WO2016015313A1 - 存储卡的加密方法和加密装置 - Google Patents

存储卡的加密方法和加密装置 Download PDF

Info

Publication number
WO2016015313A1
WO2016015313A1 PCT/CN2014/083486 CN2014083486W WO2016015313A1 WO 2016015313 A1 WO2016015313 A1 WO 2016015313A1 CN 2014083486 W CN2014083486 W CN 2014083486W WO 2016015313 A1 WO2016015313 A1 WO 2016015313A1
Authority
WO
WIPO (PCT)
Prior art keywords
memory card
key
encryption
user
level
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Ceased
Application number
PCT/CN2014/083486
Other languages
English (en)
French (fr)
Inventor
阳得常
燕青洲
程力行
王灿
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Yulong Computer Telecommunication Scientific Shenzhen Co Ltd
Original Assignee
Yulong Computer Telecommunication Scientific Shenzhen Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Yulong Computer Telecommunication Scientific Shenzhen Co Ltd filed Critical Yulong Computer Telecommunication Scientific Shenzhen Co Ltd
Priority to PCT/CN2014/083486 priority Critical patent/WO2016015313A1/zh
Priority to CN201480077810.5A priority patent/CN106462719A/zh
Publication of WO2016015313A1 publication Critical patent/WO2016015313A1/zh
Anticipated expiration legal-status Critical
Ceased legal-status Critical Current

Links

Classifications

    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/70Protecting specific internal or peripheral components, in which the protection of a component leads to protection of the entire computer
    • G06F21/71Protecting specific internal or peripheral components, in which the protection of a component leads to protection of the entire computer to assure secure computing or processing of information
    • G06F21/77Protecting specific internal or peripheral components, in which the protection of a component leads to protection of the entire computer to assure secure computing or processing of information in smart cards

Definitions

  • the present invention relates to the field of encryption technologies, and in particular, to an encryption method for a memory card and an encryption device for a memory card. Background technique
  • the SD card (Secure Digital Memory Card) confidential
  • the SD card can be directly encrypted.
  • the current encryption level is fixed, and the user cannot freely choose according to individual needs. Encryption level.
  • the user can only read the SD card on the terminal of the encrypted SD card, and cannot be in other terminals. The SD card is read on, which causes great inconvenience to the user.
  • the present invention is based on the above problems, and proposes a new technical solution, which enables the user to freely select the encryption level of the SD card according to individual needs, and improve the user experience of the encrypted SD card.
  • an aspect of the present invention provides a method for encrypting a memory card, which is used for a terminal, including: when encrypting a memory card, generating a key corresponding to the memory card; and encrypting according to a user selection The level stores the key in a different storage location; the memory card is encrypted using the key.
  • the user when the user encrypts the memory card, the user can select different encryption levels according to individual needs, and at the same time, after the user selects different encryption levels, the key corresponding to the memory card is also stored in different storage. Position, so that the user can only read the SD card on the terminal of the encrypted memory card or read the SD card on other terminals, which is beneficial to improve the user's Use experience.
  • the method further includes: encrypting the key.
  • the encrypted password input by the user can be used to encrypt the key, thereby increasing the security of the key, thereby increasing the security level of the SD card, so that Prevent unauthorized users (users without an encrypted password) from stealing keys.
  • the encryption level includes: a normal encryption level and an advanced encryption level, where the key is stored in the normal encryption level when the encryption level selected by the user is In the memory card; and when the encryption level selected by the user is the advanced encryption level, the key is stored in a preset storage area in the terminal using the memory card, and the secret may also be The key is stored in a hardware encryption chip in the terminal using the memory card.
  • the memory card can be normally encrypted so that the corresponding key is stored in the In the memory card, the user can use the memory card on different terminals as long as he has the encrypted password, which can greatly facilitate the user; on the contrary, if the user thinks that the data in the current memory card is very important, it is desirable to set it.
  • the memory card With a high security level, the memory card can be advancedly encrypted so that the corresponding key is stored in the terminal. Thus, since the key is not stored in other terminals, even if the illegal user obtains the encrypted password, It is also impossible to use the memory card on other terminals, which effectively enhances the security of the memory card.
  • the method further includes: determining, according to a privilege level of each application of the terminal, whether to allow the each application to invoke the preset storage area or the hardware encryption chip Said key.
  • the method further includes: when decrypting the memory card, clearing the key corresponding to the memory card from the storage location and modifying an encryption state of the memory card.
  • the terminal when the user decrypts the memory card, the terminal automatically clears the key of the memory card from the corresponding storage location to decrypt the memory card, and also modifies the encryption state of the memory card to be unencrypted, so as to avoid When the memory card is used again, the user is prompted to input an encrypted password to avoid inconvenience to the user.
  • Another aspect of the present invention provides an encryption device for a memory card, comprising: a generating unit, when encrypting a memory card, generating a key corresponding to the memory card; and storing a unit according to the user
  • the selected encryption level stores the key in a different storage location; an encryption unit that encrypts the memory card using the key.
  • the user when the user encrypts the memory card, the user can select different encryption levels according to individual needs, and at the same time, after the user selects different encryption levels, the key corresponding to the memory card is also stored in different storage.
  • the location so that the user can only read the SD card on the terminal of the encrypted memory card or read the SD card on other terminals, which is beneficial to improve the user experience.
  • the encryption unit is further configured to: encrypt the key before storing the key in a different storage location.
  • the encrypted password input by the user can be used to encrypt the key, thereby increasing the security of the key, thereby increasing the security level of the SD card, so that Prevent unauthorized users (users without an encrypted password) from stealing keys.
  • the encryption level includes: a normal encryption level and an advanced encryption level, where the storage unit is configured to: when the encryption level selected by the user is the normal encryption level, the density is The key is stored in the memory card; and the storage unit is further configured to: when the encryption level selected by the user is the advanced encryption level, store the key in a terminal using the memory card In the preset storage area, the key may also be stored in a hardware encryption chip in the terminal using the memory card.
  • the memory card can be generally encrypted to The corresponding key is stored in the memory card, so that the user can use the memory card on different terminals as long as the user has the encrypted password, which can greatly facilitate the user; on the contrary, if the user thinks that the data in the current memory card is very Importantly, if you want to set a high security level, you can perform advanced encryption on the memory card so that the corresponding key is stored in the terminal. Thus, since the key is not stored in other terminals, Even if an illegal user obtains an encrypted password, the memory card cannot be used on other terminals, which effectively enhances the security of the memory card.
  • the method further includes: determining, by the permission level of each application of the terminal, whether to allow the each application to invoke the preset storage area or the hardware encryption chip The key.
  • not every application can access the preset storage area or the hardware encryption chip and call the key from the preset storage area, and only the application whose permission level is higher than the preset level can invoke the key.
  • the key for example, only an application with a higher privilege level than the system privilege (such as an application with administrator privileges) can call the key, and the privilege level is lower than the system privilege, such as only applications with normal application privilege cannot be called.
  • This key which further enhances the security of the key, prevents the key from being illegally erased, resulting in the inability to decrypt.
  • the storage unit further includes: a processing unit, when decrypting the memory card, clearing the key corresponding to the memory card from the storage location and modifying the memory card Encryption status.
  • the terminal when the user decrypts the memory card, the terminal automatically clears the key of the memory card from the corresponding storage location to decrypt the memory card, and also modifies the encryption state of the memory card to be unencrypted, so as to avoid When the memory card is used again, the user is prompted to input an encrypted password to avoid inconvenience to the user.
  • the user can freely select the encryption level of the SD card according to individual needs, and improve the user experience of encrypting the SD card.
  • FIG. 1 is a flow chart showing an encryption method of a memory card according to an embodiment of the present invention
  • FIG. 2 is a flow chart showing an encryption method of a memory card according to another embodiment of the present invention
  • FIG. 3 is a block diagram showing the structure of an encryption device of a memory card according to an embodiment of the present invention. detailed description
  • FIG. 1 is a flow chart showing an encryption method of a memory card according to an embodiment of the present invention.
  • an encryption method of a memory card according to an embodiment of the present invention includes: Step 102: When encrypting a memory card, generate a key corresponding to the memory card; Step 104, according to user selection The encryption level stores the key in a different storage location; the memory card is encrypted using the key.
  • the user when the user encrypts the memory card, the user can select different encryption levels according to individual needs, and at the same time, after the user selects different encryption levels, the key corresponding to the memory card is also stored in different storage.
  • the location is such that the user can only read the SD card on the terminal of the encrypted memory card or read the SD card on other terminals, which is beneficial to improve the user experience.
  • the method further includes: encrypting the key.
  • the encrypted password input by the user can be used to encrypt the key, thereby increasing the security of the key, thereby increasing the security level of the SD card, so that Prevent unauthorized users (users without an encrypted password) from stealing keys.
  • the encryption level includes: a normal encryption level and an advanced encryption level, where the key is stored in the normal encryption level when the encryption level selected by the user is In the memory card; and when the encryption level selected by the user is the advanced encryption level, the key is stored in a preset storage area in the terminal using the memory card, and the secret may also be The key is stored in a hardware encryption core in the terminal using the memory card In the film.
  • the memory card can be normally encrypted so that the corresponding key is stored in the In the memory card, the user can use the memory card on different terminals as long as he has the encrypted password, which can greatly facilitate the user; on the contrary, if the user thinks that the data in the current memory card is very important, it is desirable to set it.
  • the memory card With a high security level, the memory card can be advancedly encrypted so that the corresponding key is stored in the terminal. Thus, since the key is not stored in other terminals, even if the illegal user obtains the encrypted password, It is also impossible to use the memory card on other terminals, which effectively enhances the security of the memory card.
  • the method further includes: determining, according to a privilege level of each application of the terminal, whether to allow the each application to invoke the preset storage area or the secret in the hardware encryption chip key.
  • not every application can access the preset storage area or the hardware encryption chip and call the key from the preset storage area, and only the application whose permission level is higher than the preset level can invoke the key.
  • Keys for example, only applications with a privilege level higher than the system privilege (such as an application with administrator privileges) can call the key, and the privilege level is lower than the system privilege. For example, only applications with normal application privilege will not be able to Calling this key further enhances the security of the key and prevents the key from being illegally erased, making it impossible to decrypt.
  • the method further includes: when decrypting the memory card, clearing the key corresponding to the memory card from the storage location and modifying an encryption state of the memory card.
  • the terminal when the user decrypts the memory card, the terminal automatically clears the key of the memory card from the corresponding storage location to decrypt the memory card, and also modifies the encryption state of the memory card to be unencrypted, so as to avoid When the memory card is used again, the user is prompted to input an encrypted password to avoid inconvenience to the user.
  • Fig. 2 is a flow chart showing an encryption method of a memory card in accordance with another embodiment of the present invention.
  • the encryption method of the memory card includes: Step 202: The user enters an interface of encrypting SD. Step 204, prompting the user to input a password, and performing the steps after the password is verified.
  • Step 206 The user acquires an encryption status of the SD card.
  • Step 208 Determine whether the SD card is encrypted, and when the SD card is encrypted, perform step 210. When the SD card is not encrypted, perform step 218.
  • Step 210 When the SD card is encrypted, prompt the user whether to decrypt the SD card with an external SD card (wherein the external SD card is an SD card that can be removed from the terminal, relative to the fixed SD card provided by the terminal).
  • an external SD card is an SD card that can be removed from the terminal, relative to the fixed SD card provided by the terminal.
  • Step 212 the user inputs a decryption instruction.
  • Step 214 clear the encryption status of the SD card.
  • Step 216 After clearing the encryption status of the SD card, clear the key corresponding to the SD card, so as to decrypt the SD card.
  • Step 218 When the SD card is not encrypted, the SD card is strongly encrypted according to an encryption instruction input by the user.
  • Step 220 Prompt the user to select advanced encryption. After the user selects advanced encryption, step 222 is performed; otherwise, step 232 is performed.
  • Step 222 When the user performs advanced encryption on the SD card, create a key corresponding to the SD card encryption process.
  • Step 224 Encrypt the key according to the encrypted password input by the user.
  • Step 226 Save the key to a specified storage area in the terminal.
  • Step 228 Encrypt the data in the SD card according to the encryption key, and change it from plaintext to ciphertext.
  • Step 230 setting the encryption status of the SD card to be encrypted.
  • Step 232 Receive a normal encryption instruction input by the user.
  • Step 234 creating a key corresponding to the SD card encryption process.
  • Step 236 Encrypt the key according to the encrypted password input by the user.
  • Step 238, save the key to the SD card, and perform step 228.
  • this embodiment determines that it is advanced encryption (step 220) or normal encryption before creating the key (step 222 and step 234) and the encryption key (steps 224 and 236). (Step 232), however, those skilled in the art should understand that determining advanced encryption (step 220) or normal encryption (step 232) may also be done after the encryption key (steps 224 and 236), and in the advanced After the judgment is made by encryption or normal encryption, step 226 or 238 is executed according to the judgment result.
  • FIG. 3 is a block diagram showing the structure of an encryption device of a memory card according to an embodiment of the present invention.
  • the encryption device 300 of the memory card according to the embodiment of the present invention includes: a generating unit 302, when encrypting the memory card, generating a key corresponding to the memory card; the storage unit 304, The key is stored in a different storage location according to the encryption level selected by the user; the encryption unit 306 encrypts the memory card using the key.
  • the user when the user encrypts the memory card, the user can select different encryption levels according to individual needs, and at the same time, after the user selects different encryption levels, the key corresponding to the memory card is also stored in different storage.
  • the location is such that the user can only read the SD card on the terminal of the encrypted memory card or read the SD card on other terminals, which is beneficial to improve the user experience.
  • the encryption unit 306 is further configured to: encrypt the key before storing the key in a different storage location.
  • the encrypted password input by the user can be used to encrypt the key, thereby increasing the security of the key, thereby increasing the security level of the SD card, so that Prevent unauthorized users (users without an encrypted password) from stealing keys.
  • the encryption level includes: a normal encryption level and an advanced encryption level
  • the storage unit 304 is configured to: when the encryption level selected by the user is the normal encryption level, a key is stored in the memory card; and the storage unit 304 is further configured to: when the encryption level selected by the user is the advanced encryption level, store the key in a terminal using the memory card
  • the key may also be stored in a hardware encryption chip in the terminal using the memory card.
  • the memory card can be normally encrypted so that the corresponding key is stored in the In the memory card, the user can use the memory card on different terminals as long as he has the encrypted password, which can greatly facilitate the user; otherwise, if the user thinks The data in the current memory card is very important. If you want to set a high security level, you can perform advanced encryption on the memory card so that the corresponding key is stored in the terminal. The key is not stored, and therefore, even if an illegal user obtains an encrypted password, the memory card cannot be used on other terminals, which effectively enhances the security of the memory card.
  • the method further includes: a determining unit 308, determining, according to a privilege level of each application of the terminal, whether to allow the each application to invoke the preset storage area or the hardware encryption The key in the chip.
  • not every application can access the preset storage area or the hardware encryption chip and call the key from the preset storage area, and only the application whose privilege level is higher than the preset level can Calling the key, for example, only applications with a privilege level higher than the system privilege (such as an application with administrator privileges) can call the key, and the privilege level is lower than the system privilege, such as only applications with normal app privilege
  • the key will not be called, which further enhances the security of the key and prevents the key from being illegally erased, making it impossible to decrypt.
  • the storage unit 304 further includes: a processing unit 3042, when decrypting the memory card, clearing the key corresponding to the memory card from the storage location and modifying the The encryption status of the memory card.
  • the terminal when the user decrypts the memory card, the terminal automatically clears the key of the memory card from the corresponding storage location to decrypt the memory card, and also modifies the encryption state of the memory card to be unencrypted, so as to avoid When the memory card is used again, the user is prompted to input an encrypted password to avoid inconvenience to the user.
  • the technical solution of the present invention is described in detail above with reference to the accompanying drawings.
  • the user can freely select the encryption level of the SD card according to individual needs, and improve the user experience of encrypting the SD card.
  • the present invention can also implement hierarchical encryption on data in a memory card, such as mail, short messages, contacts, pictures, videos, and the like.
  • the method is: when encrypting data in the memory card, generating a key corresponding to the data in the memory card; storing the key in a different storage location according to an encryption level selected by the user; The key encrypts the data in the memory card.
  • important data such as SMS, contacts, etc.
  • users can choose the advanced encryption level and store the key in the terminal.
  • the data user can select a normal encryption level, and store the key in the memory card.
  • a program product stored on a non-transitory machine readable medium, an encryption method for a memory card in a terminal, the program product comprising a computer system for causing a computer system to execute the following a machine executable instruction of the step: when encrypting the memory card, generating a key corresponding to the memory card; storing the key in a different storage location according to an encryption level selected by the user; using the key Encrypt the memory card.
  • a nonvolatile machine readable medium storing an encrypted program product for a memory card in a terminal, the program product comprising a machine executable for causing a computer system to perform the following steps An instruction: when encrypting the memory card, generating a key corresponding to the memory card; storing the key in a different storage location according to an encryption level selected by the user; using the key to the memory card Encrypt.
  • a machine readable program the program causing a machine to perform an encryption method of a memory card according to any one of the above aspects.
  • a storage medium storing a machine readable program, wherein the machine readable program causes a machine to perform an encryption method of a memory card according to any one of the above aspects.

Landscapes

  • Engineering & Computer Science (AREA)
  • Physics & Mathematics (AREA)
  • Computer Hardware Design (AREA)
  • Theoretical Computer Science (AREA)
  • Mathematical Physics (AREA)
  • Computer Security & Cryptography (AREA)
  • Software Systems (AREA)
  • General Engineering & Computer Science (AREA)
  • General Physics & Mathematics (AREA)
  • Storage Device Security (AREA)

Abstract

本发明提出了一种存储卡的加密方法和一种存储卡的加密装置,其中,存储卡的加密方法包括:在对存储卡进行加密时,生成与所述存储卡相对应的密钥;根据用户选择的加密级别将所述密钥存储在不同的存储位置;使用所述密钥对所述存储卡进行加密。通过本发明的技术方案,可以使用户根据个人需求自由选择SD卡的加密级别,并提高用户加密SD卡的使用体验。

Description

存储卡的加密方法和加密装置
技术领域
本发明涉及加密技术领域, 具体而言, 涉及一种存储卡的加密方法和 一种存储卡的加密装置。 背景技术
目前, 如果用户希望对 SD卡(Secure Digital Memory Card, 存储卡)的 数据进行保密, 则可以直接对 SD 卡进行加密即可, 但是, 目前的加密级 别是固定的, 用户无法根据个人需要自由选择加密级别, 同时, 在 SD 卡 被加密后, 由于加密密钥是存储在加密 SD 卡的终端上的, 因而, 用户也 只能在加密 SD 卡的终端上读取该 SD 卡, 无法在其它终端上读取该 SD 卡, 这给用户带来很大不便。
因此, 如何使用户可以根据个人需求自由选择 SD 卡的加密级别, 提 高用户加密 SD卡的使用体验, 成为亟待解决的问题。 发明内容
本发明正是基于上述问题, 提出了一种新的技术方案, 可以使用户根 据个人需求自由选择 SD卡的加密级别, 并提高用户加密 SD卡的使用体 验。
有鉴于此, 本发明的一方面提出了一种存储卡的加密方法, 用于终 端, 包括: 在对存储卡进行加密时, 生成与所述存储卡相对应的密钥; 根 据用户选择的加密级别将所述密钥存储在不同的存储位置; 使用所述密钥 对所述存储卡进行加密。
在该技术方案中, 在用户对存储卡加密时, 用户可以根据个人需求选 择不同的加密级别, 同时, 在用户选择不同的加密级别后, 与存储卡相应 的密钥也被存储在不同的存储位置, 以使用户只能在加密存储卡的终端上 读取该 SD卡或在其它终端上也可以读取该 SD卡, 这有利于提高用户的 使用体验。
在上述技术方案中, 优选地, 在将所述密钥存储在不同的存储位置之 前, 还包括: 对所述密钥进行加密。
在该技术方案中, 在用户对存储卡 (如 SD 卡) 进行加密时, 用户输 入的加密密码可以用来加密密钥, 以增加密钥的安全性, 进而增加 SD 卡 的安全级别, 这样可以防止非法用户 (没有加密密码的用户) 窃取密钥。
在上述技术方案中, 优选地, 所述加密级别包括: 普通加密级别和高 级加密级别, 其中, 在所述用户选择的加密级别为所述普通加密级别时, 将所述密钥存储在所述存储卡中; 以及在所述用户选择的加密级别为所述 高级加密级别时, 将所述密钥存储在使用所述存储卡的终端中的预设存储 区中, 也可可以将所述密钥存储在使用所述存储卡的终端中的硬件加密芯 片中。
在该技术方案中, 如果用户认为当前存储卡中的数据不是至关重要 的, 不希望对其设置很高的安全级别, 则可以对存储卡进行普通加密, 以 使对应的密钥被存储在存储卡中, 这样用户只要拥有加密密码就可以在不 同的终端上使用该存储卡, 这可以极大地方便用户; 反之, 如果用户认为 当前存储卡中的数据非常至关重要的, 希望对其设置很高的安全级别, 则 可以对存储卡进行高级加密时, 以使对应的密钥被存储在终端中, 这样, 由于其它终端中未存储有该密钥, 因而, 即便非法用户获得了加密密码也 无法在其它终端上使用该存储卡, 这有效地增强了存储卡的安全性。
在上述技术方案中, 优选地, 还包括: 根据所述终端的每个应用程序 的权限级别, 确定是否允许所述每个应用程序调用所述预设存储区或所述 硬件加密芯片中的所述密钥。
在该技术方案中, 并不是每个应用程序都可以访问预设存储区或所述 硬件加密芯片并从该预设存储区中调用该密钥, 只有权限级别高于预设级 别的应用程序才能调用该密钥, 例如, 只有权限级别高于系统权限的应用 程序 (如拥有管理员权限的应用程序) 才能调用该密钥, 而权限级别低于 系统权限, 如只有拥有普通应用权限的应用程序将无法调用该密钥, 这进 一步增强了密钥的安全性, 可以防止密钥被非法抹掉, 导致无法解密。 在上述技术方案中, 优选地, 还包括: 在解密所述存储卡时, 将所述 存储卡对应的所述密钥从所述存储位置清除并修改所述存储卡的加密状 态。
在该技术方案中, 当用户解密存储卡时, 终端会自动地将存储卡的密 钥从对应的存储位置清除以解密该存储卡, 同时也将该存储卡的加密状态 修改为未加密, 以免再次使用该存储卡时, 误提示用户输入加密密码, 以 避免给用户带来不便。
本发明的另一方面提出了一种存储卡的加密装置, 用于终端, 包括: 生成单元, 在对存储卡进行加密时, 生成与所述存储卡相对应的密钥; 存 储单元, 根据用户选择的加密级别将所述密钥存储在不同的存储位置; 加 密单元, 使用所述密钥对所述存储卡进行加密。
在该技术方案中, 在用户对存储卡加密时, 用户可以根据个人需求选 择不同的加密级别, 同时, 在用户选择不同的加密级别后, 与存储卡相应 的密钥也被存储在不同的存储位置, 以使用户只能在加密存储卡的终端上 读取该 SD卡或在其它终端上也可以读取 SD卡, 这有利于提高用户的使 用体验。
在上述技术方案中, 优选地, 所述加密单元还用于: 在将所述密钥存 储在不同的存储位置之前, 对所述密钥进行加密。
在该技术方案中, 在用户对存储卡 (如 SD 卡) 进行加密时, 用户输 入的加密密码可以用来加密密钥, 以增加密钥的安全性, 进而增加 SD 卡 的安全级别, 这样可以防止非法用户 (没有加密密码的用户) 窃取密钥。
在上述技术方案中, 优选地, 所述加密级别包括: 普通加密级别和高 级加密级别, 所述存储单元用于: 在所述用户选择的加密级别为所述普通 加密级别时, 将所述密钥存储在所述存储卡中; 以及所述存储单元还用 于: 在所述用户选择的加密级别为所述高级加密级别时, 将所述密钥存储 在使用所述存储卡的终端中的预设存储区中, 也可可以将所述密钥存储在 使用所述存储卡的终端中的硬件加密芯片中。
在该技术方案中, 如果用户认为当前存储卡中的数据不是至关重要 的, 不希望对其设置很高的安全级别, 则可以对存储卡进行普通加密, 以 使对应的密钥被存储在存储卡中, 这样用户只要拥有加密密码就可以在不 同的终端上使用该存储卡, 这可以极大地方便用户; 反之, 如果用户认为 当前存储卡中的数据非常至关重要的, 希望对其设置很高的安全级别, 则 可以对存储卡进行高级加密时, 以使对应的密钥被存储在终端中, 这样, 由于其它终端中未存储有该密钥, 因而, 即便非法用户获得了加密密码也 无法在其它终端上使用该存储卡, 这有效地增强了存储卡的安全性。
在上述技术方案中, 优选地, 还包括: 确定单元, 根据所述终端的每 个应用程序的权限级别, 确定是否允许所述每个应用程序调用所述预设存 储区或硬件加密芯片中的所述密钥。
在该技术方案中, 并不是每个应用程序都可以访问预设存储区或硬件 加密芯片并从该预设存储区中调用该密钥, 只有权限级别高于预设级别的 应用程序才能调用该密钥, 例如, 只有权限级别高于系统权限的应用程序 (如拥有管理员权限的应用程序) 才能调用该密钥, 而权限级别低于系统 权限, 如只有拥有普通应用权限的应用程序无法调用该密钥, 这进一步增 强了密钥的安全性, 可以防止密钥被非法抹掉, 导致无法解密。
在上述技术方案中, 优选地, 所述存储单元还包括: 处理单元, 在解 密所述存储卡时, 将所述存储卡对应的所述密钥从所述存储位置清除并修 改所述存储卡的加密状态。
在该技术方案中, 当用户解密存储卡时, 终端会自动地将存储卡的密 钥从对应的存储位置清除以解密该存储卡, 同时也将该存储卡的加密状态 修改为未加密, 以免再次使用该存储卡时, 误提示用户输入加密密码, 以 避免给用户带来不便。
通过以上技术方案, 可以使用户根据个人需求自由选择 SD 卡的加密 级别, 并提高用户加密 SD卡的使用体验。 附图说明
图 1示出了根据本发明的实施例的存储卡的加密方法的流程示意图; 图 2示出了根据本发明的另一个实施例的存储卡的加密方法的流程示 意图; 图 3示出了根据本发明的实施例存储卡的加密装置的结构示意图。 具体实施方式
为了能够更清楚地理解本发明的上述目的、 特征和优点, 下面结合附 图和具体实施方式对本发明进行进一步的详细描述。 需要说明的是, 在不 冲突的情况下, 本申请的实施例及实施例中的特征可以相互组合。
在下面的描述中阐述了很多具体细节以便于充分理解本发明, 但是, 本发明还可以釆用其他不同于在此描述的其他方式来实施, 因此, 本发明 的保护范围并不受下面公开的具体实施例的限制。
图 1示出了根据本发明的实施例的存储卡的加密方法的流程示意图。 如图 1 所示, 根据本发明的实施例的存储卡的加密方法, 包括: 步骤 102 , 在对存储卡进行加密时, 生成与所述存储卡相对应的密钥; 步骤 104, 根据用户选择的加密级别将所述密钥存储在不同的存储位置; 使用 所述密钥对所述存储卡进行加密。
在该技术方案中, 在用户对存储卡加密时, 用户可以根据个人需求选 择不同的加密级别, 同时, 在用户选择不同的加密级别后, 与存储卡相应 的密钥也被存储在不同的存储位置, 以使用户只能在加密存储卡的终端上 被读取该 SD卡或在其它终端上也可以读取 SD卡, 这有利于提高用户的 使用体验。
在上述技术方案中, 优选地, 在将所述密钥存储在不同的存储位置之 前, 还包括: 对所述密钥进行加密。
在该技术方案中, 在用户对存储卡 (如 SD 卡) 进行加密时, 用户输 入的加密密码可以用来加密密钥, 以增加密钥的安全性, 进而增加 SD 卡 的安全级别, 这样可以防止非法用户 (没有加密密码的用户) 窃取密钥。
在上述技术方案中, 优选地, 所述加密级别包括: 普通加密级别和高 级加密级别, 其中, 在所述用户选择的加密级别为所述普通加密级别时, 将所述密钥存储在所述存储卡中; 以及在所述用户选择的加密级别为所述 高级加密级别时, 将所述密钥存储在使用所述存储卡的终端中的预设存储 区中, 也可可以将所述密钥存储在使用所述存储卡的终端中的硬件加密芯 片中。
在该技术方案中, 如果用户认为当前存储卡中的数据不是至关重要 的, 不希望对其设置很高的安全级别, 则可以对存储卡进行普通加密, 以 使对应的密钥被存储在存储卡中, 这样用户只要拥有加密密码就可以在不 同的终端上使用该存储卡, 这可以极大地方便用户; 反之, 如果用户认为 当前存储卡中的数据非常至关重要的, 希望对其设置很高的安全级别, 则 可以对存储卡进行高级加密时, 以使对应的密钥被存储在终端中, 这样, 由于其它终端中未存储有该密钥, 因而, 即便非法用户获得了加密密码也 无法在其它终端上使用该存储卡, 这有效地增强了存储卡的安全性。
在上述技术方案中, 优选地, 还包括: 根据所述终端的每个应用程序 的权限级别, 确定是否允许所述每个应用程序调用所述预设存储区或硬件 加密芯片中的所述密钥。
在该技术方案中, 并不是每个应用程序都可以访问预设存储区或硬件 加密芯片并从该预设存储区中调用该密钥, 只有权限级别高于预设级别的 应用程序才能调用该密钥, 例如, 只有权限级别高于系统权限的应用程序 (如拥有管理员权限的应用程序) 才能调用该密钥, 而权限级别低于系统 权限, 如只有拥有普通应用权限的应用程序将无法调用该密钥, 这进一步 增强了密钥的安全性, 可以防止密钥被非法抹掉, 导致无法解密。
在上述技术方案中, 优选地, 还包括: 在解密所述存储卡时, 将所述 存储卡对应的所述密钥从所述存储位置清除并修改所述存储卡的加密状 态。
在该技术方案中, 当用户解密存储卡时, 终端会自动地将存储卡的密 钥从对应的存储位置清除以解密该存储卡, 同时也将该存储卡的加密状态 修改为未加密, 以免再次使用该存储卡时, 误提示用户输入加密密码, 以 避免给用户带来不便。
图 2示出了根据本发明的另一个实施例的存储卡的加密方法的流程示 意图。
如图 2所示, 根据本发明的实施例的存储卡的加密方法, 包括: 步骤 202, 用户进入加密 SD的界面。 步骤 204, 提示用户输入密码, 并在密码通过验证之后执行步骤
206。
步骤 206, 用户获取 SD卡的加密状态。
步骤 208, 判断 SD卡是否已加密, 并在 SD卡已加密时, 执行步骤 210 , 在 SD卡未加密时, 执行步骤 218。
步骤 210, 在 SD卡已加密时, 提示用户是否对 SD卡进行解密外置 SD卡 (其中, 外置 SD卡为可以移出终端的 SD卡, 相对于终端自带的固 定 SD卡而言 ) 。
步骤 212, 用户输入解密指令。
步骤 214, 清除该 SD卡的加密状态。
步骤 216, 在清除该 SD卡的加密状态后, 清除 SD卡对应的密钥, 以实现解密 SD卡。
步骤 218, 在 SD卡未加密时, 根据用户输入的加密指令, 对 SD卡 进行力口密。
步骤 220, 提示用户是否选择高级加密, 在用户选择高级加密后, 执 行步骤 222; 否则, 执行步骤 232。
步骤 222, 在用户对 SD卡进行高级加密时, 创建与 SD卡加密过程 对应的密钥。
步骤 224, 根据用户输入的加密密码对密钥进行加密。
步骤 226, 将该密钥保存至终端中的指定存储区。
步骤 228 根据加密密钥对 SD 卡中的数据进行加密, 使其从明文变 成密文。
步骤 230, 将该 SD卡的加密状态设置为已加密。
步骤 232, 接收用户输入的普通加密指令。
步骤 234, 创建与 SD卡加密过程对应的密钥。
步骤 236, 根据用户输入的加密密码对密钥进行加密。
步骤 238, 将该密钥保存至 SD卡中, 并执行步骤 228。
当然, 本实施例是在创建密钥 (步骤 222 和步骤 234 ) 与加密密钥 (步骤 224和步骤 236 )之前, 判断是高级加密 (步骤 220 ) 或普通加密 (步骤 232 ) 的, 但是, 本领域技术人员应该可以理解, 判断高级加密 (步骤 220 ) 或普通加密 (步骤 232 )也可以在加密密钥 (步骤 224 和步 骤 236 ) 之后完成, 并在对高级加密或普通加密进行判断之后, 根据判断 结果执行步骤 226或 238。
图 3示出了根据本发明的实施例存储卡的加密装置的结构示意图。 如图 3 所示, 根据本发明的实施例的存储卡的加密装置 300, 包括: 生成单元 302, 在对存储卡进行加密时, 生成与所述存储卡相对应的密 钥; 存储单元 304, 根据用户选择的加密级别将所述密钥存储在不同的存 储位置; 加密单元 306, 使用所述密钥对所述存储卡进行加密。
在该技术方案中, 在用户对存储卡加密时, 用户可以根据个人需求选 择不同的加密级别, 同时, 在用户选择不同的加密级别后, 与存储卡相应 的密钥也被存储在不同的存储位置, 以使用户只能在加密存储卡的终端上 读取该 SD卡或在其它终端上也可以读取该 SD卡, 这有利于提高用户的 使用体验。
在上述技术方案中, 优选地, 所述加密单元 306还用于: 在将所述密 钥存储在不同的存储位置之前, 对所述密钥进行加密。
在该技术方案中, 在用户对存储卡 (如 SD 卡) 进行加密时, 用户输 入的加密密码可以用来加密密钥, 以增加密钥的安全性, 进而增加 SD 卡 的安全级别, 这样可以防止非法用户 (没有加密密码的用户) 窃取密钥。
在上述技术方案中, 优选地, 所述加密级别包括: 普通加密级别和高 级加密级别, 所述存储单元 304用于: 在所述用户选择的加密级别为所述 普通加密级别时, 将所述密钥存储在所述存储卡中; 以及所述存储单元 304 还用于: 在所述用户选择的加密级别为所述高级加密级别时, 将所述 密钥存储在使用所述存储卡的终端中的预设存储区中, 也可可以将所述密 钥存储在使用所述存储卡的终端中的硬件加密芯片中。
在该技术方案中, 如果用户认为当前存储卡中的数据不是至关重要 的, 不希望对其设置很高的安全级别, 则可以对存储卡进行普通加密, 以 使对应的密钥被存储在存储卡中, 这样用户只要拥有加密密码就可以在不 同的终端上使用该存储卡, 这可以极大地方便用户; 反之, 如果用户认为 当前存储卡中的数据非常至关重要的, 希望对其设置很高的安全级别, 则 可以对存储卡进行高级加密时, 以使对应的密钥被存储在终端中, 这样, 由于其它终端中未存储有该密钥, 因而, 即便非法用户获得了加密密码也 无法在其它终端上使用该存储卡, 这有效地增强了存储卡的安全性。
在上述技术方案中, 优选地, 还包括: 确定单元 308, 根据所述终端 的每个应用程序的权限级别, 确定是否允许所述每个应用程序调用所述预 设存储区或所述硬件加密芯片中的所述密钥。
在该技术方案中, 并不是每个应用程序都可以访问预设存储区或所述 硬件加密芯片并从该预设存储区中调用该密钥, 只有权限级别高于预设级 别的应用程序才能调用该密钥, 例如, 只有权限级别高于系统权限的应用 程序 (如拥有管理员权限的应用程序) 才能调用该密钥, 而权限级别低于 系统权限, 如只有拥有普通应用权限的应用程序将无法调用该密钥, 这进 一步增强了密钥的安全性, 可以防止密钥被非法抹掉, 导致无法解密。
在上述技术方案中, 优选地, 所述存储单元 304 还包括: 处理单元 3042, 在解密所述存储卡时, 将所述存储卡对应的所述密钥从所述存储位 置清除并修改所述存储卡的加密状态。
在该技术方案中, 当用户解密存储卡时, 终端会自动地将存储卡的密 钥从对应的存储位置清除以解密该存储卡, 同时也将该存储卡的加密状态 修改为未加密, 以免再次使用该存储卡时, 误提示用户输入加密密码, 以 避免给用户带来不便。
以上结合附图详细说明了本发明的技术方案, 通过本发明的技术方 案, 可以使用户根据个人需求自由选择 SD 卡的加密级别, 并提高用户加 密 SD卡的使用体验。
本发明除可以对存储卡 (如 SD 卡) 进行分级加密外, 还可以实现对 存储卡内的数据, 如邮件、 短信、 联系人、 图片、 视频等数据, 实行分级 加密。 其方法为: 在对存储卡中的数据进行加密时, 生成与所述存储卡中 数据相对应的密钥; 根据用户选择的加密级别将所述密钥存储在不同的存 储位置; 使用所述密钥对所述存储卡中数据进行加密。 对重要数据, 如短 信、 联系人等数据, 用户可以选择高级加密级别, 并将密钥存储于终端特 定存储区或硬件加密芯片中; 对普通数据, 如图片、 视频等, 数据用户可 以选择普通加密级别, 将密钥存储于所述存储卡中。
根据本发明的实施方式, 还提供了一种存储在非易失性机器可读介质 上的程序产品, 用于终端中的存储卡的加密方法, 所述程序产品包括用于 使计算机系统执行以下步骤的机器可执行指令: 在对存储卡进行加密时, 生成与所述存储卡相对应的密钥; 根据用户选择的加密级别将所述密钥存 储在不同的存储位置; 使用所述密钥对所述存储卡进行加密。
根据本发明的实施方式, 还提供了一种非易失机器可读介质, 存储有 用于终端中存储卡的加密的程序产品, 所述程序产品包括用于使计算机系 统执行以下步骤的机器可执行指令: 在对存储卡进行加密时, 生成与所述 存储卡相对应的密钥; 根据用户选择的加密级别将所述密钥存储在不同的 存储位置; 使用所述密钥对所述存储卡进行加密。
根据本发明的实施方式, 还提供了一种机器可读程序, 所述程序使机 器执行如上所述技术方案中任一所述的存储卡的加密方法。
根据本发明的实施方式, 还提供了一种存储有机器可读程序的存储介 质, 其中, 所述机器可读程序使得机器执行如上所述技术方案中任一所述 的存储卡的加密方法。
以上所述仅为本发明的优选实施例而已, 并不用于限制本发明, 对于 本领域的技术人员来说, 本发明可以有各种更改和变化。 凡在本发明的精 神和原则之内, 所作的任何修改、 等同替换、 改进等, 均应包含在本发明 的保护范围之内。

Claims

权 利 要 求 书
1. 一种存储卡的加密方法, 用于终端, 其特征在于, 包括: 在对存储卡进行加密时, 生成与所述存储卡相对应的密钥;
根据用户选择的加密级别将所述密钥存储在不同的存储位置; 使用所述密钥对所述存储卡进行加密。
2. 根据权利要求 1 所述的存储卡的加密方法, 其特征在于, 在将所 述密钥存储在不同的存储位置之前, 还包括: 对所述密钥进行加密。
3. 根据权利要求 1 所述的存储卡的加密方法, 其特征在于, 所述加 密级别包括: 普通加密级别和高级加密级别, 其中,
在所述用户选择的加密级别为所述普通加密级别时, 将所述密钥存储 在所述存储卡中; 以及
在所述用户选择的加密级别为所述高级加密级别时, 将所述密钥存储 在使用所述存储卡的终端中的预设存储区中。
4. 根据权利要求 3 所述的存储卡的加密方法, 其特征在于, 还包 括:
根据所述终端的每个应用程序的权限级别, 确定是否允许所述每个应 用程序调用所述预设存储区中的所述密钥。
5. 根据权利要求 1 至 4 中任一项所述的存储卡的加密方法, 其特征 在于, 还包括:
在解密所述存储卡时, 将所述存储卡对应的所述密钥从所述存储位置 清除并修改所述存储卡的加密状态。
6. 一种存储卡的加密装置, 用于终端, 其特征在于, 包括: 生成单元, 在对存储卡进行加密时, 生成与所述存储卡相对应的密 钥;
存储单元, 根据用户选择的加密级别将所述密钥存储在不同的存储位 置;
加密单元, 使用所述密钥对所述存储卡进行加密。
7. 根据权利要求 6 所述的存储卡的加密装置, 其特征在于, 所述加 密单元还用于: 在将所述密钥存储在不同的存储位置之前, 对所述密钥进 行力口密。
8. 根据权利要求 6 所述的存储卡的加密装置, 其特征在于, 所述加 密级别包括: 普通加密级别和高级加密级别,
所述存储单元用于: 在所述用户选择的加密级别为所述普通加密级别 时, 将所述密钥存储在所述存储卡中; 以及
所述存储单元还用于: 在所述用户选择的加密级别为所述高级加密级 别时, 将所述密钥存储在使用所述存储卡的终端中的预设存储区中。
9. 根据权利要求 8 所述的存储卡的加密装置, 其特征在于, 还包 括:
确定单元, 根据所述终端的每个应用程序的权限级别, 确定是否允许 所述每个应用程序调用所述预设存储区中的所述密钥。
10. 根据权利要求 6至 9中任一项所述的存储卡的加密装置, 其特征 在于, 所述存储单元还包括:
处理单元, 在解密所述存储卡时, 将所述存储卡对应的所述密钥从所 述存储位置清除并修改所述存储卡的加密状态。
PCT/CN2014/083486 2014-07-31 2014-07-31 存储卡的加密方法和加密装置 Ceased WO2016015313A1 (zh)

Priority Applications (2)

Application Number Priority Date Filing Date Title
PCT/CN2014/083486 WO2016015313A1 (zh) 2014-07-31 2014-07-31 存储卡的加密方法和加密装置
CN201480077810.5A CN106462719A (zh) 2014-07-31 2014-07-31 存储卡的加密方法和加密装置

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
PCT/CN2014/083486 WO2016015313A1 (zh) 2014-07-31 2014-07-31 存储卡的加密方法和加密装置

Publications (1)

Publication Number Publication Date
WO2016015313A1 true WO2016015313A1 (zh) 2016-02-04

Family

ID=55216667

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2014/083486 Ceased WO2016015313A1 (zh) 2014-07-31 2014-07-31 存储卡的加密方法和加密装置

Country Status (2)

Country Link
CN (1) CN106462719A (zh)
WO (1) WO2016015313A1 (zh)

Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN1670817A (zh) * 2004-03-15 2005-09-21 雅马哈株式会社 用于记录和再现音乐内容的电子音乐装置
CN101091184A (zh) * 2005-01-18 2007-12-19 松下电器产业株式会社 数据存储方法、数据播放方法、数据记录装置、数据播放装置和记录介质
CN101840476A (zh) * 2010-05-07 2010-09-22 江苏新广联科技股份有限公司 一种otp-sd电子出版物加密方法
CN102667941A (zh) * 2009-10-21 2012-09-12 三星电子株式会社 具有安全功能的数据存储介质及其输出装置

Family Cites Families (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
EP1593098B2 (en) * 2003-01-31 2010-09-15 Panasonic Corporation Semiconductor memory card, and program for controlling the same
CN101484904A (zh) * 2006-07-07 2009-07-15 桑迪士克股份有限公司 使用多用途控制结构的内容控制系统和方法
CN101256609B (zh) * 2007-03-02 2010-09-08 群联电子股份有限公司 存储卡及其安全方法
CN101276432B (zh) * 2008-05-20 2011-07-20 普天信息技术研究院有限公司 一种存储卡及其实现数字内容保护的方法
CN102781001A (zh) * 2011-05-10 2012-11-14 中兴通讯股份有限公司 移动终端内置文件加密方法及移动终端

Patent Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN1670817A (zh) * 2004-03-15 2005-09-21 雅马哈株式会社 用于记录和再现音乐内容的电子音乐装置
CN101091184A (zh) * 2005-01-18 2007-12-19 松下电器产业株式会社 数据存储方法、数据播放方法、数据记录装置、数据播放装置和记录介质
CN102667941A (zh) * 2009-10-21 2012-09-12 三星电子株式会社 具有安全功能的数据存储介质及其输出装置
CN101840476A (zh) * 2010-05-07 2010-09-22 江苏新广联科技股份有限公司 一种otp-sd电子出版物加密方法

Also Published As

Publication number Publication date
CN106462719A (zh) 2017-02-22

Similar Documents

Publication Publication Date Title
CN106301774B (zh) 安全芯片、其加密密钥生成方法和加密方法
US9813247B2 (en) Authenticator device facilitating file security
US11570155B2 (en) Enhanced secure encryption and decryption system
CN107317677B (zh) 密钥存储及设备身份认证方法、装置
CN104247327A (zh) 使用密钥加密密钥的密码发射系统
CN110650010A (zh) 一种非对称密钥中的私钥生成和使用方法、装置和设备
EP2791856A1 (en) Method, device, and system for securely sharing media content from a source device
CN104200176A (zh) 对智能移动终端中文件进行透明加解密的系统及方法
KR20180094063A (ko) 문서 처리 방법 및 장치
WO2020155812A1 (zh) 一种数据存储方法、装置及设备
CN106304040A (zh) 管理移动应用的方法、装置
CN104866784A (zh) 一种基于bios加密的安全硬盘、数据加密及解密方法
CN111949999A (zh) 管理数据的设备和方法
TW201003451A (en) Safety storage device with two-stage symmetrical encryption algorithm
JP2014081613A (ja) セッション状態情報の暗号化および復号化方法
WO2015143827A1 (zh) 通讯录保护方法、装置及通信系统
WO2015176394A1 (zh) 文件加密方法、装置、加密文件的读取方法、装置及终端
JP4597784B2 (ja) データ処理装置
CN102740246B (zh) 媒体消息处理方法、系统及装置
CN114490552A (zh) 数据传输方法、装置和电子设备
CN101296226B (zh) 共享总线密钥的方法及其设备
CN112003697A (zh) 密码模块加解密方法、装置、电子设备及计算机存储介质
CN107135074B (zh) 一种高级安全方法和装置
CN105574432A (zh) 一种虚拟磁盘的秘钥处理方法及系统
CN107483187A (zh) 一种基于可信密码模块的数据保护方法及装置

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 14898678

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

32PN Ep: public notification in the ep bulletin as address of the adressee cannot be established

Free format text: NOTING OF LOSS OF RIGHTS PURSUANT TO RULE 112(1) EPC (EPO FORM 1205A DATED 23/06/2017)

122 Ep: pct application non-entry in european phase

Ref document number: 14898678

Country of ref document: EP

Kind code of ref document: A1