Computer multi-cloud data security backup method and system based on scene security

Through real-time risk assessment and dynamic policy generation, adaptive sharding encryption, intelligent routing distribution and multi-factor recovery mechanism, the problem of lack of real-time perception and dynamic adjustment in existing cloud data backup methods is solved, data security and flexibility in multi-cloud environments are achieved, and the security and integrity of data are ensured.

CN120704950AInactive Publication Date: 2025-09-26HEBEI INST OF MACHINERY ELECTRICITY
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202510812854.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-17
Publication Date
2025-09-26
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

Existing cloud data backup methods lack real-time perception and dynamic adjustment, are unable to perform adaptive encryption and sharding based on data sensitivity, and rely on a single cloud storage platform, posing the risk of data loss or leakage and an imperfect data recovery mechanism.

Method used

Through real-time risk assessment and dynamic policy generation, adaptive sharding encryption, intelligent routing distribution and multi-factor recovery mechanism, the security and flexibility of data in a multi-cloud environment are achieved. Multi-cloud storage nodes and intelligent routing technology are used to build a multi-factor data recovery mechanism.

Benefits of technology

It implements a dynamic backup strategy based on the network environment and device security status, improves the flexibility and recovery capabilities of data backup, avoids security threats from a single cloud platform, and ensures the security and integrity of data.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120704950A_ABST
    Figure CN120704950A_ABST
Patent Text Reader

Abstract

The invention discloses a computer multi-cloud data security backup method and system based on scene security, and the method comprises the steps: carrying out the risk assessment based on scene parameters, and formulating a security backup strategy; the method comprises the following steps: processing cloud data through adaptive fragmentation encryption, and dividing the cloud data into core data and non-core data; based on the relevance between the fragmented data, adding an identifier; performing evaluation based on the security index data of the multiple cloud storage nodes of each cloud storage platform to obtain the cloud storage platform meeting the storage requirement; through intelligent routing distribution, the encrypted data fragments are distributed and stored in the heterogeneous cloud storage platform, and it is ensured that the fragments stored in any single cloud platform are insufficient to reconstruct complete data; and constructing a multi-factor data recovery mechanism based on a data exception condition, and implementing dynamic migration on the fragments of the high-risk region. The method has the advantages that the flexibility and recovery capability of data backup are effectively improved through adaptive fragmentation encryption and intelligent routing distribution, and potential security threats are avoided.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to data backup technology, and in particular to a scenario-based computer multi-cloud data security backup method and system. Background Art

[0002] With the advent of the information age, data has become one of the most valuable assets for businesses and individuals. However, the risk of data loss, corruption, or malicious attacks is also increasing. Data security becomes particularly prominent in the face of hardware failures, natural disasters, cyberattacks, and human error. Cloud data backup technology has emerged as a response to this challenge. By storing data on cloud servers, it makes data backup more secure and reliable.

[0003] Current cloud data backup methods on the market typically rely on fixed backup strategies and static storage methods, lacking real-time awareness and dynamic adjustment of scenario security. These methods fail to consider the real-time network environment, device security status, and potential risks, resulting in backup strategies that cannot respond to changes in the cloud environment in a timely manner. For example, many cloud backup systems are unable to perform adaptive encryption and sharding based on the sensitivity of the data, resulting in core data and non-core data potentially receiving the same protection, lacking flexibility. In addition, traditional backup methods typically rely on a single cloud storage platform for data storage, which poses a centralized risk. If a single platform fails or suffers a security breach, data loss or leakage may occur. Moreover, many methods are not perfect in terms of data anomaly detection and recovery mechanisms, and are unable to monitor the security of cloud data in real time, resulting in an inability to respond in a timely manner or to accurately locate the source of the anomaly during data recovery. Summary of the Invention

[0004] In order to improve the existing computer cloud data backup method, a scenario-based multi-cloud data security backup method and system are provided. This method ensures the security and integrity of data in a multi-cloud environment through real-time risk assessment and dynamic policy generation. Adaptive sharding encryption, intelligent routing distribution and multi-factor recovery mechanism effectively improve the flexibility and recovery capability of data backup, avoiding potential security threats.

[0005] In order to achieve the above objects, the technical solution adopted by the present invention is:

[0006] The computer multi-cloud data security backup method based on scenario security includes:

[0007] Based on the scene parameters collected through real-time perception, risk assessment of scene security is performed and a security backup strategy is formulated for cloud data.

[0008] Based on the security backup strategy, cloud data is processed through adaptive sharding encryption and divided into core data and non-core data;

[0009] Based on the correlation between the data in each shard, an identifier is added to each shard for subsequent data integration and reorganization;

[0010] Evaluate the multi-cloud storage node security indicator data of each cloud storage platform to obtain cloud storage platforms that meet storage requirements;

[0011] Through intelligent routing distribution, encrypted data shards are distributed and stored on heterogeneous cloud storage platforms, ensuring that the shards stored on any single cloud platform are insufficient to reconstruct the complete data;

[0012] Based on data anomalies, a multi-factor data recovery mechanism is built, and dynamic migration of shards in high-risk areas is implemented.

[0013] Preferably, the risk assessment of scene security based on scene parameters collected through real-time perception and the formulation of a security backup strategy for cloud data specifically include:

[0014] By real-time monitoring of TCP retransmission rate, broadband jitter coefficient, and cloud storage node response delay, the network environment characteristics of cloud data backup are obtained;

[0015] Obtain the security status of cloud storage devices through device authentication and firmware integrity testing;

[0016] Based on the above scenario parameters, obtain the risk assessment level of the current cloud storage backup scenario;

[0017] Based on the real-time risk assessment level, a dynamic security backup strategy is generated for the cloud data at that moment, and a data sensitivity level is added to each part of the cloud data.

[0018] Preferably, the processing of cloud data by adaptive sharding encryption based on a secure backup strategy and the division into core data and non-core data specifically includes:

[0019] Divide cloud data into core data and non-core data based on the data sensitivity level attached to each part of cloud data;

[0020] For core data, a threshold sharding mechanism is used to adaptively divide the core data into multiple shards based on the scenario risk assessment level. A minimum recovery threshold is set, and a single shard contains no more than 15% complete data information.

[0021] For non-core data, it is divided into a fixed number of shards, and a single shard can contain complete data information;

[0022] Based on the core data after segmentation, double nesting is used for encryption, and the master key and shard key are protected and stored separately;

[0023] Based on the segmented non-core data, single-layer encryption and dynamic key rotation are adopted.

[0024] Preferably, the adding of identifiers to the respective shard data based on the correlation between the shard data for subsequent data integration and reorganization specifically includes:

[0025] Perform correlation analysis based on the business needs and data characteristics of each shard's cloud data, and classify the related shards' cloud data into the same group of data;

[0026] Based on the same group of data, a unique group ID identifier structure is generated, including the group ID, data type identifier, business-related identifier, and timestamp;

[0027] Divide all shard data into groups and generate and add group ID identifiers;

[0028] When restoring and extracting data, the cloud data is searched based on the group ID identifier.

[0029] Preferably, the step of evaluating the multi-cloud storage node security indicator data of each cloud storage platform to obtain a cloud storage platform that meets the storage requirements specifically includes:

[0030] Verify the certification status on the cloud service provider's official website and the validity of the certificate through the national certification and accreditation supervision platform, and check the basic security certification;

[0031] Obtain core indicator data on static encryption, transmission security, and key management for each cloud storage node;

[0032] Obtain storage status data of each cloud storage node through real-time security data collection and monitoring;

[0033] Based on the above collected data, dynamic risk assessment and quantification are carried out, and risk quantification output is obtained through a hierarchical weight model;

[0034] Obtain a cloud storage platform that meets your storage requirements based on risk assessment.

[0035] Preferably, the method of allocating and storing encrypted data shards to heterogeneous cloud storage platforms through intelligent routing distribution to ensure that the shards stored on any single cloud platform are insufficient to reconstruct the complete data specifically includes:

[0036] Set shard storage isolation rules based on the data sensitivity level of each encrypted shard;

[0037] Based on the shard storage isolation rules, a routing decision matrix is ​​constructed. By adjusting the parameters of security score, delay, and cost coefficient, the multi-objective function is optimized to calculate the optimal path.

[0038] By randomly selecting multiple shards from each cloud storage platform for data reorganization, a shard distribution compliance check is performed. If the complete data cannot be reconstructed, the distribution is normal. If the complete data can be reconstructed, the cloud data of each shard is rerouted and distributed until the complete data cannot be reconstructed.

[0039] Preferably, the multi-factor data recovery mechanism is constructed based on data anomalies, and dynamic migration of shards in high-risk areas is implemented, specifically including:

[0040] Based on data anomalies, determine the anomaly type, including data level anomalies, storage node anomalies, and geographical risk anomalies;

[0041] Classify abnormal risks based on abnormality types and verify data recovery operations through composite identity authentication and geographic and temporal constraints;

[0042] Build a safe recovery environment based on the data of each shard and reorganize the data of each shard;

[0043] When an exception occurs, the sharded data in the high-risk area will be encrypted and repackaged, incrementally migrated in batches, and the integrity of the migrated data will be verified.

[0044] Furthermore, a computer multi-cloud data security backup system based on scenario security is proposed, including:

[0045] Scenario security perception and risk assessment module: The scenario security perception and risk assessment module is mainly used to perceive and assess the risks of cloud data backup scenarios in real time, providing support for data backup strategies;

[0046] Dynamic backup strategy generation module: The dynamic backup strategy generation module is mainly used to generate dynamic security backup strategies based on risk assessment results and assign sensitivity levels to data;

[0047] Adaptive data sharding and encryption module: The adaptive data sharding and encryption module is mainly used to divide cloud data into core data and non-core data according to the data sensitivity level, and perform sharding encryption on them;

[0048] Data fragment identification and association analysis module: The data fragment identification and association analysis module is mainly used to perform association analysis on data fragments and generate a unique group ID identifier to facilitate subsequent data integration and recovery;

[0049] Cloud storage platform evaluation and selection module: The cloud storage platform evaluation and selection module is mainly used to evaluate the security of each cloud storage platform and select a cloud platform that meets the storage requirements for data storage;

[0050] Intelligent routing distribution and data storage module: The intelligent routing distribution and data storage module is mainly used to distribute encrypted data shards to heterogeneous cloud platforms through intelligent routing technology to ensure data security and integrity;

[0051] Data anomaly detection and recovery module: The data anomaly detection and recovery module is mainly used to monitor data anomalies, build a multi-factor recovery mechanism for anomalies, and dynamically migrate shards in high-risk areas;

[0052] Processor: The processor is mainly used for the calculation process of each formula and the construction calculation process of each model.

[0053] Compared with the prior art, the advantages of the present invention are:

[0054] Through real-time perception and risk assessment, dynamic security backup strategies can be formulated based on factors such as the network environment and device security status, thereby achieving precise data protection. The adaptive sharding encryption mechanism processes core and non-core data differently based on the sensitivity of the data, ensuring additional protection for high-risk data. Intelligent routing distribution technology can distribute encrypted data shards across multiple heterogeneous cloud platforms, effectively preventing the risk of data leakage or loss caused by shard storage on a single cloud platform. At the same time, the multi-factor recovery mechanism based on data anomalies provides the system with more flexible emergency response capabilities, enabling rapid data recovery and dynamic migration to high-risk areas when anomalies occur. BRIEF DESCRIPTION OF THE DRAWINGS

[0055] Figure 1 A schematic diagram of the method proposed in the present invention;

[0056] Figure 2 This is a schematic diagram of the scenario security risk assessment proposed by the present invention;

[0057] Figure 3 This is a schematic diagram of the adaptive shard encryption process proposed by the present invention;

[0058] Figure 4 Add a schematic diagram for the identifier proposed by the present invention;

[0059] Figure 5 This is a schematic diagram of obtaining the cloud storage platform proposed by the present invention;

[0060] Figure 6 This is a schematic diagram of the sharded data distribution proposed by the present invention;

[0061] Figure 7 This is a schematic diagram of the data recovery mechanism proposed by the present invention;

[0062] Figure 8 This is a diagram of the architecture of the electronic equipment in this solution;

[0063] Figure 9 This is a schematic diagram of the computer-readable storage medium structure in this solution. DETAILED DESCRIPTION

[0064] The following description is intended to disclose the present invention so that those skilled in the art can implement the present invention. The preferred embodiments described below are merely examples, and those skilled in the art may conceive of other obvious variations.

[0065] The computer multi-cloud data security backup system based on scenario security includes:

[0066] Scenario security perception and risk assessment module: The scenario security perception and risk assessment module is mainly used to perceive and assess the risks of cloud data backup scenarios in real time, providing support for data backup strategies;

[0067] Dynamic backup strategy generation module: The dynamic backup strategy generation module is mainly used to generate dynamic security backup strategies based on risk assessment results and assign sensitivity levels to data;

[0068] Adaptive data sharding and encryption module: The adaptive data sharding and encryption module is mainly used to divide cloud data into core data and non-core data according to the data sensitivity level, and perform sharding encryption on them;

[0069] Data fragment identification and association analysis module: The data fragment identification and association analysis module is mainly used to perform association analysis on data fragments and generate a unique group ID identifier to facilitate subsequent data integration and recovery;

[0070] Cloud storage platform evaluation and selection module: The cloud storage platform evaluation and selection module is mainly used to evaluate the security of each cloud storage platform and select a cloud platform that meets the storage requirements for data storage;

[0071] Intelligent routing distribution and data storage module: The intelligent routing distribution and data storage module is mainly used to distribute encrypted data shards to heterogeneous cloud platforms through intelligent routing technology to ensure data security and integrity;

[0072] Data anomaly detection and recovery module: The data anomaly detection and recovery module is mainly used to monitor data anomalies, build a multi-factor recovery mechanism for anomalies, and dynamically migrate shards in high-risk areas;

[0073] Processor: The processor is mainly used for the calculation process of each formula and the construction calculation process of each model.

[0074] See Figure 1 As shown, the scenario-based computer multi-cloud data security backup method includes:

[0075] Step 1: Based on the scene parameters collected through real-time perception, conduct a risk assessment of the scene security and develop a security backup strategy for cloud data.

[0076] Step 2: Based on the security backup strategy, cloud data is processed through adaptive sharding encryption and divided into core data and non-core data;

[0077] Step 3: Based on the correlation between the data in each shard, add an identifier to each shard for subsequent data integration and reorganization;

[0078] Step 4: Evaluate the multi-cloud storage node security indicator data of each cloud storage platform to obtain a cloud storage platform that meets the storage requirements;

[0079] Step 5: Through intelligent routing distribution, the encrypted data shards are distributed and stored on heterogeneous cloud storage platforms to ensure that the shards stored on any single cloud platform are insufficient to reconstruct the complete data;

[0080] Step 6: Build a multi-factor data recovery mechanism based on data anomalies and dynamically migrate shards in high-risk areas

[0081] See Figure 2 As shown in the figure, based on the scene parameters collected through real-time perception, the risk assessment of the scene security is carried out, and a security backup strategy is formulated for cloud data. Specifically, the following are included:

[0082] By real-time monitoring of TCP retransmission rate, broadband jitter coefficient, and cloud storage node response delay, the network environment characteristics of cloud data backup are obtained;

[0083] Obtain the security status of cloud storage devices through device authentication and firmware integrity testing;

[0084] Based on the above scenario parameters, obtain the risk assessment level of the current cloud storage backup scenario;

[0085] Based on the real-time risk assessment level, a dynamic security backup strategy is generated for the cloud data at that moment, and a data sensitivity level is added to each part of the cloud data.

[0086] Specifically, the TCP retransmission rate is used to evaluate the stability of network transmission. The higher the retransmission rate, the worse the network condition. The broadband jitter coefficient measures the fluctuation of network bandwidth. Large jitter will affect the stability of data transmission. The cloud storage node response delay is the time it takes for the storage node to respond after receiving a request. High delay indicates that the network or storage node is overloaded. The network quality index is obtained by weighted combination of the above three parameters. The formula is:

[0087] NQI=ω1·RR+ω2·BJ+ω3·NRL

[0088] Among them, NQI, RR, BJ, and NRL are network quality indicators, TCP retransmission rate, broadband jitter coefficient, and cloud storage node response delay, respectively. ω1, ω2, and ω3 are the weights of each indicator, which are adjusted according to actual needs.

[0089] The device security status can be comprehensively evaluated using the following two indicators: device authentication status and firmware integrity status;

[0090] Based on the above network environment characteristics and device security status, combined with the complexity of the backup task, the risk of the current cloud storage backup scenario can be assessed, and each part of the cloud data can be assigned a data sensitivity level, specifically: L0: public level, L1: internal level, L2: confidential level, L3: top secret level.

[0091] See Figure 3 As shown in the figure, based on the security backup strategy, cloud data is processed through adaptive sharding encryption and divided into core data and non-core data, including:

[0092] Divide cloud data into core data and non-core data based on the data sensitivity level attached to each part of cloud data;

[0093] For core data, a threshold sharding mechanism is used to adaptively divide the core data into multiple shards based on the scenario risk assessment level. A minimum recovery threshold is set, and a single shard contains no more than 15% complete data information.

[0094] For non-core data, it is divided into a fixed number of shards, and a single shard can contain complete data information;

[0095] Based on the core data after segmentation, double nesting is used for encryption, and the master key and shard key are protected and stored separately;

[0096] Based on the segmented non-core data, single-layer encryption and dynamic key rotation are adopted.

[0097] Specifically, based on the data sensitivity level attached to some cloud data, data in L0 and L1 are classified as non-core data, and data in L2 and L3 are classified as core data. Data is sharded through an adaptive policy adjustment mechanism. For example, when a network man-in-the-middle attack is detected, the number of core data shards is immediately increased to n = 7, and the route is switched to the backup channel.

[0098] For core data, a threshold sharding mechanism is used to shard, so that a single shard cannot contain too much complete data. For non-core data, a fixed number of shards are used for segmentation, and each shard contains complete data.

[0099] In the dual nested encryption strategy for core data, the first layer of encryption uses the master key to encrypt the entire core data, and the second layer of encryption uses the shard key to encrypt the shard. At the same time, the master key should be stored encrypted, usually protected by a hardware security module or key management service. Each shard key should also be stored separately and protected using encryption technology;

[0100] During the encryption process for non-core data, the encryption key is updated every period of time (such as every day or every hour) and the data is re-encrypted.

[0101] See Figure 4 As shown, based on the correlation between the data of each shard, an identifier is added to each shard for subsequent data integration and reorganization, specifically including:

[0102] Perform correlation analysis based on the business needs and data characteristics of each shard's cloud data, and classify the related shards' cloud data into the same group of data;

[0103] Based on the same group of data, a unique group ID identifier structure is generated, including the group ID, data type identifier, business-related identifier, and timestamp;

[0104] Divide all shard data into groups and generate and add group ID identifiers;

[0105] When restoring and extracting data, the cloud data is searched based on the group ID identifier.

[0106] Specifically, the shard data association includes data type, business related identifier, data stamp feature, and defines the data feature vector F i =(T i ,B i ,au i ) represents shard S i The characteristics of T i It is a data type identifier, and its value is a discrete type. i It is a business-related identifier, indicating the business module of the data. i is a timestamp indicating the time when the data was generated. Based on these features, the correlation between each two shards is calculated using the formula:

[0107]

[0108] Among them, A(S i ,S j ) is the correlation between the two shards, F i 、F j is the data feature vector, ∥F i ∥∥F j∥ are the moduli of the eigenvectors. The higher the correlation, the stronger the correlation between the two shards.

[0109] All shard data are divided into groups according to the results of their correlation analysis, and a group ID identifier is added to each shard.

[0110] See Figure 5 As shown in the figure, based on the multi-cloud storage node security indicator data of each cloud storage platform, the cloud storage platforms that meet the storage requirements are evaluated, including:

[0111] Verify the certification status on the cloud service provider's official website and the validity of the certificate through the national certification and accreditation supervision platform, and check the basic security certification;

[0112] Obtain core indicator data on static encryption, transmission security, and key management for each cloud storage node;

[0113] Obtain storage status data of each cloud storage node through real-time security data collection and monitoring;

[0114] Based on the above collected data, dynamic risk assessment and quantification are carried out, and risk quantification output is obtained through a hierarchical weight model;

[0115] Obtain a cloud storage platform that meets your storage requirements based on risk assessment.

[0116] Specifically, the core dimensions of cloud storage node security indicators include: static encryption, which evaluates the encryption status of data during storage, ensuring that data stored in the cloud is encrypted; transmission security, which evaluates the encryption and security protection during network transmission of cloud storage nodes; and key management, which evaluates how cloud service providers manage encryption keys, including key generation, storage, and rotation.

[0117] Based on the collected data, dynamic risk assessment is performed and the security risks of the cloud storage platform are quantified. The impact of various security indicators is considered through a hierarchical weight model. Based on the calculation results of the hierarchical weight model, risks are set and cloud storage platforms with comprehensive risk scores below the risk threshold are obtained as cloud data backup platforms.

[0118] See Figure 6 As shown in the figure, through intelligent routing distribution, encrypted data shards are distributed and stored on heterogeneous cloud storage platforms, ensuring that the shards stored on any single cloud platform are insufficient to reconstruct the complete data. Specifically, the following are included:

[0119] Set shard storage isolation rules based on the data sensitivity level of each encrypted shard;

[0120] Based on the shard storage isolation rules, a routing decision matrix is ​​constructed. By adjusting the parameters of security score, delay, and cost coefficient, the multi-objective function is optimized to calculate the optimal path.

[0121] By randomly selecting multiple shards from each cloud storage platform for data reorganization, a shard distribution compliance check is performed. If the complete data cannot be reconstructed, the distribution is normal. If the complete data can be reconstructed, the cloud data of each shard is rerouted and distributed until the complete data cannot be reconstructed.

[0122] Specifically, based on the set storage isolation rules, a routing decision matrix is ​​constructed. This matrix takes into account the security score, latency, and cost coefficient, and optimizes the routing decision by adjusting these parameters. The decision matrix can be expressed as:

[0123]

[0124] Among them, M is the decision matrix, S is the security score, D is the delay, C is the cost coefficient, and each element M i,j Indicates the choice between storage path i and shard j;

[0125] Combining security score, latency, and cost, we find the optimal storage path for each shard through a multi-objective function. By adjusting the weight coefficient, we minimize latency and cost and maximize the security score. The optimization function formula is:

[0126] Objective=α·S i,j +β·D i,j +γ·C i,j

[0127] Among them, Objective is the optimization function, S i,j is the security score of shard j under storage path i, D i,j is the delay corresponding to storage path i, C i,j is the cost corresponding to storage path i, α, β, and γ are weight coefficients, representing the relative importance of security, latency, and cost;

[0128] By randomly selecting multiple shards on the cloud storage platform to reorganize the data, the data compliance is checked to confirm whether the complete data can be reconstructed. If the complete data cannot be reconstructed, the distribution process meets the requirements and proceeds to the next step;

[0129] If the complete data can be reconstructed, it means that there is a compliance issue and the shards need to be rerouted. The goal of rerouting distribution is to reselect the optimal storage path by updating the routing decision matrix. After each rerouting distribution, data reorganization and compliance checks continue until the complete data cannot be reconstructed.

[0130] See Figure 7 As shown in the figure, based on data anomalies, a multi-factor data recovery mechanism is built, and dynamic migration of shards in high-risk areas is implemented. Specifically, the following are included:

[0131] Based on data anomalies, determine the anomaly type, including data level anomalies, storage node anomalies, and geographical risk anomalies;

[0132] Classify abnormal risks based on abnormality types and verify data recovery operations through composite identity authentication and geographic and temporal constraints;

[0133] Build a safe recovery environment based on the data of each shard and reorganize the data of each shard;

[0134] When an exception occurs, the sharded data in the high-risk area will be encrypted and repackaged, incrementally migrated in batches, and the integrity of the migrated data will be verified.

[0135] Specifically, data-level anomalies can be detected through hash verification, storage node anomalies can be determined through heartbeat mechanisms or node status monitoring, and geographic risk anomalies can be determined by combining geographic location with spatiotemporal constraints.

[0136] Based on anomaly type and risk classification, data recovery operations are verified through composite identity authentication and geographic and temporal constraints. Multiple authentication mechanisms (such as biometrics and digital certificates) ensure that only legitimate users can perform recovery operations. Geographic and temporal constraints ensure that recovery operations can only be performed within a legal scope. For example, data recovery operations can only be completed in a specific geographic location or time period.

[0137] When an exception occurs, the shard data in the high-risk area is encrypted and repackaged, and migrated incrementally. Only newly added or changed shard data is migrated, improving efficiency through the incremental backup mechanism.

[0138] The migrated data needs to be verified for integrity to ensure that it has not been corrupted during the migration process. This can be verified by comparing the hash value. If the calculated hash value matches the expected value, the data is intact and the migration was successful.

[0139] Furthermore, the method according to the embodiment of the present application can also be used with the aid of Figure 8 The electronic device architecture shown in FIG. Figure 8 As shown, the electronic device 500 may include a bus 501, one or more CPUs 502, a read-only memory (ROM) 503, a random access memory (RAM) 504, a communication port 505 connected to a network, an input / output component 506, a hard disk 507, etc. The storage device in the electronic device 500, such as the ROM 503 or the hard disk 507, may store the scenario-based computer multi-cloud data security backup method and system provided in this application. The electronic device 500 may also include a terminal interface 508. Of course, Figure 8The architecture shown is only exemplary and can be omitted according to actual needs when implementing different devices. Figure 8 One or more components of an electronic device are shown.

[0140] Figure 9 This is a schematic diagram of the computer-readable storage medium structure provided by an embodiment of the present application. Figure 9 As shown, a computer-readable storage medium 600 according to one embodiment of the present application is shown. Computer-readable instructions are stored on the computer-readable storage medium 600. When the computer-readable instructions are executed by the processor, the scenario-based computer multi-cloud data security backup method and system according to the embodiment of the present application described with reference to the above figures can be executed. The storage medium 600 includes, but is not limited to, for example, volatile memory and / or non-volatile memory. Volatile memory may include, for example, random access memory (RAM) and cache memory (cache). Non-volatile memory may include, for example, read-only memory (ROM), hard disk, flash memory, etc.

[0141] It should be noted that the order in which the embodiments of the present invention are described above is for illustrative purposes only and does not necessarily represent the superiority or inferiority of the embodiments. Furthermore, the foregoing descriptions of specific embodiments of this specification are provided. Furthermore, the processes depicted in the accompanying drawings do not necessarily require the specific order or sequential sequence shown to achieve the desired results. In certain embodiments, multitasking and parallel processing are also possible or may be advantageous.

[0142] The various embodiments in this specification are described in a progressive manner, and the same or similar parts between the various embodiments can be referred to each other. Each embodiment focuses on the differences from other embodiments.

[0143] The above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent replacements, improvements, etc. made within the principles of the present invention should be included in the scope of protection of the present invention.

Claims

1. A computer multi-cloud data security backup method based on scenario security, characterized in that: include: Based on the scene parameters collected through real-time perception, risk assessment of scene security is performed and a security backup strategy is formulated for cloud data. Based on the security backup strategy, cloud data is processed through adaptive sharding encryption and divided into core data and non-core data; Based on the correlation between the data in each shard, an identifier is added to each shard for subsequent data integration and reorganization; Evaluate the multi-cloud storage node security indicator data of each cloud storage platform to obtain cloud storage platforms that meet storage requirements; Through intelligent routing distribution, encrypted data shards are distributed and stored on heterogeneous cloud storage platforms, ensuring that the shards stored on any single cloud platform are insufficient to reconstruct the complete data; Based on data anomalies, a multi-factor data recovery mechanism is built, and dynamic migration of shards in high-risk areas is implemented.

2. The computer multi-cloud data security backup method based on scenario security according to claim 1 is characterized in that: The scenario parameters collected based on real-time perception are used to conduct risk assessments on scenario security and formulate a security backup strategy for cloud data. Specifically, the following steps are involved: By real-time monitoring of TCP retransmission rate, broadband jitter coefficient, and cloud storage node response delay, the network environment characteristics of cloud data backup are obtained; Obtain the security status of cloud storage devices through device authentication and firmware integrity testing; Based on the above scenario parameters, obtain the risk assessment level of the current cloud storage backup scenario; Based on the real-time risk assessment level, a dynamic security backup strategy is generated for the cloud data at that moment, and a data sensitivity level is added to each part of the cloud data.

3. The computer multi-cloud data security backup method based on scenario security according to claim 1 is characterized in that: The processing of cloud data by adaptive sharding encryption based on the security backup strategy and the division of cloud data into core data and non-core data specifically include: Divide cloud data into core data and non-core data based on the data sensitivity level attached to each part of cloud data; For core data, a threshold sharding mechanism is used to adaptively divide the core data into multiple shards based on the scenario risk assessment level. A minimum recovery threshold is set, and a single shard contains no more than 15% complete data information. For non-core data, it is divided into a fixed number of shards, and a single shard can contain complete data information; Based on the core data after segmentation, double nesting is used for encryption, and the master key and shard key are protected and stored separately; Based on the segmented non-core data, single-layer encryption and dynamic key rotation are adopted.

4. The computer multi-cloud data security backup method based on scenario security according to claim 1 is characterized in that: The adding of identifiers to the respective shard data based on the correlation between the shard data for subsequent data integration and reorganization specifically includes: Perform correlation analysis based on the business needs and data characteristics of each shard's cloud data, and classify the related shards' cloud data into the same group of data; Based on the same group of data, a unique group ID identifier structure is generated, including the group ID, data type identifier, business-related identifier, and timestamp; Divide all shard data into groups and generate and add group ID identifiers; When restoring and extracting data, the cloud data is searched based on the group ID identifier.

5. The computer multi-cloud data security backup method based on scenario security according to claim 1 is characterized in that: The evaluation of the multi-cloud storage node security indicator data of each cloud storage platform to obtain a cloud storage platform that meets the storage requirements specifically includes: Verify the certification status on the cloud service provider's official website and the validity of the certificate through the national certification and accreditation supervision platform, and check the basic security certification; Obtain core indicator data on static encryption, transmission security, and key management for each cloud storage node; Obtain storage status data of each cloud storage node through real-time security data collection and monitoring; Based on the above collected data, dynamic risk assessment and quantification are carried out, and risk quantification output is obtained through a hierarchical weight model; Obtain a cloud storage platform that meets your storage requirements based on risk assessment.

6. The computer multi-cloud data security backup method based on scenario security according to claim 1 is characterized in that: The method of allocating encrypted data shards to heterogeneous cloud storage platforms through intelligent routing distribution ensures that the shards stored on any single cloud platform are insufficient to reconstruct the complete data. Specifically, the method includes: Set shard storage isolation rules based on the data sensitivity level of each encrypted shard; Based on the shard storage isolation rules, a routing decision matrix is ​​constructed. By adjusting the parameters of security score, delay, and cost coefficient, the multi-objective function is optimized to calculate the optimal path. By randomly selecting multiple shards from each cloud storage platform for data reorganization, a shard distribution compliance check is performed. If the complete data cannot be reconstructed, the distribution is normal. If the complete data can be reconstructed, the cloud data of each shard is rerouted and distributed until the complete data cannot be reconstructed.

7. The computer multi-cloud data security backup method based on scenario security according to claim 1 is characterized in that: The aforementioned multi-factor data recovery mechanism is constructed based on data anomalies, and dynamic migration of shards in high-risk areas is implemented, specifically including: Based on data anomalies, determine the anomaly type, including data level anomalies, storage node anomalies, and geographical risk anomalies; Classify abnormal risks based on abnormality types and verify data recovery operations through composite identity authentication and geographic and temporal constraints; Build a safe recovery environment based on the data of each shard and reorganize the data of each shard; When an exception occurs, the sharded data in the high-risk area will be encrypted and repackaged, incrementally migrated in batches, and the integrity of the migrated data will be verified.

8. In combination with a computer multi-cloud data security backup system based on scenario security, it is used to implement the computer multi-cloud data security backup method based on scenario security as described in any one of claims 1 to 7, characterized in that: include: Scenario security perception and risk assessment module: The scenario security perception and risk assessment module is mainly used to perceive and assess the risks of cloud data backup scenarios in real time, providing support for data backup strategies; Dynamic backup strategy generation module: The dynamic backup strategy generation module is mainly used to generate dynamic security backup strategies based on risk assessment results and assign sensitivity levels to data; Adaptive data sharding and encryption module: The adaptive data sharding and encryption module is mainly used to divide cloud data into core data and non-core data according to the data sensitivity level, and perform sharding encryption on them; Data fragment identification and association analysis module: The data fragment identification and association analysis module is mainly used to perform association analysis on data fragments and generate a unique group ID identifier to facilitate subsequent data integration and recovery; Cloud storage platform evaluation and selection module: The cloud storage platform evaluation and selection module is mainly used to evaluate the security of each cloud storage platform and select a cloud platform that meets the storage requirements for data storage; Intelligent routing distribution and data storage module: The intelligent routing distribution and data storage module is mainly used to distribute encrypted data shards to heterogeneous cloud platforms through intelligent routing technology to ensure data security and integrity; Data anomaly detection and recovery module: The data anomaly detection and recovery module is mainly used to monitor data anomalies, build a multi-factor recovery mechanism for anomalies, and dynamically migrate shards in high-risk areas; Processor: The processor is mainly used for the calculation process of each formula and the construction calculation process of each model.

9. An electronic device, characterized in that: include: at least one processor; and a memory communicatively connected to the at least one processor; wherein, The memory stores instructions that can be executed by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to execute the scenario-based security computer multi-cloud data security backup method as described in any one of claims 1 to 7.

10. A computer-readable storage medium storing computer-readable instructions, characterized in that: When the computer-readable instructions are executed by a processor, the scenario-based security-based computer multi-cloud data security backup method according to any one of claims 1 to 7 is implemented.

Citation Information

Cited By

  • Vehicle testing system, method, equipment and medium

    CN121783565A