Data processing method and apparatus, electronic device, and storage medium
By marking the physical page in flash memory as invalid status and updating the invalid information record table, and then physically erasing the data blocks, the leakage problem caused by incomplete data deletion in flash memory media is solved, and data security and privacy protection are achieved.
Patent Information
- Application Number
- PCT/CN2024/143750
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-01-04
- Filing Date
- 2024-12-30
- Publication Date
- 2025-07-10
AI Technical Summary
In the prior art, flash memory-based storage media can still be read by others through special means after user data is deleted, resulting in a higher risk of user data leakage.
By receiving a data deletion request, mark the physical page as an invalid state and update the invalid information record table, and then physically erase the corresponding physical blocks to ensure that the data cannot be restored.
It effectively reduces the risk of user data leakage, improves data security, and ensures that data cannot be restored after data is deleted.
Smart Images

Figure CN2024143750_10072025_PF_FP_ABST
Abstract
Description
Data processing method, device, electronic device and storage medium
[0001] CROSS-REFERENCE TO RELATED APPLICATIONS
[0002] This application claims priority to Chinese patent application No. 202410017250.X, filed on January 4, 2024, entitled “Data processing method, device, electronic device and storage medium,” and the entire contents of that application are incorporated herein by reference. Technical Field
[0003] The embodiments of the present application relate to the field of secure storage technology, and in particular to a data processing method, device, electronic device, and storage medium. Background Art
[0004] With the rapid development of storage technology, more and more terminal devices are equipped with storage media based on Flash Memory. Users can use the terminal devices to conveniently operate data in the storage media, such as data storage, data deletion, etc.
[0005] However, due to the inherent storage characteristics of flash memory, when a user needs to delete user data, the terminal device's deletion operation only cancels the association between the user data's logical address and physical address. Therefore, if the user's terminal device is obtained by someone else, they can still read the user data in the flash memory through special means, resulting in user data leakage. Therefore, how to improve the security of user data is an urgent problem to be solved. Summary of the Invention
[0006] The purpose of the embodiments of the present application is to provide a data processing method, device, electronic device and readable storage medium, which can improve the security of user data and effectively reduce the risk of user data leakage.
[0007] In a first aspect, an embodiment of the present application provides a data processing method, the method comprising:
[0008] receiving a data deletion request, where the data deletion request includes a first logical address of the first data;
[0009] In response to a data deletion request, marking the state of each physical page included in the first physical block as invalid, updating the number of invalid physical pages of the first physical block in the invalid information recording table, and physically erasing the data stored in the first physical block;
[0010] The first physical block is a physical block corresponding to the first physical address mapped by the first logical address.
[0011] In a second aspect, an embodiment of the present application provides a data processing device, the device comprising:
[0012] A receiving module, configured to receive a data deletion request, where the data deletion request includes a first logical address of the first data;
[0013] a processing module configured to, in response to a data deletion request, mark a state of each physical page included in the first physical block as invalid, update the number of invalid physical pages of the first physical block in the invalid information recording table, and physically erase the data stored in the first physical block;
[0014] The first physical block is a physical block corresponding to the first physical address mapped by the first logical address.
[0015] In a third aspect, an embodiment of the present application provides an electronic device comprising a processor and a memory, wherein the memory stores programs or instructions that can be run on the processor, and when the programs or instructions are executed by the processor, the steps of the method described in the first aspect are implemented.
[0016] In a fourth aspect, an embodiment of the present application further provides an electronic device, which is configured to execute the data processing method as described in the first aspect.
[0017] In a fifth aspect, an embodiment of the present application provides a readable storage medium, on which a program or instruction is stored. When the program or instruction is executed by a processor, the steps of the method described in the first aspect are implemented.
[0018] In a sixth aspect, an embodiment of the present application provides a chip, comprising a processor and a communication interface, wherein the communication interface is coupled to the processor, and the processor is used to run programs or instructions to implement the method described in the first aspect.
[0019] In a seventh aspect, an embodiment of the present application provides a computer program product, which is stored in a storage medium and is executed by at least one processor to implement the method described in the first aspect.
[0020] In an embodiment of the present application, upon receiving a data deletion request, the state of each physical page included in the first physical block is updated to an invalid state, the number of invalid physical pages of the first physical block in the invalid information record table is updated, and the data stored in the first physical block is physically erased. Since the data stored in the first physical block is physically erased upon receiving the data deletion request, the data in the storage device can be physically erased upon receiving the data deletion request, effectively improving the security of user data and reducing the risk of user data leakage. BRIEF DESCRIPTION OF THE DRAWINGS
[0021] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the following briefly introduces the drawings required for use in the description of the embodiments of the present application. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.
[0022] FIG1 is a schematic diagram of the structure of a data processing system provided in an embodiment of the present application;
[0023] FIG2 is a flow chart of a data processing method provided in an embodiment of the present application;
[0024] FIG3 is a schematic structural diagram of a data processing device provided in an embodiment of the present application;
[0025] FIG4 is a schematic structural diagram of an electronic device provided in an embodiment of the present application;
[0026] FIG5 is a schematic diagram of the hardware structure of another electronic device provided in an embodiment of the present application. DETAILED DESCRIPTION
[0027] The following will be combined with the accompanying drawings in the embodiments of the present application to clearly describe the technical solutions in the embodiments of the present application. Obviously, the embodiments described are part of the embodiments of the present application, not all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in this field are within the scope of protection of this application.
[0028] The terms "first," "second," and the like in the specification and claims of this application are used to distinguish similar objects, and are not used to describe a specific order or precedence. It should be understood that the terms used in this manner are interchangeable where appropriate, so that the embodiments of this application can be implemented in an order other than that illustrated or described herein, and that the objects distinguished by "first," "second," and the like are generally of the same type, and do not limit the number of objects; for example, the first object can be one or more. In addition, the term "and / or" in the specification and claims refers to at least one of the connected objects, and the character " / " generally indicates that the objects connected are in an "or" relationship.
[0029] In response to the problems existing in the prior art, the embodiments of the present application provide a data processing method, device, electronic device and readable storage medium, which can improve the security of user data and effectively reduce the risk of user data leakage.
[0030] The data processing method, device, electronic device, and readable storage medium provided in the embodiments of the present application are described in detail below with reference to specific embodiments and their application scenarios in conjunction with the accompanying drawings.
[0031] In an embodiment of the present application, the execution subject of the data processing method can be a data processing device, and the data processing device can specifically be a flash memory (FM) device with data storage function, that is, flash memory. For the sake of convenience of description, in the embodiment of the present application, flash memory devices are collectively referred to as flash memory.
[0032] The data processing device can perform basic operations such as reading, writing, and erasing data. Taking NAND flash memory as an example, a NAND flash memory can include one or more flash memory chips, a flash memory chip can include one or more logical units (DIEs or LUNs), a DIE (or LUN) can include multiple planes, a plane can include multiple blocks, a block can include multiple physical pages, and a physical page can include multiple cells. A cell is the smallest working unit for the flash memory to perform data reading and writing tasks, and a block is the smallest working unit for the flash memory to perform erasure tasks.
[0033] To facilitate understanding of the embodiments of the present application, Figure 1 is a structural schematic diagram of a flash memory provided in an embodiment of the present application. The flash memory provided in the embodiment of the present application can be implemented based on a flash translation layer (FTL). The flash memory can respond to the user's demand for complete deletion of user data and instantly realize physical erasure of user data, thereby improving the security of user data and reducing the risk of user data leakage.
[0034] As shown in Figure 1, the flash memory includes an interface 11, an address translation / mapping and block allocation unit 12, and a data deletion unit 13. Among them, the interface 11 can receive a data deletion request and read out the first logical address included in the data deletion request. The interface 11 can send the first logical address to the address translation / mapping and block allocation unit 12, so that the address translation / mapping and block allocation unit 12 can process the first data stored in the physical storage location according to the first logical address according to the data processing method provided in the embodiment of the application. The first physical block mapped by the first logical address is the physical storage space of the first data, and then trigger the data deletion unit 13 to physically erase the first data.
[0035] The data processing method provided by the embodiment of the present application is described below in conjunction with specific embodiments. FIG2 is a flow chart of a data processing method provided by the embodiment of the present application. As shown in FIG2 , the data processing method may include steps 201 to 202 .
[0036] Step 201: Receive a data deletion request, wherein the data deletion request includes a first logical address of first data;
[0037] Step 202: In response to a data deletion request, mark the status of each physical page included in the first physical block as invalid, update the number of invalid physical pages of the first physical block in the invalid information record table, and physically erase the data stored in the first physical block.
[0038] The above steps are described in detail below.
[0039] First, referring to the above step 201, the user may use the terminal device to send a data deletion request to the flash memory.
[0040] The data deletion request includes a first logical address of the first data, so that the flash memory can find the physical storage location of the first data through the first logical address. The first data is data stored in the flash memory, and specifically can be image data, files, etc. The type of data stored in the flash memory is not specifically limited.
[0041] Optionally, after receiving the data deletion request, the flash memory can directly perform physical erasure on the first data according to the data processing method provided in the embodiment of the present application. In another optional embodiment, in order to reduce the loss of the physical space of the flash memory, the data processing method provided in the embodiment of the present application can also be executed for the data that needs to be physically erased immediately. For example, a preset flag can be set in advance, and when the flash memory recognizes that the data deletion request includes the preset flag, it can be determined that the first data needs to be physically erased.
[0042] Next, the above step 202 is specifically referred to. In response to the data deletion request, the data stored in the first physical block is immediately physically erased.
[0043] An address mapping table can be maintained in the flash memory. The address mapping table is used to record the mapping relationship between logical addresses and physical addresses. Physical blocks can be found through physical addresses. Based on this, the flash memory can find a first physical address in the address mapping table that has a mapping relationship with the first logical address based on the first logical address of the first data. The physical storage space corresponding to the first physical address is the first physical block where the first data is located.
[0044] An invalid information record table may also be maintained in the flash memory, and the invalid information record table may record the number of physical pages (Pages) in an invalid state included in each physical block in the flash memory. In an embodiment of the present application, the state of each physical page included in the first physical block in the invalid information record table is updated to an invalid state.
[0045] After the status of each physical page included in the first physical block in the invalid information record table is updated to an invalid status, at this time, the number of physical pages in the invalid status included in the first physical block is the maximum number of physical pages included in the physical block, that is, if the total number of physical pages in the first physical block is N, then the number of physical pages in the invalid status in the first physical block is N, and N is a positive integer.
[0046] For example, taking the first physical block including N physical pages as an example, before the status of the N physical pages is modified, if the N physical pages are all used to store the first data, or a part of the N physical pages are used to store the first data and the other part of the physical pages are in an idle state, then the status of the N physical pages can be modified to an invalid state, and the first data stored in the first physical block can be conveniently erased.
[0047] In another example, if before the status of N physical pages in the first physical block is modified, a part of the N physical pages are used to store the first data, and another part of the N physical pages store other user data, at this time, before marking each physical page in the first physical block as invalid, the user data stored in the other part of the physical pages can be moved to other free physical pages. In this way, the status of the N physical pages can be modified to an invalid state, and the data stored in the first physical block can be conveniently erased without affecting other user data.
[0048] Optionally, the invalid information record table may also record the number of physical pages in a valid state included in each physical block. The specific record content is not restricted here. The invalid state of a physical page means that the data stored in the physical page needs to be deleted, the valid state of a physical page means that the data stored in the physical page is valid, and the idle state of a physical page means that there is no data stored in the physical page.
[0049] For example, taking each physical block as including 4 physical pages, Table 1 is an invalid information record table provided in an embodiment of the present application. As shown in Table 1, the number of invalid pages (Invalidpages) corresponding to the first physical block Y is 4, and the number of spare pages (Spare pages) is 0. The number of invalid pages (Invalidpages) of another physical block X is 0, and the number of spare pages (Spare pages) is 2.
[0050] Table 1
[0051] After the number of invalid state physical pages included in the first physical block in the invalid information recording table is updated, the physical erasing task may be triggered immediately to physically erase the data stored in the first physical block.
[0052] For example, because the number of invalid physical pages in the first physical block in the invalid information record table is the maximum number of physical pages in the physical block, the deletion priority of the first physical block is high. Therefore, after the flash memory is triggered to perform a physical erase task, the data stored in the first physical block can be physically erased first.
[0053] Optionally, an algorithm for performing physical erasure is configured in the flash memory, such as a garbage collection (GC) algorithm. The physical erasure algorithm can read the invalid information record table and search for physical blocks corresponding to high priorities in the invalid information record table.
[0054] Because the invalid information record table can be used to record the number of invalid physical pages included in each physical block of all physical blocks in the flash memory, it is possible that the number of invalid physical pages included in other physical blocks other than the first physical block also reaches the maximum value, and the content stored in other physical blocks can also be physically erased. The method for marking the invalid physical pages in other physical blocks is not specifically limited herein. For example, multiple physical pages included in a physical block can be modified once or multiple times so that the number of invalid physical pages included in the physical block also reaches the maximum value.
[0055] In an embodiment of the present application, upon receiving a data deletion request, the state of each physical page included in the first physical block is updated to an invalid state, the number of invalid physical pages of the first physical block in the invalid information record table is updated, and the data stored in the first physical block is physically erased. Since the data stored in the first physical block is physically erased upon receiving the data deletion request, the data in the storage device can be physically erased upon receiving the data deletion request, effectively improving the security of user data and reducing the risk of user data leakage.
[0056] In some embodiments of the present application, after updating the status of each physical page included in the first physical block in the invalid information recording table to an invalid state and physically erasing the data stored in the first physical block, the mapping relationship between the first logical address and the first physical address can be deleted in the address mapping table, and the first physical block can be added to the storage space recording table, wherein the storage space recording table can be used to record physical pages in an idle state, and then the first physical block can be used to store data.
[0057] In some embodiments, the user may also request to physically erase the encrypted data in the flash memory through a data deletion request. The encrypted data is stored in the flash memory in the form of a key and ciphertext.
[0058] For example, the target data is unencrypted, and the user can request that it be encrypted for storage. Based on this, the terminal device can first generate a first key, then use the first key to encrypt the target data, generating a first ciphertext. Therefore, the target data is specifically stored in the flash memory in the form of the first key and the first ciphertext. If access to the target data is required, the first key can be used to decrypt the first ciphertext, allowing for convenient access to the target data.
[0059] In addition, the terminal device can also obtain the physical storage space required for the target data. When the physical storage space required for the target data is greater than a preset threshold, the target data can be encrypted and stored, wherein the preset threshold is, for example, the physical storage space corresponding to two physical blocks. In the case where the physical storage space required for the target data is large, the first key can be conveniently stored in a separate physical block by encrypting the storage before storing it. In this way, when the user needs to physically erase the target data, the physical block where the first key is located can be easily found, and the data processing method provided in the embodiment of the present application can be directly used to physically erase the physical block where the first key is located, thereby simplifying the physical erasure process and improving the efficiency of data processing. In the absence of a key, the technical difficulty of decrypting the first ciphertext is high, and the decryption process takes a long time. Therefore, it is difficult for other users to obtain the target data through decryption, thereby protecting the security of the target data and effectively reducing the risk of target data leakage.
[0060] Specifically, the first data is a first key of the target data, the data deletion request further includes a second logical address of the second data, and the second data is a first ciphertext obtained by encrypting the target data using the first key.
[0061] Optionally, the data processing method may further include: marking a first physical page as invalid, wherein the first physical page is a physical page corresponding to a second physical address mapped to the second logical address, and the first physical page is a physical storage space for the second data.
[0062] Specifically, the data deletion request also includes the second logical address of the second data. Based on this, in response to the data deletion request, a second physical address that has a mapping relationship with the second logical address can be found in the address mapping table, wherein the physical storage space corresponding to the second physical address is the first physical page where the second data is located.
[0063] In some embodiments, the number of the first physical page may be one or more. When the number of the first physical page is more than one, the multiple first physical pages may belong to different physical blocks.
[0064] In an embodiment of the present application, the first physical page is marked as invalid. When the flash memory performs a physical erase task, it can be determined whether to perform physical erase on the physical block to which the first physical page belongs based on the number of physical pages in invalid state in the physical block to which the first physical page belongs.
[0065] In addition, for the first key, since it is stored in the first physical block, and the status of each physical page included in the first physical block is marked as invalid, and the number of physical pages in the invalid state of the first physical block is updated in the invalid information recording table, the first key in the flash memory can be deleted immediately after the physical erase task is triggered.
[0066] According to the embodiment of the present application, since the first key in the first physical block has been immediately erased, even if the first ciphertext remains in the flash memory, it is difficult for others to obtain the original target data. This is because decrypting the ciphertext without the key is technically difficult and time-consuming. As a result, it is almost impossible for other users to obtain the actual target data stored in the flash memory, thereby protecting the security of user data and reducing the risk of user data leakage.
[0067] According to an embodiment of the present application, when a user's terminal is abandoned or transferred, the key of the data stored in the terminal can be physically erased, so that the user can safely abandon or transfer the terminal without worrying about data leakage.
[0068] In an embodiment of the present application, whether the data in the first physical page is deleted can be judged based on the number of physical pages in an invalid state in the physical block to which the first physical page belongs. If the number of physical pages in an invalid state in the physical block to which the first physical page belongs is already the maximum, then after triggering the execution of the physical erasure task, the physical block to which the first physical page belongs will also be physically erased. If the number of physical pages in an invalid state in the physical block to which the first physical page belongs has not reached the maximum number, then after triggering the immediate execution of the preset data deletion algorithm, the physical block to which the first physical page belongs may not be immediately physically erased. Instead, after the number of physical pages in an invalid state in the physical block to which the first physical page belongs reaches the maximum number, the physical block to which the first physical page belongs can be physically erased.
[0069] In some embodiments, when a user needs to store user data, the flash memory can search for available physical pages for storage, where an available physical page is an idle physical page. The user data is stored in the physical page. After the user data is stored, the status of the physical page is marked as valid, and the physical address and logical address of the physical page are also written into the address mapping table.
[0070] However, when the amount of user data is large or the amount of user data is not an integer multiple of the physical block size, storing user data based on finding available physical pages may result in user data being stored in multiple different physical pages, which are in turn scattered in different physical blocks. Different physical blocks may also store other data, which makes it inconvenient to directly erase the physical blocks involved in the user data when the user needs to physically erase the user data.
[0071] Based on this, the data processing method provided in the embodiment of the present application may further include steps 301 to 302.
[0072] Step 301: receiving a data storage request, wherein the data storage request includes third data;
[0073] Step 302: When the space required to be occupied by the third data is less than or equal to the storage space of one physical block, determine a second physical block that is in an idle state and store the third data in the second physical block; or, when the space required to be occupied by the third data is greater than the storage space of one physical block, determine a third physical block that is in an idle state, obtain a second key, and store the second key in the third physical block, wherein the second key is used to encrypt the third data.
[0074] Specifically, a user can use a terminal device to send a data storage request to the flash memory. Optionally, the flash memory can use the data processing method provided in the embodiment of the present application to store data in response to the received data storage request. In another optional embodiment, in order to reduce the waste of physical storage space, a preset identifier can be pre-set for data with confidentiality requirements. When the preset identifier is included in the data storage request, the data corresponding to the data storage request is stored using the data processing method provided in the embodiment of the present application.
[0075] Specifically, if the data storage request includes the third data, the flash memory may obtain the space required for the third data and, based on the space required for the third data, determine the number of physical blocks used to store the third data. The third data may be image data, files, or the like, and the type of the third data is not specifically limited.
[0076] Optionally, the storage space record table in the flash memory records the physical pages in the idle state, and the physical blocks in which all the physical pages are in the idle state can be determined according to the storage space record table.
[0077] When the space occupied by the third data is less than or equal to the storage space of one physical block, the number of the second physical block is one. After the second physical block is found, the third data can be stored in the physical page of the second physical block.
[0078] In the case that the space required to be occupied by the third data is equal to the storage space of one physical block, the second physical block can be fully utilized.
[0079] In some embodiments of the present application, when the space required to be occupied by the third data is less than the storage space of a physical block, after the third data is completely stored in the second physical block, the second physical block also includes unused physical pages. Optionally, in an embodiment of the present application, storing the third data in the second physical block can further include the following steps: storing the third data in the second physical block; and determining the second physical page in the second physical block, wherein the second physical page is an unused physical page in the second physical block; and storing the preset data in the second physical page.
[0080] Specifically, after the third data is stored, if there are still unused physical pages in the second physical block, the remaining unused physical pages in the second physical block can be filled with preset data. Optionally, the preset data can be a combination of "1" and "0", or all "0" or all "1". There is no specific limitation on the preset data.
[0081] It can be understood that after all the third data are stored, the mapping relationship between the logical address of the third data and the physical address of the second physical block where the third data is located can be updated in the address mapping table, so that the user can access the third data according to the logical address later, wherein the logical address of the third data can be carried in the data storage request.
[0082] According to an embodiment of the present application, for the third data that the user wants to store, a physical block is provided for separate storage. In this way, when the user has a need to physically erase the third data, the flash memory can easily find the physical block where the third data is located, and directly use the data processing method provided in the embodiment of the present application to physically erase the physical block where the third data is located, thereby simplifying the physical erasure process and improving the efficiency of data processing.
[0083] Optionally, after storing the third data in the second physical block, the state of each physical page in the second physical block can be marked as valid, wherein the valid state means that the physical page stores data. Based on this, other data can be prevented from being stored in the second physical block.
[0084] In some optional embodiments, if the space required for the third data is greater than the storage space of a physical block, then a plurality of available physical blocks are required for storing the third data, where "plurality" refers to two or more. Alternatively, the third data can be stored directly. For example, the number of physical blocks used to store the third data can be determined based on the space required for the third data. Next, the third data can be stored in the first physical block. Once the first physical block is full, the remaining unstored data in the third data can be stored in the second physical block, and so on, until all the third data is stored. Thereafter, the status of each physical page in each physical block is marked as valid, thereby completing the physical storage of the third data. Optionally, if there are still unused physical pages in the last physical block, the remaining unused physical pages of the physical block can be filled with preset data. Optionally, the preset data can be a combination of data such as "1" or "0", and there is no specific limitation on the preset data.
[0085] According to an embodiment of the present application, for the third data that the user wants to store, a physical block is provided for separate storage. In this way, when the user has a need to physically erase the third data, the flash memory can easily find the physical block where the third data is located, and directly use the data processing method provided in the embodiment of the present application to physically erase the physical block where the third data is located, thereby simplifying the physical erasure process and improving the efficiency of data processing.
[0086] In some optional embodiments, when the space required to be occupied by the third data is larger than the storage space of a physical block, it can also be stored in the following manner: determine a third physical block that is in an idle state, obtain a second key, and store the second key in the third physical block, wherein the second key is used to encrypt the third data.
[0087] Specifically, the second key can be used to encrypt the third data to obtain the second ciphertext. If the space required by the second key is small and smaller than the storage space of a physical block, the second key can be conveniently stored in a separate physical block, which can effectively save physical storage space.
[0088] Specifically, based on the space required by the second key, an available physical block in which each physical page is in an idle state, that is, a third physical block, can be searched in the available physical block table. After the third physical block is found, the second key can be stored in the third physical block.
[0089] According to an embodiment of the present application, a physical block is provided for separate storage of the second key. In this way, when a user needs to physically erase the third data, the flash memory can easily find the third physical block and directly use the data processing method provided in the embodiment of the present application to physically erase the third physical block involved in the second key, thereby simplifying the physical erasure process and improving the efficiency of data processing.
[0090] In some embodiments, the space required to be occupied by the third data is greater than the storage space of a physical block. After obtaining the second key, the method further includes: encrypting the third data using the second key to generate a second ciphertext; determining a third physical page in an idle state based on the space required to be occupied by the second ciphertext and a storage space record table, wherein the storage space record table is used to record physical pages in an idle state; storing the second ciphertext in the third physical page, and marking the state of the third physical page as a valid state.
[0091] Specifically, a physical page in an idle state can be searched in the available physical block table to determine the third physical page for storing the second ciphertext. The number of third physical pages can be one or more. If there are multiple third physical pages, the multiple third physical pages can belong to different physical blocks. The physical location of the third physical block is not restricted.
[0092] After the third physical page is determined, the second ciphertext may be stored in the third physical page.
[0093] According to the embodiment of the present application, by storing the second ciphertext in an available physical page, data security can be protected, the risk of data leakage can be reduced, and storage resources can be effectively saved.
[0094] It can be understood that after the second ciphertext is completely stored, the mapping relationship between the logical address of the third data and the physical page where the second ciphertext is located and the physical block where the key is located can be updated in the address mapping table, so that the user can access the third data according to the logical address later, wherein the logical address of the third data can be carried in the data storage request.
[0095] According to an embodiment of the present application, since the second key is stored separately in the physical block, when the user needs to delete the third data, the second key of the third physical block can be deleted immediately. Since the second key has been erased immediately, even if the second ciphertext generated based on the second key remains in the flash memory, in the absence of the key, the technical difficulty of decrypting the second ciphertext is high and the decryption process takes a long time. Therefore, it is difficult for other users to obtain the third data through decryption, thereby protecting the security of the third data and reducing the risk of leakage of the third data.
[0096] In some embodiments, if the user needs to update the stored data and the updated data can still be conveniently physically erased based on the data processing method provided in the embodiment of the present application, based on this, the data processing method provided in the embodiment of the present application also includes steps 410 to 440.
[0097] Step 410: receiving a data update request, wherein the data update request includes fourth data and a fourth logical address;
[0098] Step 420 , in response to the data update request, obtain fifth data, wherein the fifth data is obtained by updating the sixth data according to the fourth data, and the sixth data is data stored in the physical block corresponding to the fourth physical address mapped by the fourth logical address.
[0099] Exemplarily, the data stored in the physical block corresponding to the fourth physical address mapped to the fourth logical address is data that needs to be updated. A processor with data processing functionality in the terminal device can read the data that needs to be updated based on the fourth logical address and, based on the data update request, update the sixth data using the fourth data to obtain the fifth data.
[0100] Optionally, the fourth data may include a request to change the sixth data, which may be to delete part of the data in the sixth data, to add new data in the sixth data, or to adjust the positional relationship between existing data in the sixth data, etc. There is no specific restriction on the fourth data here.
[0101] Step 430: Determine a fourth physical block based on the space required for the fifth data and the available physical block table, wherein each physical page included in the fourth physical block is in an idle state.
[0102] Step 440: Store the fifth data into the fourth physical block.
[0103] According to the embodiment of the present application, the fifth data is updated data, and a physical block is provided to separately store the fifth data. In this way, when the user needs to physically erase the fifth data, the flash memory can easily find the fourth physical block and directly use the data processing method provided in the embodiment of the present application to physically erase the fourth physical block involved in the fifth data, thereby simplifying the physical erasure process and improving the efficiency of data processing.
[0104] In some embodiments of the present application, after storing the fifth data in the fourth physical block, the state of each physical page included in the fourth physical block may be marked as valid, and the mapping relationship between the fourth logical address and the corresponding physical address of the fourth physical block may be updated in the address mapping table. This facilitates user access to the fifth data.
[0105] In some embodiments, the process further includes marking the state of each physical page included in the physical block corresponding to the fourth physical address as invalid, and updating the number of invalid physical pages included in the physical block corresponding to the fourth physical address in the invalid information record table. Because the number of invalid physical pages included in the fourth physical block in the invalid information record table is the maximum number of physical pages included in the physical block, the deletion priority of the fourth physical block is high. Therefore, after triggering the flash memory to perform a physical erase task, the data stored in the fourth physical block can be physically erased first. This effectively deletes historical data stored in the fourth physical block.
[0106] The data processing method provided in the embodiment of the present application can be executed by a data processing device. In the embodiment of the present application, the data processing device provided in the embodiment of the present application is described by taking the data processing method executed by the data processing device as an example.
[0107] FIG3 is a schematic structural diagram of a data processing device provided in an embodiment of the present application. As shown in FIG3 , the data processing device may include a receiving module 310 and a processing module 320 .
[0108] A receiving module 310 is configured to receive a data deletion request, where the data deletion request includes a first logical address of first data;
[0109] A processing module 320 is configured to, in response to a data deletion request, mark the state of each physical page included in the first physical block as invalid, update the number of invalid physical pages of the first physical block in the invalid information recording table, and physically erase the data stored in the first physical block;
[0110] The first physical block is a physical block corresponding to the first physical address mapped by the first logical address.
[0111] In an embodiment of the present application, upon receiving a data deletion request, the state of each physical page included in the first physical block is updated to an invalid state, the number of invalid physical pages of the first physical block in the invalid information record table is updated, and the data stored in the first physical block is physically erased. Since the data stored in the first physical block is physically erased upon receiving the data deletion request, the data in the storage device can be physically erased upon receiving the data deletion request, effectively improving the security of user data and reducing the risk of user data leakage.
[0112] In some embodiments, the first data is a first key for target data, the data deletion request further includes a second logical address for second data, and the second data is a first ciphertext obtained by encrypting the target data using the first key;
[0113] The processing module 320 is further configured to mark a first physical page as invalid, wherein the first physical page is a physical page corresponding to a second physical address mapped to the second logical address, and the first physical page is a physical storage space for the second data.
[0114] According to the embodiment of the present application, since the first key in the first physical block has been immediately erased, even if the first ciphertext remains in the flash memory, it is difficult for others to obtain the original target data. This is because decrypting the ciphertext without the key is technically difficult and time-consuming, making it difficult for other users to obtain the actual target data stored in the flash memory, thereby protecting the security of user data and reducing the risk of user data leakage.
[0115] According to an embodiment of the present application, when a user's terminal is abandoned or transferred, the key of the data stored in the terminal can be physically erased, so that the user can safely abandon or transfer the terminal without worrying about data leakage.
[0116] In some embodiments, the receiving module 310 is further configured to receive a data storage request, wherein the data storage request includes the third data;
[0117] The processing module 320 is further configured to, when the space required to be occupied by the third data is less than or equal to the storage space of one physical block, determine a second physical block that is in an idle state and store the third data in the second physical block; or
[0118] The processing module 320 is also used to determine a third physical block that is in an idle state when the space required by the third data is greater than the storage space of a physical block, and obtain a second key and store the second key in the third physical block, wherein the second key is used to encrypt the third data.
[0119] According to an embodiment of the present application, for the third data that the user wants to store, a physical block is provided for separate storage. In this way, when the user has a need to physically erase the third data, the flash memory can easily find the physical block where the third data is located, and directly use the data processing method provided in the embodiment of the present application to physically erase the physical block where the third data is located, thereby simplifying the physical erasure process and improving the efficiency of data processing.
[0120] In some embodiments, the space required to be occupied by the third data is less than the storage space of one physical block;
[0121] The processing module 320 is further configured to store the third data into the second physical block;
[0122] The processing module 320 is further configured to determine a second physical page in the second physical block, wherein the second physical page is an unused physical page in the second physical block;
[0123] The processing module 320 is further configured to store the preset data into the second physical page.
[0124] According to an embodiment of the present application, for the third data that the user wants to store, a physical block is provided for separate storage. In this way, when the user has a need to physically erase the third data, the flash memory can easily find the physical block where the third data is located, and directly use the data processing method provided in the embodiment of the present application to physically erase the physical block where the third data is located, thereby simplifying the physical erasure process and improving the efficiency of data processing.
[0125] In some embodiments, the space required to be occupied by the third data is greater than the storage space of one physical block;
[0126] The processing module 320 is further configured to encrypt the third data using the second key to generate a second ciphertext;
[0127] The processing module 320 is further configured to determine a third physical page in an idle state based on the space required to be occupied by the second ciphertext and the storage space record table, wherein the storage space record table is used to record the physical pages in the idle state;
[0128] The processing module 320 is further configured to store the second ciphertext in a third physical page and mark the status of the third physical page as valid.
[0129] According to the embodiment of the present application, by storing the second ciphertext in an available physical page, data security can be protected, the risk of data leakage can be reduced, and storage resources can be effectively saved.
[0130] The data processing device in the embodiment of the present application can be an electronic device or a component in the electronic device, such as an integrated circuit or a chip. The electronic device can be a terminal or other device other than a terminal. For example, the electronic device can be a mobile phone, a tablet computer, a laptop computer, a PDA, an in-vehicle electronic device, a mobile Internet device (MID), an augmented reality (AR) / virtual reality (VR) device, a robot, a wearable device, an ultra-mobile personal computer (UMPC), a netbook or a personal digital assistant (PDA), etc. It can also be a server, a network attached storage (NAS), a personal computer (PC), a television (TV), a teller machine or a self-service machine, etc., and the embodiment of the present application does not specifically limit it.
[0131] The data processing device in the embodiment of the present application may be a device having an operating system. The operating system may be an Android operating system, an iOS operating system, or other possible operating systems, which are not specifically limited in the embodiment of the present application.
[0132] The data processing device provided in the embodiment of the present application can implement each process implemented by the data processing method embodiment provided in the embodiment of the present application. To avoid repetition, they will not be described here.
[0133] Optionally, as shown in Figure 4, an embodiment of the present application also provides an electronic device 400, including a processor 401 and a memory 402, and the memory 402 stores a program or instruction that can be run on the processor 401. When the program or instruction is executed by the processor 401, the various steps of the above-mentioned data processing method embodiment are implemented and the same technical effect can be achieved. To avoid repetition, it will not be repeated here.
[0134] It should be noted that the electronic devices in the embodiments of the present application include the above-mentioned mobile electronic devices and non-mobile electronic devices.
[0135] FIG5 is a schematic diagram of the hardware structure of an electronic device implementing an embodiment of the present application.
[0136] The electronic device 500 includes but is not limited to components such as a radio frequency unit 501 , a network module 502 , an audio output unit 503 , an input unit 504 , a sensor 505 , a display unit 506 , a user input unit 507 , an interface unit 508 , a memory 509 , and a processor 510 .
[0137] Those skilled in the art will appreciate that the electronic device 500 may further include a power source (e.g., a battery) to power various components. The power source may be logically connected to the processor 510 via a power management system, thereby enabling the power management system to manage charging, discharging, and power consumption. The electronic device structure shown in FIG5 does not limit the electronic device. The electronic device may include more or fewer components than shown, or may combine certain components or arrange the components differently, which will not be described in detail here.
[0138] The memory 509 is configured to receive a data deletion request, where the data deletion request includes a first logical address of the first data;
[0139] The memory 509 is configured to, in response to the data deletion request, mark the state of each physical page included in the first physical block as invalid, update the number of invalid physical pages of the first physical block in the invalid information recording table, and physically erase the data stored in the first physical block;
[0140] The first physical block is a physical block corresponding to the first physical address mapped by the first logical address.
[0141] In an embodiment of the present application, upon receiving a data deletion request, the state of each physical page included in the first physical block is updated to an invalid state, the number of invalid physical pages of the first physical block in the invalid information record table is updated, and the data stored in the first physical block is physically erased. Since the data stored in the first physical block is physically erased upon receiving the data deletion request, the data in the storage device can be physically erased upon receiving the data deletion request, effectively improving the security of user data and reducing the risk of user data leakage.
[0142] In some embodiments, the first data is a first key for target data, the data deletion request further includes a second logical address for second data, and the second data is a first ciphertext obtained by encrypting the target data using the first key;
[0143] The memory 509 is further configured to mark a first physical page as invalid, wherein the first physical page is a physical page corresponding to a second physical address mapped to the second logical address, and the first physical page is a physical storage space for the second data.
[0144] According to the embodiment of the present application, since the first key in the first physical block has been immediately erased, even if the first ciphertext remains in the flash memory, it is difficult for others to obtain the original target data. This is because decrypting the ciphertext without the key is technically difficult and time-consuming, making it difficult for other users to obtain the actual target data stored in the flash memory, thereby protecting the security of user data and reducing the risk of user data leakage.
[0145] According to an embodiment of the present application, when a user's terminal is abandoned or transferred, the key of the data stored in the terminal can be physically erased, so that the user can safely abandon or transfer the terminal without worrying about data leakage.
[0146] In some embodiments, the input unit 504 is further configured to receive a data storage request, wherein the data storage request includes the third data;
[0147] The memory 509 is further configured to, when the space required to be occupied by the third data is less than or equal to the storage space of one physical block, determine a second physical block that is in an idle state and store the third data in the second physical block; or
[0148] Memory 509 is also used to determine a third physical block in an idle state when the space required by the third data is larger than the storage space of a physical block, and obtain a second key and store the second key in the third physical block, wherein the second key is used to encrypt the third data.
[0149] According to an embodiment of the present application, for the third data that the user wants to store, a physical block is provided for separate storage. In this way, when the user has a need to physically erase the third data, the flash memory can easily find the physical block where the third data is located, and directly use the data processing method provided in the embodiment of the present application to physically erase the physical block where the third data is located, thereby simplifying the physical erasure process and improving the efficiency of data processing.
[0150] In some embodiments, the space required to be occupied by the third data is less than the storage space of one physical block;
[0151] The memory 509 is further configured to store the third data into the second physical block;
[0152] The memory 509 is further configured to determine a second physical page in the second physical block, wherein the second physical page is an unused physical page in the second physical block;
[0153] The memory 509 is further configured to store the preset data into the second physical page.
[0154] According to an embodiment of the present application, for the third data that the user wants to store, a physical block is provided for separate storage. In this way, when the user has a need to physically erase the third data, the flash memory can easily find the physical block where the third data is located, and directly use the data processing method provided in the embodiment of the present application to physically erase the physical block where the third data is located, thereby simplifying the physical erasure process and improving the efficiency of data processing.
[0155] In some embodiments, the space required to be occupied by the third data is greater than the storage space of one physical block;
[0156] The memory 509 is further configured to encrypt the third data using the second key to generate a second ciphertext;
[0157] The memory 509 is further configured to determine a third physical page in an idle state based on the space required to be occupied by the second ciphertext and the storage space record table, wherein the storage space record table is configured to record the physical pages in an idle state;
[0158] The memory 509 is further configured to store the second ciphertext into the third physical page, and mark the status of the third physical page as valid.
[0159] According to the embodiment of the present application, by storing the second ciphertext in an available physical page, data security can be protected, the risk of data leakage can be reduced, and storage resources can be effectively saved.
[0160] It should be understood that in an embodiment of the present application, the input unit 504 may include a graphics processing unit (GPU) 5041 and a microphone 5042, and the graphics processor 5041 processes the image data of a static picture or video obtained by an image capture device (such as a camera) in a video capture mode or an image capture mode. The display unit 506 may include a display panel 5051, and the display panel 5051 may be configured in the form of a liquid crystal display, an organic light emitting diode, etc. The user input unit 507 includes a touch panel 5071 and at least one of other input devices 5072. The touch panel 5071 is also called a touch screen. The touch panel 5071 may include two parts: a touch detection device and a touch controller. Other input devices 5072 may include, but are not limited to, a physical keyboard, function keys (such as volume control keys, switch keys, etc.), a trackball, a mouse, and a joystick, which will not be repeated here.
[0161] The memory 509 can be used to store software programs and various data. The memory 509 may mainly include a first storage area for storing programs or instructions and a second storage area for storing data, wherein the first storage area may store an operating system, applications or instructions required for at least one function (such as a sound playback function, an image playback function, etc.). In addition, the memory 509 may include a volatile memory or a non-volatile memory, or the memory 509 may include both volatile and non-volatile memories. Among them, the non-volatile memory may be a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), or a flash memory. The volatile memory may be a random access memory (RAM), a static random access memory (SRAM), a dynamic random access memory (DRAM), a synchronous dynamic random access memory (SDRAM), a double data rate synchronous dynamic random access memory (DDRSDRAM), an enhanced synchronous dynamic random access memory (ESDRAM), a synchronous link dynamic random access memory (SLDRAM), and a direct memory bus random access memory (DRRAM). The memory 509 in the embodiment of the present application includes but is not limited to these and any other suitable types of memory.
[0162] Processor 510 may include one or more processing units. Optionally, processor 510 integrates an application processor and a modem processor. The application processor primarily handles operations related to the operating system, user interface, and application programs, while the modem processor primarily processes wireless communication signals, such as a baseband processor. It is understood that the modem processor may not be integrated into processor 510.
[0163] An embodiment of the present application also provides a readable storage medium, on which a program or instruction is stored. When the program or instruction is executed by a processor, the various processes of the above-mentioned data processing method embodiment are implemented and the same technical effect can be achieved. To avoid repetition, it will not be repeated here.
[0164] The processor is the processor in the electronic device described in the above embodiment. The readable storage medium includes a computer readable storage medium, such as a computer read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disk.
[0165] An embodiment of the present application further provides a chip, which includes a processor and a communication interface, wherein the communication interface is coupled to the processor, and the processor is used to run programs or instructions to implement the various processes of the above-mentioned data processing method embodiment and can achieve the same technical effect. To avoid repetition, it will not be repeated here.
[0166] It should be understood that the chip mentioned in the embodiments of the present application can also be called a system-level chip, a system chip, a chip system or a system-on-chip chip, etc.
[0167] An embodiment of the present application provides a computer program product, which is stored in a storage medium. The program product is executed by at least one processor to implement the various processes of the above-mentioned data processing method embodiment and can achieve the same technical effect. To avoid repetition, it will not be repeated here.
[0168] It should be noted that, in this article, the terms "comprise", "include" or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device comprising a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, article or device. In the absence of further restrictions, an element defined by the statement "comprises a ..." does not exclude the presence of other identical elements in the process, method, article or device comprising the element. In addition, it should be noted that the scope of the methods and devices in the embodiments of the present application is not limited to performing functions in the order shown or discussed, and may also include performing functions in a substantially simultaneous manner or in the opposite order according to the functions involved. For example, the described method may be performed in an order different from that described, and various steps may also be added, omitted, or combined. In addition, the features described with reference to certain examples may be combined in other examples.
[0169] Through the description of the above implementation methods, those skilled in the art can clearly understand that the above-mentioned embodiment methods can be implemented by means of software plus the necessary general hardware platform, and of course can also be implemented by hardware, but in many cases the former is a better implementation method. Based on this understanding, the technical solution of the present application is essentially or the part that contributes to the prior art can be embodied in the form of a computer software product, which is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk), including a number of instructions for enabling a terminal (which can be a mobile phone, computer, server, or network device, etc.) to execute the methods described in each embodiment of the present application.
[0170] The embodiments of the present application are described above in conjunction with the accompanying drawings, but the present application is not limited to the above-mentioned specific implementation methods. The above-mentioned specific implementation methods are merely illustrative and not restrictive. Under the guidance of this application, ordinary technicians in this field can also make many forms without departing from the purpose of this application and the scope of protection of the claims, all of which are within the protection of this application.
Claims
1. A data processing method, comprising: Receiving a data deletion request, the data deletion request including a first logical address of first data; In response to the data deletion request, marking the status of each physical page included in the first physical block as an invalid status, updating the number of physical pages with an invalid status in the first physical block in the invalid information record table, and physically erasing the data stored in the first physical block; Wherein, the first physical block is the physical block corresponding to the first physical address mapped by the first logical address.
2. The method according to claim 1, wherein The first data is the first key of the target data, the data deletion request further includes a second logical address of second data, and the second data is the first ciphertext obtained by encrypting the target data using the first key; The method further includes: Marking a first physical page as an invalid status, wherein the first physical page is the physical page corresponding to the second physical address mapped by the second logical address, and the first physical page is the physical storage space of the second data.
3. The method according to claim 1, the method further includes: Receiving a data storage request, wherein the data storage request includes third data; When the space required by the third data is less than or equal to the storage space of one physical block, determining a second physical block in an idle state and storing the third data in the second physical block; or, When the space required by the third data is greater than the storage space of one physical block, determining a third physical block in an idle state and obtaining a second key, and storing the second key in the third physical block, wherein the second key is used to encrypt the third data.
4. The method according to claim 3, wherein, The space required by the third data is less than the storage space of one physical block, and storing the third data in the second physical block includes: Storing the third data in the second physical block; And determining a second physical page in the second physical block, wherein the second physical page is an unused physical page in the second physical block; Storing preset data in the second physical page.
5. The method according to claim 3, wherein, The space required by the third data is greater than the storage space of one physical block. After obtaining the second key, the method further includes: Encrypting the third data using the second key to generate a second ciphertext; Determining a third physical page in an idle state according to the space required by the second ciphertext and the storage space record table, wherein the storage space record table is used to record physical pages in an idle state; Storing the second ciphertext in the third physical page and marking the status of the third physical page as an effective status.
6. A data processing apparatus, comprising: A receiving module, configured to receive a data deletion request, the data deletion request including a first logical address of first data; A processing module, configured to, in response to the data deletion request, mark the status of each physical page included in the first physical block as an invalid status, update the number of physical pages with an invalid status in the first physical block in the invalid information record table, and physically erase the data stored in the first physical block; Wherein, the first physical block is the physical block corresponding to the first physical address mapped by the first logical address.
7. The apparatus according to claim 6, wherein, The first data is the first key of the target data, and the data deletion request further includes the second logical address of the second data, where the second data is the first ciphertext obtained by encrypting the target data using the first key; The processing module is further configured to mark the first physical page as an invalid state, where the first physical page is the physical page corresponding to the second physical address mapped by the second logical address, and the first physical page is the physical storage space of the second data.
8. The apparatus according to claim 6, wherein, The receiving module is further configured to receive a data storage request, where the data storage request includes third data; The processing module is further configured to, when the space required by the third data is less than or equal to the storage space of one physical block, determine a second physical block in an idle state and store the third data in the second physical block; or, The processing module is further configured to, when the space required by the third data is greater than the storage space of one physical block, determine a third physical block in an idle state and obtain a second key, and store the second key in the third physical block, where the second key is used to encrypt the third data.
9. The apparatus according to claim 8, wherein, The space required by the third data is less than the storage space of one physical block; The processing module is further configured to store the third data in the second physical block; The processing module is further configured to determine a second physical page in the second physical block, where the second physical page is an unused physical page in the second physical block; The processing module is further configured to store preset data in the second physical page.
10. The apparatus according to claim 8, wherein, The space required by the third data is greater than the storage space of one physical block; The processing module is further configured to encrypt the third data using the second key to generate a second ciphertext; The processing module is further configured to determine a third physical page in an idle state according to the space required by the second ciphertext and the storage space record table, where the storage space record table is used to record the physical pages in an idle state; The processing module is further configured to store the second ciphertext in the third physical page and mark the state of the third physical page as an effective state.
11. An electronic device, comprising a processor and a memory, where the memory stores a program or instruction that can be run on the processor, and when the program or instruction is executed by the processor, the steps of the data processing method according to any one of claims 1-5 are implemented.
12. An electronic device, where the electronic device is configured to execute the data processing method according to any one of claims 1-5.
13. A readable storage medium, where a program or instruction is stored on the readable storage medium, and when the program or instruction is executed by a processor, the steps of the data processing method according to any one of claims 1-5 are implemented.
14. A computer program product, which is executed by at least one processor to implement the data processing method according to any one of claims 1-5.
15. A chip, which includes a processor and a communication interface. The communication interface is coupled to the processor, and the processor is used to run programs or instructions to implement the data processing method according to any one of claims 1-5.
Citation Information
Patent Citations
Flash memory secure deletion method and system based on file-level granularity
CN107037988A
Solid state disk garbage collection method with wear balance consciousness
CN110221774A
Data deletion method and electronic equipment
CN115357930A
Data processing method and device, electronic equipment and readable storage medium
CN117828687A
Selective erasure of data in a SSD
US20200218465A1