The method and apparatus for generating encrypted
operating system installation files, in this embodiment, at the
operating system level, encrypts the files of the kernel,
temporary file system, and root
file system necessary for running the
operating system layer by layer. Data in the root
file system can only be accessed by sequentially decrypting the files during
system startup on the target product hardware platform according to the bootloader, kernel,
temporary file system, and root
file system. This avoids the risk of static decryption after system files are extracted, achieving system-level protection of storage media data and improving
operating system security. Writing the aforementioned files according to second hardware
address mapping information prevents users without access rights from directly reading the files, further enhancing
data security. At the
user interface level, users can only use product functions in a limited
operating environment, preventing users with lower-level permissions from accessing data in the root file system, effectively protecting storage media data at the user level.