The invention discloses a
system and method for full
disk encryption based on hardware. The method comprises the following steps: (1) performing registration and binding on a blank
encryption hard disk of a host and a certification UKey through a registration center; storing a certification program and an identity key to a reserved area of the
encryption hard disk; storing the identity key, an
encryption Key and the certification program through the UKey; (2) prior to
electrification of the host, inserting the UKey in the host; (3) after
electrification, executing encryption hard disk and UKey
mutual authentication; (4) after the
authentication is successful, through the encryption hard disk, storing the Key obtained from the UKey in a buffer area memory undergoing power down loss; through an encryption and decryption module, using the Key to decrypt data and starting an
operating system of the host; and (5) after the
operating system is started, through the encryption and decryption module, utilizing the Key to decrypt read data, encrypt read-in data and then store the read-in data to an encrypted data
storage area of the encryption hard disk. The
system and method for full
disk encryption based on the hardware greatly improves hard disk
data security.