CN100451999C - Memory and method for protecting storage data - Google Patents

Memory and method for protecting storage data Download PDF

Info

Publication number
CN100451999C
CN100451999C CNB2005101320239A CN200510132023A CN100451999C CN 100451999 C CN100451999 C CN 100451999C CN B2005101320239 A CNB2005101320239 A CN B2005101320239A CN 200510132023 A CN200510132023 A CN 200510132023A CN 100451999 C CN100451999 C CN 100451999C
Authority
CN
China
Prior art keywords
data
control module
end host
storage device
order
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Active
Application number
CNB2005101320239A
Other languages
Chinese (zh)
Other versions
CN1983215A (en
Inventor
周正三
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Egis Technology Inc
Original Assignee
XIANGQUN SCI-TECH Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by XIANGQUN SCI-TECH Co Ltd filed Critical XIANGQUN SCI-TECH Co Ltd
Priority to CNB2005101320239A priority Critical patent/CN100451999C/en
Publication of CN1983215A publication Critical patent/CN1983215A/en
Application granted granted Critical
Publication of CN100451999C publication Critical patent/CN100451999C/en
Active legal-status Critical Current
Anticipated expiration legal-status Critical

Links

Images

Landscapes

  • Image Input (AREA)
  • Collating Specific Patterns (AREA)
  • Measurement Of The Respiration, Hearing Ability, Form, And Blood Characteristics Of Living Organisms (AREA)

Abstract

A method for protecting data stored in storage unit includes loading proper driving program and application program in host automatically by control module, using two said programs to receive command from user by host for informing control module to control biological transducer to fetch out biological data to be identified and to extract out character data to be identified of user, using control module to compare character data to be identified with character data stored in storage module and enabling host to make access on a secret block of storage module if compared character data are fitted to each other.

Description

The guard method of a kind of storage device and storage data thereof
Technical field
The present invention is relevant for the guard method of a kind of storage device and storage data thereof, particularly relevant for a kind of guard method that contains the storage device and the storage data thereof of fingerprint sensor.The present invention also is associated to part inventor's following patent: (a) Chinese invention patent application case 200310116995.X, the applying date is on Dec 5th, 2003, and denomination of invention is " containing the guard method of the memorizer memory devices and the storage data thereof of fingerprint sensor "; And (b) Chinese invention patent application case numbers 200410038204.0, the applying date is on May 13rd, 2004, denomination of invention is " containing the guard method that the Portable of biological identification is encrypted storage device and storage data thereof ".
Background technology
Traditionally, the practice of maintaining secrecy about personal data, the most normal use is to adopt the mode of cryptoguard to reach.Yet, access to your password and protect personal data, not only have the trouble that the user forgets Password easily, the danger that more has password cracked by the people.Therefore, about the distinctive biological data of individual, such as biological identification methods such as fingerprint, vocal print, person's handwriting, iris, provided comparatively complete and the active data protected mode by development gradually.Its advantage is that biological characteristic is carried and must not be remembered, and more can't be stolen, and is particularly in conjunction with the biological characteristic guard method of fingerprint, not only tight, and use quite convenient.
In recent years more because the invention of chip type fingerprint sensor, making compact electronic product integrate fingeprint distinguisher no longer is infeasible technology, the correlation technique content can be referring to following patent of this case inventor straight three: 1. the Chinese invention patent application case number 02105960.8, the applying date is on April 10th, 2002, denomination of invention is " capacitance type fingerprint access chip ", and publication number is 1450489; 2. the Chinese invention patent application case number 02123058.7, and the applying date is on June 13rd, 2002, and denomination of invention is " pressure type fingerprint reads chip and manufacture method thereof ", and publication number is 1464471; 3. the Chinese invention patent application case number 02124906.7, and the applying date is on June 25th, 2002, and denomination of invention is " temperature sensor and use the identification of fingerprint chip of this temperature sensor ", and publication number is 1463674; And 4. Chinese invention patent application cases number 02132054.3, the applying date is on September 10th, 2002, and denomination of invention be " the fingerprint access chip structure of capacitive pressure little sensing unit and application thereof ", and publication number is 1482440.This has also opened up a kind of brand-new individualized application, the function of the also promptly individual carry-on subsidiary identification of fingerprint of electronic product.
Particularly aspect the protection of Storage Media; especially in conjunction with the important development project of biological identification method; for example: United States Patent (USP) the 4th before 20 years; 582; No. 985 communiques have just disclosed a kind of guard method of Storage Media, wherein utilize the mode protection of finger print identifying to be stored in personal data in the personal identification card-type device.After the identification of fingerprint program was passed through, the protected data that is stored in the card-type device was just exported for carrying out follow-up processing or authentication procedure.The lateral dimension of this kind device is same as general credit card at present, it mainly comprises a fingerprint sensor, image processing and recognition module and storing memory, is a fingeprint distinguisher (also being that fingerprint acquisition and identification all are to carry out in same device) fully independently.Even its application purpose is prevent personal credit card etc. for example counterfeit, yet, costing an arm and a leg of this device, for example except fingerprint sensor, the microprocessor that image processing and recognition module need high-order is the risc processor or the dsp chip of 32 (bits) for example, makes that this a kind of independent device for identifying is difficult for promoting.
United States Patent (USP) the 6th, 213, what No. 403 communiques, European patent EP 124079A1 communique, world patent WO 02/42887A2 communique, No. 2003/005337 communique of U.S. Patent Publication and BrP GB2387933 communiques all disclosed various use distinct interfaces is similar to United States Patent (USP) the 4th, the independently fingeprint distinguisher of 582, No. 985 communiques.
So far, aforesaid known technology has a common characteristic, and a fingeprint distinguisher independently just is provided, and inside comprises fingerprint sensor, and fingerprint image is handled and identification IC.Such design advantage is, perhaps need the fingerprint application program be installed at the terminal system end, and provide the ease of use of hot plug, but derive another major issue, that costs an arm and a leg exactly, a fingerprint image is handled and the cost of identification IC and supporting design thereof because must increase, usually this IC is 32 Reduced Instruction Set Computer (Reduced Instruction Set Computer, RISC) or digital signal processor (DigitalSignal Processor, DSP), could carry out identification of fingerprint fast.Therefore, traditional portable memory device with fingerprint sensor has expensive shortcoming.
For solving expensive problem, best mode is to utilize the microprocessor of terminal system to carry out fingerprint image processing and identification, just can effectively reduce cost.But known technology there is no for this method and clearly discloses and propose solution at present.
Because if the work of fingerprint image processing and identification be carried out the microprocessor that changes terminal system into by storage device carries out, then this contrive equipment must have the function of automatic download fingerprint application program (comprising fingerprint image processing, identification and encryption and decryption functions or the like) in terminal system, just can reach the function of hot plug and the convenience that can use in any terminal system.The yet above-mentioned known technology of such solution does not provide.
Perhaps disclose, fingerprint processing and recognition software can be installed on the terminal system,, perhaps need the install software that wastes time and energy just such design makes the user to use in the different terminals system as No. 2003/005337 communique of U.S. Patent Publication.Traditional practice provides a CD, for the user driver of the storer in the storage device is installed respectively, and the driver of fingerprint sensor, could allow whole storage device bring into use.In the case, in setting the first time of each computer system, the user also will carry CD and could use this storage device in other computer system except will carrying portable memory device.Though can pass through the network download driver, this is not the perfect practice, because some computing machine not necessarily can both connect to network.
For this reason, the inventor is at above-mentioned (a) and (b) disclosed a kind of design that automatically performs (Auto Run) identification of fingerprint and application program in terminal system in the patent, storage device is cut into several zones, and one of them regional simulation become CD-ROM (allow terminal system think CD-ROM device), and be stored in this regional identification of fingerprint and application program just can be automatically performed.Solve known technology expensive (needing independent device for identifying) or need the prior method that identification of fingerprint software is installed on computers.
In these invention cases, the processing of fingerprint image and contrast all are to carry out in terminal system, open the authority of read-write after finishing contrast again by special instruction (special command) notice storage device.
Such design still has some shortcomings, if that has the people to intercept this special instruction at end host exactly, then might not need fingerprint contrast and has cracked the security of storage device.
Continue above-mentioned invention, this case inventor will further provide a kind of guard method of storage data, can protect storage device of the present invention can not captured the key of memory device starting fully when terminal system is operated.
Summary of the invention
In view of this; fundamental purpose of the present invention just provides the guard method of a kind of storage device and storage data thereof; this storage device is to be connected with an end host; and by with the acting in conjunction of this end host; can under the cost that increases this storage device not significantly, provide the storage device that contains fingerprint sensor.
Another object of the present invention provides the guard method of a kind of storage device and storage data thereof, and it can hide its fingerprint sensor and storer to an end host, in order to simplify the control mode of this end host.
Another purpose again of the present invention provides the guard method of a kind of storage device and storage data thereof, and its special instruction that can avoid end host control storage device to open is blocked and loses the function of data protection.
For reaching above-mentioned purpose, the invention provides a kind of storage device.This storage device comprises a host interface that is connected to an end host, a biological sensor (sensor) and a memory module that is connected to a control module of host interface and is connected to control module substantially.Control module makes end host be written into automatically and carries out driver and the application program that is suitable for end host.End host receives from user's by this two program and instructs, and a biological data to be identified that reads the user with notice control module control biology sensor deals with and extract characteristic to be identified.End host passes through host interface loopback characteristic to be identified in control module, contrast characteristic to be identified and the template characteristic data that are stored in memory module by control module, and make a secret block of end host energy access memory module according to the result that coincide.
The present invention also provides a kind of guard method of storage data of said storage unit; by in control module, carrying out the contrast of characteristic; so that control module is controlled the activation (enable) and forbidden energy (disable) state of memory module, the situation that can effectively avoid end host to be blocked in order to the special instruction of the secret block of opening memory module.
By the present invention, do not needing to increase under any hardware cost, the characteristic comparing function that fingerprint is last designs in the microprocessor in control module and carries out, and can prevent your interception and cracks, and really reaches the convenience of the security and the use of data confidentiality.Moreover the design of ciphering and deciphering device can prevent to steal data after memory module from being pulled out.
Description of drawings
Fig. 1 represents the connection status synoptic diagram according to the storage device of first embodiment of the invention and an end host;
Fig. 2 represents to have the application system flow process of the storage device of fingerprint sensor;
Fig. 3 shows the synoptic diagram that the memory module of apparatus of the present invention is cut into different isolated areas;
Fig. 4 represents the connection status synoptic diagram according to the storage device of second embodiment of the invention and an end host.
The primary clustering symbol description:
10: storage device
100: end host
102: control module
102A: microprocessor
102B:RAM
102C:ROM
102D: enciphering/deciphering device
103: expansion slot
104: memory module
104A: public block
104B: secret block
104C: hidden blocks
105: external memorizer
106: fingerprint sensor
108: host interface
110: memory interface
200: logical space
202: entity space
210-280: step
600: disk
Embodiment
As shown in Figure 1, it is the functional block diagram of the storage device 10 of first embodiment of the invention.This device 10 comprises a control module 102, a memory module 104, one biological identification sensor 106 and a host interface 108 basically.Biological identification sensor 106 can the sensing user biological data, such as person's handwriting, iris, sound, fingerprint etc. below only explain with fingerprint sensor 106.The host interface 108 of present embodiment is the interface of USB (universal serial bus) (USB), yet also can be a pcmcia interface, PCI (PCI EXPRESS) interface or an IEEE 1394 interfaces or other standard interface at a high speed.Host interface 108 is to be connected with end host 100, and control module 102 is connected with end host 100 by host interface 108, and is connected with memory module 104 by memory interface 110.The task of control module 102 is to link up with end host 100, simultaneously diode-capacitor storage module 104 and fingerprint sensor 106.
Control module 102 has mainly comprised a microprocessor 102A, an one RAM 102B and a ROM 102C, wherein RAM 102B is the working storage during as data processing, and ROM 102C has also stored the program code of fingerprint characteristic data contrast except having stored the firmware (firmware) that makes whole storage device work.Microprocessor 102A, RAM 102B and ROM 102C can be incorporated in the one chip and become single chip design may.Perhaps, control module 102 can also comprise a hardware enciphering/deciphering device 102D, in order to the data of enciphering/deciphering turnover memory module 104.Enciphering/deciphering device 102D is also can be from control module 102 independent and be connected between memory module 104 and the control module 102.Enciphering/deciphering device 102D also can be incorporated in the one chip with microprocessor 102A, RAM 102B and ROM 102C and become single chip design may.
Memory module 104 must comprise that at least one is used for the storage chip or the storer of storage data, for example flash memory, programmable read-only memory (prom), ROM (read-only memory) (ROM) or the programmable read only memory (EEPROM) of can electrically erasing.Memory module 104 is split into: a public block 104A comprises a fingerprint application program in interior at least one application program in order to storage; One secret block 104B is in order to store data to be protected; An and hidden blocks 104C; in order to store at least one template characteristic data; also can be in order to storing enciphering/deciphering gold key, and this enciphering/deciphering gold key also can be transferred to this enciphering/deciphering device 102D the data to be protected from secret block 104B access are given encrypt/decrypt.
Fingerprint sensor 106 has comprised the area-type fingerprint sensor that leaves standstill finger print thereon in order to sensing, or slides through the sweep fingerprint sensor of the finger print on it in order to sensing.Real-time finger print data (biological data) is grasped in fingerprint sensor 106 controlled module 102 access control, and be sent to end host 100, make end host 100 that this finger print data is done image processing (also being that so-called image strengthens and two materialization are handled), and extract characteristic to be identified or unique point (featurepoints or minutiae points), be transmitted back to microprocessor 102A in the control module 102 and characteristic to be identified and previous template characteristic data are done template contrast with being about to this characteristic to be identified.So-called template characteristic data, the owner who is exactly storage device 10 is when using for the first time this device, and left therein primary finger print data (biological data), this finger print data are in order to the benchmark of conduct with the contrast of subsequent fingerprint data.Therefore, fingerprint sensor 106 is to be connected to described control module 102, in order to sensing authorized user's template characteristic data, also can come with the contrast of template characteristic data in order to sensing one user's a characteristic to be identified.
As shown in Figure 2, the guard method of the storage data of storage device 10 of the present invention after being connected to end host 100 is as follows.At first, control module 102 is linked up with end host 100 by host interface 108, memory module 104 is configured and it is considered as logic magnetic disc, and make end host 100 will be suitable for the driver of operating system of end host 100 and fingerprint application Automatic Program being written into and being mounted in this end host 100, shown in step 210.In one embodiment, making the operating system of end host 100 download the technology of carrying out fingerprint application program and driver automatically, is that the public block 104A with memory module 104 is modeled to CD-ROM promoter region (booting area).Then, in step 220, demonstrate a window (can guide the user to carry out) on the end host 100 and enter a fingerprint login mode (step 225) or a finger print identifying pattern (step 230) for user's selection or automatic judgement with the mode of spring window.
If will enter the fingerprint login mode, then end host 100 notice control modules 102 control fingerprint sensors 106 read authorized user's template fingerprint data, and the template fingerprint data are sent to (step 235,245) in the end host 100.At this moment, end host 100 utilizes fingerprint application routine processes template fingerprint data and produces the template characteristic data, and the template characteristic data transmission is stored to hidden blocks 104C.Perhaps, the fingerprint application program can be utilized golden key encrypted template characteristic (step 255), and the template characteristic data transmission that will encrypt then stores (step 265) to hidden blocks 104C.
If will enter the finger print identifying pattern, then the microprocessor 102A of control module 102 reads template characteristic data (step 230) from hidden blocks 104C, then with golden key deciphering template characteristic data (step 240).Then, end host 100 notice control modules 102 control fingerprint sensors 106 read user's fingerprint to be identified (biology) data, and finger print data to be identified is sent in the end host 100 (step 250).Then, end host 100 utilizes application program to handle finger print data to be identified to produce characteristic to be identified, and the microprocessor 102A that characteristic to be identified is transmitted back to control module 102 does the template contrast with characteristic to be identified and template characteristic data, and judge both whether coincide in fact (steps 260), and untie secret block when substantially coincideing so that secret block 104B activation (enable) for end host 100 accesses (step 280), otherwise make secret block 104B forbidden energy (disable) to prevent end host 100 accesses, inquire perhaps whether the user continues recently authenticating (step 270) again.
The method of the employed control module 102 diode-capacitor storage modules 104 of apparatus of the present invention, be this memory module can be cut into different independent blocks to store different data respectively, with the embodiment of the invention, this memory module 104 is to be cut into a public block 104A, a secret block 104B and a hidden blocks 104C.See also Fig. 3, it is the explanation that the memory module 104 of apparatus of the present invention is cut into different isolated areas.
As shown in Figure 3, control module 102 in the storage device 10 of the present invention is divided into three complete independent blocks with the logical space 200 of memory module 104, wherein comprises the secret block 104B of public block 104A, Q to M-1 logical blocks of the 0th to P logical blocks and the hidden blocks 104C of M logical blocks.Partition information is to be stored in the information specific block.Logical space 200 is to map to entity space 202, and entity space 202 has comprised information block and the 1st to N physical blocks.
In another embodiment, when apparatus of the present invention with after end host is connected, end host can be considered as this device one disk 600 independently, and link the public block 104A of independence in the memory module 104 automatically, on the display device of end host, to show the archives option of fingerprint application program, and select a fingerprint login screen for example to occur to carry out this fingerprint application program by the user.
After the fingerprint pre-treatment application program that executes this public block 104A (comprising the action of image enhancing, two materialization, graph thinning and characteristic extraction), and this characteristic is back to microprocessor 102A in the control module 102 can the automatic switchover block after differentiating successfully, switches to secret block 104B by public block 104A.And this characteristic can also comprise enciphering/deciphering mechanism to this characteristic in the transmission of 102 of end host and control modules.Corresponding, the switching of picture can appear on the display device of end host, also promptly switch to shielded secret block 104B, to demonstrate protected data in this block, make the user can free access.
In brief, when using apparatus of the present invention, control module 102 can switch to public block earlier and download fingerprint pre-treatment application program automatically, and the microprocessor 102A of passback characteristic in control module 102, switches to secret block again after contrast (matching) success.And so automatic download fingerprint pre-treatment application program, contrast characteristic's data among the microprocessor 102A in control module 102, and the function that picture switches causes apparatus of the present invention can be different from existing known technology, except the pre-treatment of making fingerprint by the microprocessor of end host to reduce the storage device cost, also designed simultaneously and automatically performed the function of fingerprint application program, exempted the puzzlement (being unfavorable for that portable type is used in others' computing machine) that needs to install at end host in advance identification of fingerprint and application program in the known technology in end host.And most important spirit of the present invention is, do not needing to increase under any hardware cost, the characteristic comparing function that fingerprint is last designs among the microprocessor 102A in control module 102 and carries out, can prevent your interception and crack, really reach the convenience of the security and the use of data confidentiality.Moreover the design of ciphering and deciphering device can prevent to steal data after memory module 104 from being pulled out.
What deserves to be explained is that the Any Application of public block of the present invention all is a read-only file, can't do any change.
In the present invention, a hidden blocks 104C is arranged in addition, this block need pass through direct and control module 102 communications of separate procedure, and this block is had no way of discovering by system, and the big I of hidden blocks 104C is adjusted according to design.Hidden blocks is deposited the template characteristic data, is encrypted golden key, electronic certificate ... wait private data.As required, size that also can hidden blocks is set to zero, and at this moment, end host only manifests secret block 104B and public block 104A in the disk in the face of the disk 600 that this device shone upon.
In another embodiment of the present invention, as shown in Figure 4, storage device 10 is except comprising the control module 102 that is similar to Fig. 1, memory module 104, beyond fingerprint sensor 106 and the host interface 108, can also comprise a storage expansion slot 103, this storage expansion slot 103 is in fact in order to the capacity of the storer that expands apparatus of the present invention, or by the reader (memory reader) that this device is considered as an external memorizer 105, this external memorizer such as CF card, intelligent media (smartmedia), the external memorizer of memory stick (memory stick) or other standard interface, or hard disk (particularly an inch or littler hard disk claim micro hard disk (micro drive) again).Expansion slot 103 is to be electrically connected with control module 102 by memory interface 110, in order to be electrically connected with an external memorizer 105, uses the memory span that increases storage device.After external memorizer 105 was inserted into expansion slot 103, control module 102 was planned to the secret block of single expansion with external memorizer 105, in order to store extra data to be protected.This device can provide the method for any external memorizer 105 data protections thus.Enciphering/deciphering device 102D also can pass in and out the data of external memorizer 105 in order to enciphering/deciphering.
By above-mentioned structure of the present invention, the on-line unit of being seen on the computer system, no longer comprise a non-volatility memorizer and a fingerprint sensor, so do not need the driver that is applicable to this non-volatility memorizer and this fingerprint sensor is installed simultaneously, so computer system does not need the running of two devices of control tasks.The substitute is, the on-line unit of being seen on the computer system only has a portable memory device, so computer system only need be controlled the running of a device.As for the running of non-volatility memorizer in the portable memory device and fingerprint sensor, can control by control module.It should be noted that the control module of indication of the present invention, can comprise other assembly of the running of control non-volatility memorizer and fingerprint sensor largo, such as ROM (read-only memory) (ROM), random-access memory (ram) etc.In addition, because last characteristic contrast action carries out in control module, and the administration authority of memory module is also in this control module, therefore is not afraid of to be cracked.In a word, end host is finished the most complicated image processing, and simple relatively characteristic contrast can be handled by microprocessor (for example 8051 processors), and the advantage that makes the present invention thereby captured autonomous device does not need to increase cost yet.
The embodiment that is proposed in the detailed description of preferred embodiment is only in order to convenient explanation technology contents of the present invention, rather than with narrow sense of the present invention be limited to the foregoing description, in not exceeding spirit of the present invention and claim, the many variations of being done is implemented, and all should belong to scope of the present invention.

Claims (12)

1. a storage device is connected with an end host, it is characterized in that this storage device comprises:
One host interface is in order to be connected with described end host;
One control module, be connected to described host interface, and comprise a microprocessor, a random access memory ram and a read only memory ROM, the working storage of described RAM during as data processing, and described ROM stores the firmware that makes described storage device work and for the program code of characteristic contrast usefulness;
One biological sensor is connected to described control module, in order to sensing one user's a biological data to be identified; And
One memory module is connected to described control module, and this memory module is split into:
One public block is in order to store a plurality of drivers and a plurality of application program;
One secret block is in order to store data to be protected; And
One hidden blocks, in order to store template characteristic data, wherein:
Described control module is handed over described end host by described host interface and is held communication, and makes described end host will be suitable for one of them driver of this end host and one of them application program being written into and being mounted in this end host;
The microprocessor of described control module is written into described template characteristic data;
Described end host receives from described user's by described driver and described application program and instructs, notifying described control module to control this biological data to be identified that described biology sensor reads this user, and should be sent in the described end host by biological data to be identified; And
Described end host utilizes described application program to handle described biological data to be identified and produces a characteristic to be identified, and should characteristic to be identified be transmitted back in the described microprocessor, this microprocessor utilizes described program code to judge whether described template characteristic data and described characteristic to be identified be identical in fact, and when coincideing in fact, make described secret block activation, otherwise make described secret block forbidden energy to prevent described end host access for described end host access.
2. storage device as claimed in claim 1 is characterized in that, described control module more comprises a hardware enciphering/deciphering device, passes in and out the data of described memory module in order to enciphering/deciphering.
3. storage device as claimed in claim 2; it is characterized in that; described hidden blocks makes described hardware enciphering/deciphering device according to this enciphering/deciphering gold key the data to be protected from the block access of described closed security zone be given encrypt/decrypt also in order to store enciphering/deciphering gold key.
4. storage device as claimed in claim 1 is characterized in that, described biology sensor is area-type fingerprint sensor or sweep fingerprint sensor.
5. storage device as claimed in claim 1 is characterized in that, also comprises:
One expansion slot is electrically connected with described control module, in order to be electrically connected with an external memorizer, uses the memory span that increases described storage device.
6. storage device as claimed in claim 5 is characterized in that, described control module also comprises an enciphering/deciphering device, passes in and out the data of described external memorizer in order to enciphering/deciphering.
7. storage device as claimed in claim 5 is characterized in that, after described external memorizer was inserted into described expansion slot, described control module was planned to the secret block of single expansion with this external memorizer, in order to store extra data to be protected.
8. the guard method of the storage data of a storage device, this storage device comprises a host interface, in order to be connected with an end host; One control module, be connected to described host interface, and comprise a microprocessor, a random access memory ram and a read only memory ROM, described RAM is the working storage during as data processing, and described ROM stores the firmware that makes described storage device work and for the program code of characteristic contrast usefulness; One biological sensor is connected to described control module, in order to sensing one authorized user's a template biological data; And a memory module, being connected to described control module, this memory module is split into: a public block, in order to store a plurality of drivers and a plurality of application program; One secret block is in order to store data to be protected; And a hidden blocks, wherein, with described storage device with after an end host is electrically connected, it is characterized in that described guard method comprises following steps:
Described control module is linked up with described end host by described host interface, and makes this end host will be suitable for one of them driver of this end host and one of them application program being written into and being mounted in the described end host; And
Enter a login mode or a certification mode,
In described login mode:
Described end host notifies described control module to control the described template biological data that described biology sensor reads described authorized user, and this template biological data is sent in the described end host; And
Described end host utilizes described application program to handle described template biological data and produces template characteristic data, and this template characteristic data transmission is stored to described hidden blocks; And
In described certification mode:
The microprocessor of described control module is written into described template characteristic data;
Described end host notifies described control module to control the biological data to be identified that described biology sensor reads a user, and should be sent in the described end host by biological data to be identified; And
Described end host utilizes described application program to handle described biological data to be identified and produces a characteristic to be identified, and should characteristic to be identified be transmitted back in the described microprocessor, this microprocessor utilizes described program code to judge whether described template characteristic data and described characteristic to be identified be identical in fact, and when coincideing in fact, make described secret block activation, otherwise make described secret block forbidden energy to prevent described end host access for described end host access.
9. the guard method of the storage data of storage device as claimed in claim 8 is characterized in that, described control module more comprises a hardware enciphering/deciphering device, passes in and out the data of described memory module in order to enciphering/deciphering.
10. the guard method of the storage data of storage device as claimed in claim 9; it is characterized in that; described hidden blocks makes described hardware enciphering/deciphering device according to this enciphering/deciphering gold key the data described to be protected from the block access of described closed security zone be given encrypt/decrypt more in order to store enciphering/deciphering gold key.
11. the guard method of the storage data of storage device as claimed in claim 8; wherein said storage device more comprises an expansion slot; be electrically connected with described control module; in order to be electrically connected with an external memorizer; use the memory span that increases this storage device; it is characterized in that this guard method more comprises following steps:
After described external memorizer was inserted into described expansion slot, described control module was planned to the secret block of single expansion with this external memorizer, in order to store extra data to be protected.
12. the guard method of the storage data of storage device as claimed in claim 11 is characterized in that, described control module more comprises an enciphering/deciphering device, passes in and out the data of described external memorizer in order to enciphering/deciphering.
CNB2005101320239A 2005-12-16 2005-12-16 Memory and method for protecting storage data Active CN100451999C (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
CNB2005101320239A CN100451999C (en) 2005-12-16 2005-12-16 Memory and method for protecting storage data

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
CNB2005101320239A CN100451999C (en) 2005-12-16 2005-12-16 Memory and method for protecting storage data

Publications (2)

Publication Number Publication Date
CN1983215A CN1983215A (en) 2007-06-20
CN100451999C true CN100451999C (en) 2009-01-14

Family

ID=38165768

Family Applications (1)

Application Number Title Priority Date Filing Date
CNB2005101320239A Active CN100451999C (en) 2005-12-16 2005-12-16 Memory and method for protecting storage data

Country Status (1)

Country Link
CN (1) CN100451999C (en)

Families Citing this family (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101968773A (en) * 2009-07-28 2011-02-09 茂晖科技股份有限公司 Data storage system with biometric protection and method thereof
JP4886866B2 (en) * 2010-02-10 2012-02-29 株式会社バッファロー Method for speeding up access to main storage device and storage device system
CN112700799B (en) * 2020-12-24 2023-02-10 上海良茂网络科技有限公司 Data storage device for computer software development

Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20020073340A1 (en) * 2000-12-12 2002-06-13 Sreenath Mambakkam Secure mass storage device with embedded biometri record that blocks access by disabling plug-and-play configuration
CN1462410A (en) * 2001-06-28 2003-12-17 特科2000国际有限公司 Portable device having biometrics-based authentication capabilities
US20050144464A1 (en) * 2003-12-02 2005-06-30 Aimgene Technology Co., Ltd Memory storage device with a fingerprint sensor and method for protecting the data therein
CN1696960A (en) * 2004-05-13 2005-11-16 瀚群科技股份有限公司 Method for protecting portable cryptographic storage device of containing biological identification and stored data

Patent Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20020073340A1 (en) * 2000-12-12 2002-06-13 Sreenath Mambakkam Secure mass storage device with embedded biometri record that blocks access by disabling plug-and-play configuration
CN1462410A (en) * 2001-06-28 2003-12-17 特科2000国际有限公司 Portable device having biometrics-based authentication capabilities
US20050144464A1 (en) * 2003-12-02 2005-06-30 Aimgene Technology Co., Ltd Memory storage device with a fingerprint sensor and method for protecting the data therein
CN1696960A (en) * 2004-05-13 2005-11-16 瀚群科技股份有限公司 Method for protecting portable cryptographic storage device of containing biological identification and stored data

Also Published As

Publication number Publication date
CN1983215A (en) 2007-06-20

Similar Documents

Publication Publication Date Title
US5515440A (en) Preboot protection of unauthorized use of programs and data with a card reader interface
US7519203B2 (en) Portable encrypted storage device with biometric identification and method for protecting the data therein
US7461266B2 (en) Storage device and method for protecting data stored therein
JP4221385B2 (en) Biometric authentication device, terminal device and automatic transaction device
TWI282940B (en) Memory storage device with a fingerprint sensor and method for protecting the data therein
US7337323B2 (en) Boot-up and hard drive protection using a USB-compliant token
US7845567B2 (en) Contactless card reader and information processing system
TWI326846B (en)
CN101986597A (en) Identity authentication system with biological characteristic recognition function and authentication method thereof
KR20150113152A (en) Smart card and smart card system with enhanced security features
WO2009095263A1 (en) Method of secure pin entry and operation mode setting in a personal portable device
CN101082884A (en) Finger print safety storage U disk
JP2006338670A (en) Portable storage device capable of automatically executing biometrics application and method for automatically executing biometrics application
CN101017462A (en) Portable memory devices having biological date protection mechanism and protection method thereof
US20080126810A1 (en) Data protection method for optical storage media/device
CN100451999C (en) Memory and method for protecting storage data
CN1284090C (en) Storage store device containing finger print senser and method for protecting its stored document
US7519829B2 (en) Storage device and method for protecting data stored therein
US20070150746A1 (en) Portable storage with bio-data protection mechanism & methodology
CN100452000C (en) Portable memory devices and method for automatically performing biology identification application program
WO2009038446A1 (en) A portable secure identity and mass storage unit
CN100476764C (en) Storage device and method for protecting stored data
CN1333348C (en) Method for protecting portable cryptographic storage device of containing biological identification and stored data
JP2007122731A (en) Hard disk apparatus with biometrics sensor and method of protecting data therein
CN101089896A (en) Protection method for file of optical store medium/device

Legal Events

Date Code Title Description
C06 Publication
PB01 Publication
C10 Entry into substantive examination
SE01 Entry into force of request for substantive examination
C14 Grant of patent or utility model
GR01 Patent grant
ASS Succession or assignment of patent right

Owner name: SHENDUN CO., LTD.

Free format text: FORMER OWNER: XIANGQUN SCIENCE CO., LTD.

Effective date: 20090807

C41 Transfer of patent application or patent right or utility model
TR01 Transfer of patent right

Effective date of registration: 20090807

Address after: Taipei city of Taiwan Province

Patentee after: Egis Technology Inc.

Address before: Hsinchu Science Industrial Park, Taiwan

Patentee before: Xiangqun Sci-Tech Co., Ltd.