random numbers and filling the random numbers into the empty stream key block array;

[0216] Initializing the certificate area, generating a device public and private key pair as a protection key, and storing the protection key in the certificate area;

[0217] Switch to monitoring mode and respond to requests from external user hosts.

[0218] In one embodiment, the main controller further includes a device binding module, specifically configured to:

[0219] Triggering the user host to generate a quantum cryptography device uevent event so that the user host can query the certificate status of the quantum cryptography device;

[0220] When there is no device certificate, trigger the user host to bind the storage device, and then trigger the user host to verify the hard disk serial number of the storage device where the user input directory is located;

[0221] When the device certificate exists, the user host is triggered to verify the hard disk serial number of the storage device where the user input directory is located.

[0222] In one embodiment, the device binding module includes a verification unit, specifically configured to:

[0223] Receive a hash value of a hard disk serial number sent by the user host, where the hard disk serial number is the hard disk serial number of the storage device where the user input protection directory is located;

[0224] Verify whether the hash value of the hard disk serial number is the registered hard disk serial number, and return the verification result to the user host so that the user host performs the mount directory authentication or continues to wait for the user to enter the protection directory.

[0225] In one embodiment, the controller further includes a mount directory authentication module, specifically configured to:

[0226] Receive the inode value of the directory name file sent by the user host;

[0227] When the root directory index table corresponding to the inode value of the directory name file is found to exist, receiving the authentication password sent by the user host and calculating the hash value of the authentication password;

[0228] Obtain the second hash value of the password from the root directory index table corresponding to the inode value of the directory name file;

[0229] When the hash value 1 is equal to the hash value 2, the security mode value of the directory is returned to the user host, and then the root directory index table corresponding to the inode value of the file with the directory name mounted is set to a locked state field;

[0230] When hash value 1 is not equal to hash value 2, the mount directory authentication process is exited.

[0231] In one embodiment, the mount directory authentication module is specifically used to:

[0232] Receive the inode value of the directory name file sent by the user host;

[0233] When the root directory index table corresponding to the inode value of the directory name file does not exist, receiving the authentication password and the security mode value sent by the user host;

[0234] Calculating the hash value of the authentication password, creating a root directory index table in the secure storage area, and filling the created root directory index table with the inode value of the directory name file, the hash value of the authentication password, and the security mode value;

[0235] Set the newly created root directory index table to the locked state field.

[0236] It should be noted that other embodiments of the quantum cryptography device described in this application or implementation methods can refer to the above-mentioned method embodiments, which will not be repeated here.

[0237] Example 5

[0238] A fifth embodiment of the present application discloses a file system stream encryption and decryption system based on a quantum cryptographic device. The system includes a user host and a quantum cryptographic device. The user file system runs on the user host. The quantum cryptographic device and a storage device are connected to the user host. The user file system is created with a daemon process, a file node query module, and a quantum encryption and decryption interface. A main controller and a secure storage area are provided in the quantum cryptographic device. The secure storage is provided with an index table area. The main controller includes an index number query module, a key query module, and an encryption / decryption operation module.

[0239] The daemon process is used to receive a file access operation request triggered by a user, wherein the file access operation request carries an inode value of a target file;

[0240] The file node query module is used to obtain the index number corresponding to the target file from the index number query module according to the inode value of the target file, and send the inode value, index number and file access operation request of the target file to the quantum encryption and decryption interface;

[0241] The quantum encryption and decryption interface is used to parse the file access operation request and pass the content of the target file and the corresponding index number to the key query module;

[0242] The key query module is used to query the stream key block table based on the index number to obtain the key stream or query the key value based on the index number to obtain the encryption key;

[0243] The encryption / decryption operation module is used to perform encryption operation or decryption operation on the content of the target file using the key stream or the encryption key, obtain the file operation result and return it to the daemon process.

[0244] Specifically, the workflow of the file system stream encryption and decryption system based on quantum cryptography equipment is as follows:

[0245] (1) Quantum cryptography device initialization:

[0246] S1. Equipment self-test.

[0247] S2. If the secure storage area is empty, execute the initialization secure storage area sub-process:

[0248] S2-1. Initialize the index table area and create a new root directory index empty table.

[0249] S2-2. Initialize the key storage area and create a new stream key block empty table.

[0250] S2-3. Create an empty stream key block array, each block is 4096 bytes.

[0251] S2-4. The quantum cryptography device calls the random number entropy source and injects random numbers into the array block.

[0252] S2-5. Initialize the certificate area, generate a public and private key pair for the device, and store the key pair in the certificate area.

[0253] S3. The main controller switches to monitoring mode and responds to external requests.

[0254] (2) Binding and verification of storage devices:

[0255] QEncryptfs-daemon is a file system daemon (hereinafter referred to as daemon) created by the quantum-Ecryptfs user file system software. The startup process is as follows:

[0256] S1. After the host is powered on, the quantum-Ecryptfs user file system is automatically enabled and the daemon process is loaded.

[0257] S2. Insert the quantum cryptography device into the host, and the kernel passes the quantum cryptography device uevent event to the daemon process.

[0258] S3: The daemon process queries the certificate status of the cryptographic device. If there is no device certificate in the certificate area, the daemon process triggers the device binding sub-process; if there is a device certificate in the certificate area, S4 is executed.

[0259] The device binding sub-process is as follows:

[0260] S3-1. The daemon process obtains the name of the storage device to be bound input by the user.

[0261] S3-2. The daemon process obtains the SN (hard disk serial number) of the bound device and calculates the hash value, and imports it into a temporary file.

[0262] S3-3. The daemon process passes the temporary file to the cryptographic device.

[0263] S3-4. The cryptographic device signs the file using the device private key and saves the signature certificate in the certificate area.

[0264] S3-5. The cryptographic device returns the device public key to the daemon process.

[0265] S4. The daemon process blocks and waits for the user to input the protected directory path.

[0266] S5. The daemon process automatically obtains the SN number of the storage device where the directory input by the user is located.

[0267] S6. The daemon process sends the hash value of the SN to the cryptographic device.

[0268] S7. The cryptographic device checks whether the hash value is the registered SN number and returns the verification result.

[0269] S8: If the verification is successful, the daemon process executes the "mount directory authentication" process; if not, the daemon process jumps to S4.

[0270] (3) Mount directory authentication:

[0271] S1. Get the inode number of the file with the passed directory name.

[0272] S2. The inode number is passed into the quantum cryptography device to check whether the root directory index table of the inode exists. If it exists, the directory table lookup sub-process is entered; otherwise, the directory mapping sub-process is triggered.

[0273] Directory lookup process:

[0274] S1-1. The user enters the authentication password.

[0275] S1-2. Pass the password to the quantum cryptography device, and the cryptography device calculates the password hash value 1.

[0276] S1-3. The quantum cryptography device obtains the password hash value 2 from the root directory index table of the inode.

[0277] S1-4. If value 1 is not equal to value 2, the cryptographic device returns an authentication failure result and jumps to process S5; otherwise, jumps to S1-5.

[0278] S1-5. The quantum cryptography device returns the Encryp-Mode security mode value of the directory.

[0279] Directory mapping process:

[0280] S2-1. Confirm that the user enters a new authentication password and security mode.

[0281] S2-2. Pass the inode value / new password / security mode value to the quantum cryptography device, and the device calculates the password hash value.

[0282] S2-3. The device creates a root directory index table in the secure storage area and fills in the inode / password hash / security mode fields.

[0283] S3. Notify the quantum cryptography device and set the lock status field (lock mark) of the mounted inode root directory index table.

[0284] S4. Execute the operating system mounting process.

[0285] S5. Exit the process.

[0286] (4) File node query

[0287] According to the file operation type, the following process is triggered:

[0288] 4-1) Create a new file:

[0289] S1. Create a file.

[0290] S2. Get the inode information of the new file.

[0291] S3. Pass the file inode value to the quantum cryptography device.

[0292] S4. The cryptographic device checks the inode value in the root directory index table and adds the inode value to the end of the table.

[0293] S5. The cryptographic device creates a file index handle and adds the index number to the end of the table.

[0294] S6. The cryptographic device returns the operation result.

[0295] 4-2) File access operations

[0296] S1. Get the inode information of the file.

[0297] S2. Pass the file inode value to the quantum cryptography device.

[0298] S3. The quantum cryptography device queries the file inode value in the root directory index table and returns the next field (index number) of the inode's position in the table.

[0299] S4. Pass the inode, file operation code and index number to the quantum encryption and decryption interface.

[0300] 4-3) File deletion operation

[0301] S1. Get the inode information of the file.

[0302] S2. Pass the file inode value to the quantum cryptography device.

[0303] S3. The quantum cryptography device queries the file inode value in the root directory index table to obtain the index number.

[0304] S4. The quantum cryptography device deletes the file index handle of the file and releases the storage area mapped by the handle.

[0305] S5. The quantum cryptography device deletes the inode field and the next field (index number) in the root directory index table, and ensures the continuity of the root directory index table.

[0306] S6. The quantum cryptography device returns the operation result.

[0307] S7. Continue to execute the local directory node number and disk file deletion operation.

[0308] (5) Quantum encryption and decryption interface:

[0309] Parse file opcodes. Write operations trigger the encryption interface, while read operations trigger the decryption interface. Interact with the quantum cryptography device master controller (hereinafter referred to as the master controller) to complete the encryption and decryption process. Read the security mode mounted in the root directory. Strong security mode calls the key stream interface, while normal mode calls the national secret algorithm.

[0310] 5-1) Strong security mode (key stream) encryption process:

[0311] S1. Open the file through inode and get the file size.

[0312] S2. Obtain the 4096-byte plaintext file and pass the index number to the quantum cryptography device.

[0313] S3. The master controller queries the stream key block table through the index number and obtains the block number; if it finds that the number of blocks is insufficient, it triggers the key block filling process.

[0314] Key block filling sub-process:

[0315] S3-1. The master controller queries the stream key block array, obtains a free block number, and adds it to the block table.

[0316] S3-2. The master controller transmits the block number to the quantum random number entropy source.

[0317] S3-3. The quantum random number entropy source generates random numbers and injects them into the block.

[0318] S3-4. The random number entropy source returns the operation result to the main controller.

[0319] S4. The master controller reads the key stream on the block and performs an XOR operation with the 4096-byte plaintext.

[0320] S5. The master controller returns the ciphertext to the algorithm interface.

[0321] S6. Repeat S2-S5 until all sizes are processed.

[0322] S7. The operating system writes the ciphertext from the cache to the disk.

[0323] 5-2) Decryption process of strong security mode (key stream):

[0324] S1. Open the disk file through inode and obtain the file size.

[0325] S2. Pass the 4096-byte file ciphertext and index number to the quantum cryptography device.

[0326] S3. The master controller finds the stream key block table through the index number and reads the block number.

[0327] S4. The master controller reads the key stream on the block and performs an XOR operation with the incoming file content.

[0328] S5. The main controller returns the plain text to the algorithm interface.

[0329] S6. Repeat S2-S5 until all sizes are processed.

[0330] S7. The user reads the plaintext from the cache.

[0331] 5-3) Encryption process of normal mode (national secret algorithm):

[0332] S1. Open the file through inode and get the file size.

[0333] S2. Pass the 4096-byte file plaintext and index number to the quantum cryptography device.

[0334] S3. The main controller queries the key value through the index number. If the key value is found to be empty, the key filling process is triggered.

[0335] Key filling sub-process:

[0336] S3-1. The master controller assigns a key value.

[0337] S3-2. The master controller transmits the key value to the quantum random number entropy source.

[0338] S3-3. The quantum random number entropy source generates random numbers and fills them into the key storage area together with the key value.

[0339] S3-4. The random number entropy source returns the operation result to the main controller.

[0340] S4. The main controller queries the key value to obtain the encryption key and calls the national secret algorithm to encrypt the plaintext.

[0341] S5. The main controller returns the encryption result.

[0342] S6. Repeat S2-S5 until all sizes are processed.

[0343] S7. Write the file ciphertext to the disk partition.

[0344] 5-4) Decryption process of normal mode (national secret algorithm):

[0345] S1. Open the file ciphertext through inode and obtain the file size.

[0346] S2. Pass the 4096-byte ciphertext and index number to the quantum cryptography device.

[0347] S3. The main controller queries the key value through the index number.

[0348] S4. The main controller queries the key value to obtain the key and calls the national secret algorithm to decrypt the ciphertext.

[0349] S5. The master controller returns the plain text result.

[0350] S6. Repeat S2-S5 until all sizes are processed.

[0351] S7. The user reads the plaintext from the cache.

[0352] Throughout this specification, reference to terms such as "one embodiment," "some embodiments," "examples," "specific examples," or "some examples" means that a specific feature, structure, material, or characteristic described in conjunction with that embodiment or example is included in at least one embodiment or example of the present application. In this specification, schematic representations of the above terms do not necessarily refer to the same embodiment or example. Furthermore, the specific features, structures, materials, or characteristics described may be combined in any suitable manner in any one or more embodiments or examples.

[0353] Furthermore, the terms "first" and "second" are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the number of the technical features being referred to. Thus, a feature defined as "first" or "second" may explicitly or implicitly include at least one of such features. Throughout the description of this application, "plurality" means at least two, for example, two, three, etc., unless otherwise specifically defined.

[0354] Although the embodiments of the present application have been shown and described above, it can be understood that the above embodiments are exemplary and cannot be understood as limitations on the present application. Ordinary technicians in this field can change, modify, replace and modify the above embodiments within the scope of the present application.

Claims

1. A method for encrypting and decrypting a file system stream based on a quantum cryptographic device, wherein, Applied to a user host, the method includes: Receiving a file access operation request, where the file access operation request carries the inode value of the target file; Obtaining the index number corresponding to the target file from a quantum cryptography device according to the inode value of the target file; Transmitting the target file and the corresponding index number to the quantum cryptography device, so that the quantum cryptography device queries the stream key block table based on the index number to obtain a key stream or queries the key key value based on the index number to obtain an encryption key; Receiving the file operation result returned by the quantum cryptography device, where the file operation result is obtained by the quantum cryptography device performing an encryption operation or a decryption operation on the target file based on the key stream or the encryption key.

2. The file system stream encryption and decryption method based on a quantum cryptographic device according to claim 1, wherein, Before receiving the file access operation request, the method further includes: Inquiring about the certificate status of the quantum cryptography device when detecting a quantum cryptography device uevent event; Binding a storage device when the certificate status is no device certificate, and verifying the hard disk serial number of the storage device where the user input directory is located; When the certificate status is that there is a device certificate, verifying the hard disk serial number of the storage device where the user input directory is located.

3. The file system stream encryption and decryption method based on a quantum cryptographic device according to claim 2, wherein, The binding of the storage device when the certificate status is no device certificate includes: Obtaining the identifier of the storage device to be bound input by the user; Obtaining the hard disk serial number of the storage device to be bound and calculating a hash value, and importing it into a temporary file; Transmitting the temporary file to the quantum cryptography device, so that the quantum cryptography device signs the temporary file using the device private key and saves the signature certificate in the certificate area of the quantum cryptography device; Receiving the device public key returned by the quantum cryptography device.

4. The file system stream encryption and decryption method based on a quantum cryptographic device according to claim 2, wherein, The verification of the hard disk serial number of the storage device where the user input directory is located includes: Waiting for the user to input the protected directory path; Obtaining the hard disk serial number of the storage device where the protected directory path is located, and sending the hash value of the hard disk serial number to the quantum cryptography device, so that the quantum cryptography device checks whether the hash value of the hard disk serial number is the registered hard disk serial number; Receiving the hard disk serial number verification result returned by the quantum cryptography device.

5. The file system stream encryption and decryption method based on a quantum cryptographic device according to claim 2 or 4, wherein, After the verification of the hard disk serial number is passed, the method further includes: Obtaining the inode value of the incoming directory name file, and transmitting the inode value to the quantum cryptography device, so that the quantum cryptography device queries the corresponding root directory index table based on the inode value; When the root directory index table corresponding to the inode value exists, obtaining the authentication password input by the user; Transmitting the authentication password to the quantum cryptography device, so that the quantum cryptography device calculates the hash value one of the authentication password, and compares the hash value one with the hash value two to generate an authentication result, where the hash value two is taken out by the quantum cryptography device from the root directory index table corresponding to the inode value; When the authentication result is authentication success, receiving the security mode value of the directory returned by the quantum cryptography device; When the authentication result is authentication failure, exiting the process.

6. The file system stream encryption and decryption method based on a quantum cryptographic device according to claim 2 or 4, wherein, After the verification of the hard disk serial number is passed, the method further includes: Obtain the inode value of the incoming directory name file and pass the inode value to the quantum cryptographic device, so that the quantum cryptographic device queries the corresponding root directory index table based on the inode value; When the root directory index table corresponding to the inode value does not exist, obtain the authentication password and security mode value input by the user; Pass the inode value, authentication password, and security mode value to the quantum cryptographic device, so that the quantum cryptographic device calculates the hash value of the authentication password and fills the inode value, the hash value of the authentication password, and the security mode field into the created root directory index table; Send a mount instruction to the quantum cryptographic device to enable the quantum cryptographic device to set the lock status field of the mount root directory index table; Execute the mount process of the operating system and exit the process.

7. The file system stream encryption and decryption method based on a quantum cryptographic device according to claim 1, wherein, The method further includes: Receive a file creation operation request, where the file creation operation request carries the inode value of the newly created file; Send the inode value of the newly created file to the quantum cryptographic device, so that the quantum cryptographic device retrieves the inode value of the newly created file in the root directory index table, adds the inode value of the newly created file to the end of the root directory index table, creates a file index handle corresponding to the inode value of the newly created file, and adds the index number to the end of the root directory index table; Receive the file creation operation result returned by the quantum cryptographic device.

8. The file system stream encryption and decryption method based on a quantum cryptographic device according to claim 1, wherein, The method further includes: Receive a file deletion operation request, where the file deletion operation request carries the inode value of the file to be deleted; Send the inode value of the file to be deleted to the quantum cryptographic device, so that the quantum cryptographic device queries the index number corresponding to the inode value of the file to be deleted in the root directory index file, and deletes the file index handle of the file to be deleted and the fields where the inode value of the file to be deleted and the index number corresponding to the inode value are located in the root directory index table; Receive the file deletion operation result returned by the quantum cryptographic device; Execute the operation of the local directory node number and disk file deletion.

9. A file system stream encryption and decryption method based on a quantum cryptographic device, wherein, Applied to a quantum cryptographic device, the method includes: Receive the inode value of the target file sent by the user host; Query the index number corresponding to the inode value of the target file in the index table area and return it to the user host; Receive the content and index number of the target file sent by the user host, and query the stream key block table based on the index number to obtain the key stream or query the key key value based on the index number to obtain the encryption key; Use the key stream or the encryption key to perform encryption or decryption operations on the content of the target file, obtain the file operation result, and return it to the user host.

10. The file system stream encryption and decryption method based on a quantum cryptographic device according to claim 9, wherein, A secure storage area is provided in the quantum cryptography device. The secure storage area includes an index table area and a key storage area. The index table area includes a root directory index table, a file index handle, and a stream key block table. Each mounted root directory corresponds to a root directory index table. The root directory index table records the inode values and index values of all encrypted files in the mounted root directory. The file index handle records the mapping relationship between the file and the stream key block table or the group key key value. The stream key block table records the row and column numbers of a group of key blocks; The key storage area includes a stream key block array and a key key value. The stream key block array stores stream keys. The key key value stores the encryption key used by the SM4 algorithm in the form of a key-value pair. Both the stream key and the encryption key are generated by a quantum random number entropy source.

11. The file system stream encryption and decryption method based on a quantum cryptographic device according to claim 10, wherein, The secure storage area also includes a certificate area for storing the protection key and the device certificate. Before receiving the inode value of the target file sent by the user host, the method further includes: When self-checking determines that the secure storage area is empty, create an empty root directory index table, an empty stream key block table, and an empty stream key block array in the secure storage area; Call the random number entropy source to generate random numbers and fill them into the empty stream key block array; Initialize the certificate area, generate a device public-private key pair as the protection key, and store the protection key in the certificate area; Switch to the listening mode to respond to requests from external user hosts.

12. The file system stream encryption and decryption method based on a quantum cryptographic device according to claim 10, wherein, After the quantum cryptography device performs self-checking initialization, the method further includes: Trigger the user host to generate a quantum cryptography device uevent event to enable the user host to query the certificate status of the quantum cryptography device; When there is no device certificate, trigger the user host to bind the storage device, and then trigger the user host to verify the hard disk serial number of the storage device where the user input directory is located; When there is a device certificate, trigger the user host to verify the hard disk serial number of the storage device where the user input directory is located.

13. The file system stream encryption and decryption method based on a quantum cryptographic device as recited in claim 12, wherein, The triggering the user host to bind the storage device when there is no device certificate includes: Receive a temporary file sent by the user host, which imports the hash value calculated from the hard disk serial number of the bound storage device; Sign the temporary file using the device private key and save the signature in the certificate area; Return the device public key to the user host.

14. The file system stream encryption and decryption method based on a quantum cryptographic device according to claim 12, wherein, The triggering the user host to verify the hard disk serial number of the storage device where the user input directory is located includes: Receive the hash value of the hard disk serial number, where the hard disk serial number is the hard disk serial number of the storage device where the user input protected directory is located; Verify whether the hash value of the hard disk serial number is a registered hard disk serial number, and return the verification result to the user host so that the user host can perform mounted directory authentication or continue to wait for the user to input the protected directory.

15. The file system stream encryption and decryption method based on a quantum cryptographic device according to claim 14, wherein, The process of the mounted directory authentication includes: Receive the inode value of the directory name file sent by the user host; When the root directory index table corresponding to the inode value of the directory name file is found to exist, receive the authentication password sent by the user host and calculate the first hash value of the authentication password; Retrieve the second hash value of the password from the root directory index table corresponding to the inode value of the directory name file; When the first hash value is equal to the second hash value, return the security mode value of the directory to the user host, and then set the lock status field of the root directory index table corresponding to the inode value of the mounted directory name file; When the first hash value is not equal to the second hash value, exit the mount directory authentication process.

16. The file system stream encryption and decryption method based on a quantum cryptographic device according to claim 14, wherein, The process of mounting directory authentication includes: Receive the inode value of the directory name file sent by the user host; When the root directory index table corresponding to the inode value of the directory name file is not found, receive the authentication password and the security mode value sent by the user host; Calculate the hash value of the authentication password, create a root directory index table in the secure storage area, and fill in the inode value of the directory name file, the hash value of the authentication password, and the security mode value in the created root directory index table; Set the lock status field of the newly created root directory index table for mounting.

17. The file system stream encryption and decryption method based on a quantum cryptographic device according to claim 10, wherein, The receiving the content and index number of the target file sent by the user host and querying the stream key block table based on the index number to obtain the key stream or querying the key key value based on the index number to obtain the encryption key includes: Receive the plaintext or ciphertext of the target file and the index number sent by the user host, and query the mounted security mode in the root directory index table; When the security mode is the strong security mode, query the stream key block table number based on the index number and obtain the key stream on the corresponding stream key block table; When the security mode is the normal mode, query the key key value based on the index number to obtain the encryption key; Correspondingly, the encrypting or decrypting the content of the target file using the key stream or the encryption key specifically is: Encrypt the plaintext of the target file or decrypt the ciphertext of the target file using the key stream or the encryption key.

18. The file system stream encryption and decryption method based on a quantum cryptographic device as recited in claim 17, wherein, When querying the stream key block table number based on the index number, if the number of blocks of the stream key block is insufficient, trigger the key block filling process, including: Query the stream key block array, obtain an idle block number and add it to the stream key block table; Transfer the block number to the quantum random number entropy source so that the quantum random number entropy source generates a random number and fills the random number into the stream key block corresponding to the block number.

19. The file system stream encryption and decryption method based on a quantum cryptographic device according to claim 17, wherein, When querying the key key value based on the index number to obtain the encryption key, if the key key value is empty, trigger the key filling process, including: Allocate a key key value and transfer the key key value to the quantum random number entropy source so that the quantum random number entropy source generates a random number, and fill the random number and the key value into the key storage area.

20. The file system stream encryption and decryption method based on a quantum cryptographic device according to claim 10, wherein, The method further includes: Receive the inode value of the newly created file sent by the user host; Check the inode value of the newly created file in the root directory index table and add the inode value of the newly created file to the end of the root directory index table; Create a file index handle and add the index number of the file index handle to the field after the inode value of the newly created file in the root directory index table; Return the result of the file creation operation to the user host.

21. The file system stream encryption and decryption method based on a quantum cryptographic device according to claim 10, wherein, The method further includes: Receive the inode value of the file to be deleted sent by the user host; Query the inode value of the file to be deleted in the root directory index table to obtain the index number after the position of the inode value of the file to be deleted; Delete the file index handle corresponding to this index number; Delete the field where the inode value of the file to be deleted is located in the root directory index table and the field after it; Return the result of the file deletion operation to the user host.

22. A user host, wherein, A user file system runs in the user host, and the user file system creates a daemon process, a file node query module, and a quantum encryption and decryption interface, where: The daemon process is used to receive a file access operation request, and the file access operation request carries the inode value of the target file; The file node query module is used to obtain the index number corresponding to the target file from the quantum cryptographic device according to the inode value of the target file, and send the inode value, index number, and file access operation request of the target file to the quantum encryption and decryption interface; The quantum encryption and decryption interface is used to parse the file access operation request, and transfer the content of the target file and the corresponding index number to the quantum cryptographic device, so that the quantum cryptographic device queries the stream key block table based on the index number to obtain the key stream or queries the key value based on the index number to obtain the encryption key; The daemon process is further used to receive the file operation result returned by the quantum cryptographic device, and the file operation result is obtained by the quantum cryptographic device performing an encryption operation or a decryption operation on the target file based on the key stream or the encryption key.

23. The user host according to claim 22, wherein, The user file system also creates a virtual file system event, where: The virtual file system event is used to obtain the quantum cryptographic device uevent event passed by the kernel and transfer it to the daemon process, and the daemon process inquires about the certificate status of the quantum cryptographic device; The daemon process is used to bind the storage device when the certificate status is no device certificate, and verify the hard disk serial number of the storage device where the user input directory is located; and when the certificate status is the existence of a device certificate, verify the hard disk serial number of the storage device where the user input directory is located.

24. The user host according to claim 22, wherein, The user file system also creates a quantum cryptographic device authentication module, which is used to detect the legality of the bound quantum cryptographic device and initialize the secure storage area of the quantum cryptographic device.

25. The user host according to claim 22, wherein, The user file system also creates a mounted directory authentication module, which is used to trigger a directory lookup process or a directory mapping process, so that the quantum cryptographic device sets the locked state field of the mounted root directory index table.

26. A quantum cryptographic device, wherein, A main controller and a secure storage area are set in the quantum cryptographic device, and an index table area is set in the secure storage. The main controller includes: The index number query module is used to receive the inode value of the target file sent by the user host, query the index number corresponding to the inode value of the target file in the index table area, and return it to the user host; The key query module is used to receive the content and index number of the target file sent by the user host, and query the stream key block table based on the index number to obtain the key stream or query the encryption key based on the index number to obtain the encryption key; The encryption / decryption operation module is used to perform encryption operation or decryption operation on the content of the target file by using the key stream or the encryption key, obtain the file operation result, and return it to the user host.

27. The quantum cryptographic device according to claim 26, wherein, The secure storage area includes an index table area and a key storage area. The index table area includes a root directory index table, a file index handle, and a stream key block table. Each mounted root directory corresponds to a root directory index table. The root directory index table records the inode values and index values of all encrypted files in the mounted root directory. The file index handle records the mapping relationship between the file and the stream key block table or the grouped key key value. The stream key block table records the row and column numbers of a group of key blocks; The key storage area includes a stream key block array and a key key value. The stream key is stored in the stream key block array. The key key value stores the encryption key used by the SM4 algorithm in the form of a key-value pair.

28. The quantum cryptographic device according to claim 27, wherein, A quantum random number entropy source is also set in the quantum cryptography device. Both the stream key and the encryption key are generated by the quantum random number entropy source.

29. The quantum cryptographic device according to claim 27, wherein, A national cryptography algorithm device is also set in the quantum cryptography device, which is used to perform encryption or decryption operation on the content of the target file according to the encryption key.

30. A file system stream encryption and decryption system based on a quantum cryptographic device, wherein, The system includes a user host and a quantum cryptography device. The user file system runs in the user host. The quantum cryptography device and the storage device are connected to the user host. The user file system creates a daemon process, a file node query module, and a quantum encryption / decryption interface. A main controller and a secure storage area are set in the quantum cryptography device. An index table area is set in the secure storage. The main controller includes an index number query module, a key query module, and an encryption / decryption operation module; The daemon process is used to receive the file access operation request triggered by the user, and the file access operation request carries the inode value of the target file; The file node query module is used to obtain the index number corresponding to the target file from the index number query module according to the inode value of the target file, and send the inode value, index number, and file access operation request of the target file to the quantum encryption / decryption interface; The quantum encryption / decryption interface is used to parse the file access operation request, and transfer the content and corresponding index number of the target file to the key query module; The key query module is used to query the stream key block table based on the index number to obtain the key stream or query the encryption key based on the index number to obtain the encryption key; The encryption / decryption operation module is used to perform encryption operation or decryption operation on the content of the target file by using the key stream or the encryption key, obtain the file operation result, and return it to the daemon process.

Citation Information

Patent Citations

  • File encryption method and device based on quantum key, electronic equipment and medium

    CN114448633A

  • Quantum privacy query method and system based on quantum homomorphic encryption

    CN116244732A

  • Software packing method and unpacking method based on quantum random number entropy source

    CN116361749A

  • Electrical operation data processing method, device, equipment, medium and program product

    CN116842204A

  • File system stream encryption and decryption method and system based on quantum cryptography equipment

    CN117521149A