WO2018205723A1 - 具有安全加密功能的安全盘及安全加密方法 - Google Patents

具有安全加密功能的安全盘及安全加密方法 Download PDF

Info

Publication number
WO2018205723A1
WO2018205723A1 PCT/CN2018/077962 CN2018077962W WO2018205723A1 WO 2018205723 A1 WO2018205723 A1 WO 2018205723A1 CN 2018077962 W CN2018077962 W CN 2018077962W WO 2018205723 A1 WO2018205723 A1 WO 2018205723A1
Authority
WO
WIPO (PCT)
Prior art keywords
security
secure
file
disk
algorithm
Prior art date
Application number
PCT/CN2018/077962
Other languages
English (en)
French (fr)
Inventor
张金银
Original Assignee
深圳市夏日晨光数码有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 深圳市夏日晨光数码有限公司 filed Critical 深圳市夏日晨光数码有限公司
Publication of WO2018205723A1 publication Critical patent/WO2018205723A1/zh

Links

Classifications

    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/60Protecting data
    • G06F21/602Providing cryptographic facilities or services
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F2221/00Indexing scheme relating to security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F2221/21Indexing scheme relating to G06F21/00 and subgroups addressing additional information or applications relating to security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F2221/2107File encryption

Definitions

  • the present invention relates to the field of security encryption, and in particular, to a security disk and a security encryption method.
  • Files stored in existing computers or mobile phones can only be encrypted by software, and the software is easily cracked, causing information leakage. Files uploaded and downloaded in the cloud must pass through the network, and are easily hacked during cloud storage or network transmission, resulting in insecure information.
  • the invention overcomes the deficiencies of the prior art and provides a security disk with a security encryption function.
  • the security disk with encryption function is connected to an external storage device, and includes a casing, a transmission interface disposed on the casing, and a security chip connected to the transmission interface, where the security chip has a security algorithm.
  • the security algorithm is configured to isolate the storage device from a secure storage space, and the secure storage space can be accessed after the security disk is inserted into the device and the correct authentication information is input, and the security algorithm is further configured to upload the file in the cloud. Encrypt and decrypt while the file is being downloaded.
  • the security algorithm is an AES-256 algorithm.
  • the secure storage space is invisible when the security disk is not inserted.
  • the security algorithm scrambles the order of the file data when the file is uploaded, and restores the file data when downloading.
  • the external storage device is a mobile phone, a tablet computer, a personal computer or a workstation.
  • the present invention also provides a method for secure encryption, which includes a first security mode and a second security mode.
  • the secure storage space is separated from the external storage device by a security algorithm built in the security disk and is secure.
  • the storage space is encrypted.
  • the secure storage space can be read or written after the external storage device is connected to the security disk and input correct authentication information.
  • the security algorithm built in the security disk uploads the external storage device.
  • the file to the cloud or server is encrypted, and the file is decrypted when the external storage device downloads the file from the cloud or the server.
  • the security algorithm is an AES-256 algorithm.
  • the security algorithm scrambles the order of the file data when the file is uploaded, and restores the file data when downloading.
  • the security disk and the security encryption method of the invention can double-encrypt the storage space of the storage device by software and hardware, and encrypt the file during file uploading, thereby improving the security of the file stored in the cloud, and in the file downloading Automatic decryption, while ensuring security, will not bring tedious decryption process to the user.
  • FIG. 1 is a schematic structural view of a security disk of the present invention.
  • the security disk 100 of the present invention is connected to an external storage device (not shown), and includes a casing 1 , a transmission interface 2 disposed on the casing, and a security chip 3 connected to the transmission interface. 3 built-in security algorithm.
  • the security algorithm is preferably AES-256 algorithm (Advanced Encryption) Standard, Advanced Encryption Standard).
  • the external device is a mobile phone, a tablet computer, a personal computer or a workstation.
  • the security algorithm built in the security chip 3 is configured to isolate the external storage device from a secure storage space, and the secure storage space can be used to store confidential information.
  • the secure storage space can be accessed, read or written only after the security disk is inserted into the device and the correct authentication information is entered. That is, the secure storage space implements double encryption of software and hardware, and only the security disk is inserted or only the correct authentication is input. No information can be opened to secure storage for high security encryption. It is worth noting that the secure storage space is not visible when the security disk is not inserted.
  • the security chip 3 When an external storage device uploads files to the cloud or server, the security chip 3 encrypts through a security algorithm, so that files are not obtained by others when transmitted and stored in the cloud or server.
  • the security algorithm automatically decrypts the file when the external storage device downloads the file from the cloud or the server.
  • the encryption method may be changing the order of file data, encryption and compression, etc., and may be selected according to requirements.
  • the present invention also provides a method for secure encryption, which includes a first security mode and a second security mode.
  • the AES-256 algorithm built in the security disk separates the secure storage space from the external storage device and Encrypting the secure storage space, which can be read or written after the external storage device is connected to the security disk and input correct authentication information;
  • the AES-256 algorithm built into the security disk will The file uploaded to the cloud or server by the external storage device is encrypted, and the file is automatically decrypted when the external storage device downloads the file from the cloud or the server.
  • the security algorithm scrambles the order of the file data when the file is uploaded, and restores the order of the file data at the time of downloading to implement encryption and decryption.
  • the security disk and the security encryption method of the invention can double-encrypt the storage space of the storage device by software and hardware, and encrypt the file during file uploading, thereby improving the security of the file stored in the cloud, and in the file downloading Automatic decryption, while ensuring security, will not bring tedious decryption process to the user.

Landscapes

  • Engineering & Computer Science (AREA)
  • Theoretical Computer Science (AREA)
  • Health & Medical Sciences (AREA)
  • Bioethics (AREA)
  • General Health & Medical Sciences (AREA)
  • Computer Hardware Design (AREA)
  • Computer Security & Cryptography (AREA)
  • Software Systems (AREA)
  • Physics & Mathematics (AREA)
  • General Engineering & Computer Science (AREA)
  • General Physics & Mathematics (AREA)
  • Storage Device Security (AREA)

Abstract

一种具有加密功能的安全盘,与外接存储设备连接,其包括外壳、设置于外壳的传输接口及连接传输接口的安全芯片,所述安全芯片内置安全算法,所述安全算法配置为将存储设备隔离出一个安全存储空间,且该安全存储空间在安全盘插入设备且输入正确的验证信息后能够被访问,所述安全算法还配置为将上传云端的文件进行加密,并在文件下载的同时进行解密。该安全盘及安全加密方法,可对存储设备的存储空间进行软硬件双重加密,且在文件上传时对文件进行加密,提高了存储于云端的文件的安全性,而在文件下载时自动解密,保证安全性的同时,不会给用户带来繁琐的解密过程。

Description

具有安全加密功能的安全盘及安全加密方法 技术领域
本发明涉及一种安全加密领域,尤其涉及一种安全盘及安全加密方法。
背景技术
现有电脑或手机中存储的文件只能通过软件进行加密,软件容易被破解,造成信息的泄露。云端上传和下载的文件都要通过网络,在云端存储或网络传输过程中容易被劫取,造成信息不安全。
技术问题
而现有安全加密手机也只能在一台设备上实现加密功能,无法进行广泛的应用。
技术解决方案
本发明即是克服现有技术不足,提供一种具有安全加密功能的安全盘。
具体来说,本发明所述的一种具有加密功能的安全盘,与外接存储设备连接,其包括外壳、设置于外壳的传输接口及连接传输接口的安全芯片,所述安全芯片内置安全算法,所述安全算法配置为将存储设备隔离出一个安全存储空间,且该安全存储空间在安全盘插入设备且输入正确的验证信息后能够被访问,所述安全算法还配置为将上传云端的文件进行加密,并在文件下载的同时进行解密。
进一步的,所述安全算法为AES-256算法。
进一步的,所述安全存储空间在安全盘未插入时是不可见的。
进一步的,所述安全算法在文件上传时将文件数据的顺序打乱,并在下载时恢复文件数据。
进一步的,所述外接存储设备为手机、平板电脑、个人电脑或工作站。
本发明还提供一种安全加密的方法,其包括第一安全模式及第二安全模式,在第一安全模式下,通过安全盘内置的安全算法将外接存储设备中分离出安全存储空间并对安全存储空间进行加密,所述安全存储空间在外接存储设备连接安全盘且输入正确的验证信息后能够被读取或写入;在第二安全模式下,安全盘内置的安全算法将外接存储设备上传至云端或服务器的文件进行加密,且在外接存储设备自云端或服务器下载文件时进行文件解密。
进一步的,所述安全算法为AES-256算法。
进一步的,所述安全算法在文件上传时将文件数据的顺序打乱,并在下载时恢复文件数据。
有益效果
本发明所述的安全盘及安全加密方法,可对存储设备的存储空间进行软硬件双重加密,且在文件上传时对文件进行加密,提高了存储于云端的文件的安全性,而在文件下载时自动解密,保证安全性的同时,不会给用户带来繁琐的解密过程。
附图说明
图1为本发明安全盘的结构示意图。
本发明的实施方式
以下结合附图,对本发明所述的安全盘及安全加密方法进行非限制性地说明,目的是为了公众更好地理解所述的技术内容。
如图1所示,本发明所述的安全盘100与外接存储设备(未图示)连接,其包括外壳1、设置于外壳的传输接口2及连接传输接口的安全芯片3,所述安全芯片3内置安全算法。所述安全算法优选为AES-256算法(Advanced Encryption Standard,高级加密标准)。所述外接设备为手机、平板电脑、个人电脑或工作站。
所述安全盘连接至外接存储设备时,所述安全芯片3内置的安全算法配置为将外接存储设备隔离出一个安全存储空间,该安全存储空间可用于存储机密信息。安全存储空间仅在安全盘插入设备且输入正确的验证信息后能够被访问、读取或写入,即该安全存储空间实现软件与硬件的双重加密,仅有安全盘插入或仅输入正确的验证信息均不能打开安全存储空间,以实现高安全性的加密。值得注意的是,所述安全存储空间在安全盘未插入时是不可见的。
在外接存储设备向云端或服务器上传文件时,安全芯片3通过安全算法进行加密,使传输及在云端或服务器存储时,文件均不会被他人获得。而在外接存储设备自云端或服务器下载文件时,安全算法可自动对文件进行解密。加密方式可以是改变文件数据的顺序、加密压缩等,具体可根据需求进行选择。
本发明还提供一种安全加密的方法,其包括第一安全模式及第二安全模式,在第一安全模式下,通过安全盘内置的AES-256算法将外接存储设备中分离出安全存储空间并对安全存储空间进行加密,所述安全存储空间在外接存储设备连接安全盘且输入正确的验证信息后能够被读取或写入;在第二安全模式下,安全盘内置的AES-256算法将外接存储设备上传至云端或服务器的文件进行加密,且在外接存储设备自云端或服务器下载文件时自动进行文件解密。
所述安全算法在文件上传时将文件数据的顺序打乱,并在下载时恢复文件数据的顺序,以实现加密与解密。
本发明所述的安全盘及安全加密方法,可对存储设备的存储空间进行软硬件双重加密,且在文件上传时对文件进行加密,提高了存储于云端的文件的安全性,而在文件下载时自动解密,保证安全性的同时,不会给用户带来繁琐的解密过程。
应该理解的是,上述内容不是对所述技术方案的限制,事实上,凡以相同或近似原理对所述技术方案进行的改进,包括各部分的形状、尺寸、所用材质的改进,以及相似功能元件的替换,都在本发明要求保护的技术方案之内。

Claims (8)

  1. 一种具有加密功能的安全盘,与外接存储设备连接,其包括外壳、设置于外壳的传输接口及连接传输接口的安全芯片,所述安全芯片内置安全算法,所述安全算法配置为将外接存储设备隔离出一个安全存储空间,且该安全存储空间在安全盘插入设备且输入正确的验证信息后能够被访问,所述安全算法还配置为将上传云端的文件进行加密,并在文件下载的同时进行解密。
  2. 根据权利要求1所述的具有加密功能的安全盘,其特征在于:所述安全算法为AES-256算法。
  3. 根据权利要求2所述的具有加密功能的安全盘,其特征在于:所述安全存储空间在安全盘未插入时是不可见的。
  4. 根据权利要求1所述的具有加密功能的安全盘,其特征在于:所述安全算法在文件上传时将文件数据的顺序打乱,并在下载时恢复文件数据的顺序。
  5. 根据权利要求1所述的具有加密功能的安全盘,其特征在于:所述外接存储设备为手机、平板电脑、个人电脑或工作站。
  6. 一种安全加密的方法,其包括第一安全模式及第二安全模式,
    在第一安全模式下,通过安全盘内置的安全算法将外接存储设备中分离出安全存储空间并对安全存储空间进行加密,所述安全存储空间在外接存储设备连接安全盘且输入正确的验证信息后能够被读取或写入;
    在第二安全模式下,安全盘内置的安全算法将外接存储设备上传至云端或服务器的文件进行加密,且在外接存储设备自云端或服务器下载文件时自动进行文件解密。
  7. 根据权利要求6所述的安全加密的方法,其特征在于:所述安全算法为AES-256算法。
  8. 根据权利要求6所述的安全加密的方法,其特征在于:所述安全算法在文件上传时将文件数据的顺序打乱,并在下载时恢复文件数据的顺序。
PCT/CN2018/077962 2017-05-09 2018-03-05 具有安全加密功能的安全盘及安全加密方法 WO2018205723A1 (zh)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN201710320366.0A CN106960159A (zh) 2017-05-09 2017-05-09 具有安全加密功能的安全盘及安全加密方法
CN201710320366.0 2017-05-09

Publications (1)

Publication Number Publication Date
WO2018205723A1 true WO2018205723A1 (zh) 2018-11-15

Family

ID=59482074

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2018/077962 WO2018205723A1 (zh) 2017-05-09 2018-03-05 具有安全加密功能的安全盘及安全加密方法

Country Status (2)

Country Link
CN (1) CN106960159A (zh)
WO (1) WO2018205723A1 (zh)

Families Citing this family (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN106960159A (zh) * 2017-05-09 2017-07-18 深圳市夏日晨光数码有限公司 具有安全加密功能的安全盘及安全加密方法
CN109660604B (zh) * 2018-11-29 2023-04-07 上海碳蓝网络科技有限公司 数据存取方法及设备

Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101051293A (zh) * 2007-05-11 2007-10-10 广东天海威数码技术有限公司 对个人电脑存储空间的访问控制方法
CN202009402U (zh) * 2010-12-23 2011-10-12 中科方德软件有限公司 支持云存储的便携式存储装置及系统
CN103051664A (zh) * 2012-08-14 2013-04-17 深圳市朗科科技股份有限公司 一种云存储系统的文件管理方法、装置及该云存储系统
CN204669402U (zh) * 2015-04-03 2015-09-23 王爱华 一种基于u盘的云数据信息加密解密系统
CN106960159A (zh) * 2017-05-09 2017-07-18 深圳市夏日晨光数码有限公司 具有安全加密功能的安全盘及安全加密方法

Family Cites Families (7)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101714123B (zh) * 2008-10-07 2011-09-21 上海众人网络安全技术有限公司 可保证信息安全的文件移动存储设备的实现方法
CN102841861A (zh) * 2011-06-24 2012-12-26 同方股份有限公司 一种以sd为通讯接口的数据安全存储设备及其工作方法
CN103198263B (zh) * 2012-10-26 2016-07-06 高榕科技(深圳)有限公司 借助个人计算机的外设密钥建立加/解密存储空间的方法
CN103942499B (zh) * 2014-03-04 2017-01-11 中天安泰(北京)信息技术有限公司 基于移动存储器的数据黑洞处理方法及移动存储器
CN104219234B (zh) * 2014-08-28 2017-11-24 杭州华澜微电子股份有限公司 一种云存储个人数据安全的方法
CN104834873A (zh) * 2015-04-03 2015-08-12 王爱华 一种用于云数据信息加密解密的u盘及实现方法
CN105847305A (zh) * 2016-06-21 2016-08-10 新昌县七星街道明盛模具厂 一种云资源的安全处理与访问方法

Patent Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101051293A (zh) * 2007-05-11 2007-10-10 广东天海威数码技术有限公司 对个人电脑存储空间的访问控制方法
CN202009402U (zh) * 2010-12-23 2011-10-12 中科方德软件有限公司 支持云存储的便携式存储装置及系统
CN103051664A (zh) * 2012-08-14 2013-04-17 深圳市朗科科技股份有限公司 一种云存储系统的文件管理方法、装置及该云存储系统
CN204669402U (zh) * 2015-04-03 2015-09-23 王爱华 一种基于u盘的云数据信息加密解密系统
CN106960159A (zh) * 2017-05-09 2017-07-18 深圳市夏日晨光数码有限公司 具有安全加密功能的安全盘及安全加密方法

Also Published As

Publication number Publication date
CN106960159A (zh) 2017-07-18

Similar Documents

Publication Publication Date Title
US9735962B1 (en) Three layer key wrapping for securing encryption keys in a data storage system
TWI601405B (zh) 用於雲端輔助式密碼術之方法及設備
US9537918B2 (en) File sharing with client side encryption
US9448949B2 (en) Mobile data vault
US9413754B2 (en) Authenticator device facilitating file security
WO2017193950A1 (zh) 一种移动办公方法、服务端、客户端及系统
CN109948322B (zh) 本地化加密防护的个人云存储数据保险箱装置及方法
WO2017034642A3 (en) Optimizable full-path encryption in a virtualization environment
US10027660B2 (en) Computer program, method, and system for secure data management
PH12018550176A1 (en) Using hardware based secure isolated region to prevent piracy and cheating on electronic devices
TW201329776A (zh) 保護檔案內容安全的方法和系統
CN103559453A (zh) 一种手机数据硬件加密保护方法和系统
CA2891610C (en) Agent for providing security cloud service and security token device for security cloud service
CN105227299A (zh) 一种数据加解密管理设备及其应用方法
US20140281513A1 (en) Block encryption
US20210266301A1 (en) Secure application processing systems and methods
CN103905557A (zh) 用于云环境的数据存储方法和装置、及下载方法和装置
WO2018205723A1 (zh) 具有安全加密功能的安全盘及安全加密方法
CN103425938B (zh) 一种类Unix操作系统的文件夹加密方法和装置
US20180137291A1 (en) Securing files at rest in remote storage systems
US10380353B2 (en) Document security in enterprise content management systems
CN112800451A (zh) 一种基于硬件物理隔离的数据转储装置
TW201317823A (zh) 一種雲端安全儲存系統
CN108154037B (zh) 进程间的数据传输方法和装置
CN111917688B (zh) 一种通过云平台传输加密数据的方法、装置和系统

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 18798817

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 18798817

Country of ref document: EP

Kind code of ref document: A1