A cloud-based data storage protection system and its method

The hybrid cloud-terminal data security system addresses cloud storage vulnerabilities by integrating terminal encryption and cloud monitoring, enhancing security and minimizing data loss risks.

CN115374471BActive Publication Date: 2025-07-15SHANGHAI PACO INFORMATION TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202210982988.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-08-16
Publication Date
2025-07-15
Estimated Expiration
2042-08-16

AI Technical Summary

Technical Problem

The transparency of cloud storage data security protection makes it difficult for users to know the protection mechanism and correctness, and the loss of cloud data may lead to information leakage.

Method used

The split encryption system is used to split and encrypt data at the terminal, the cloud performs data verification and monitoring scanning, and the terminal performs security verification and report generation, forming a security protection system that cooperates with the cloud and the terminal.

Benefits of technology

It realizes reasonable allocation of security work between the cloud and the terminal, improves the security and integrity of data transmission, reduces the risk of data leakage, and has the ability to quickly identify and block threats.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115374471B_ABST
    Figure CN115374471B_ABST
Patent Text Reader

Abstract

The present invention relates to the technical field of data protection, and discloses a cloud-based data storage protection system and method thereof. The cloud-based data storage protection system includes a data transmission system, which is used to transmit terminal data and cloud data. The transmission directions include from the terminal to the cloud and from the cloud to the terminal, and the transmission link is encrypted during the transmission process. By integrating the cloud and the terminal, the present invention enables the cloud to perform security protection work, while the terminal, i.e., the user side, verifies the security protection of the cloud. Thus, the data security work is reasonably allocated to the cloud and the terminal, making full use of their respective advantages to form a more perfect security protection method with a smaller burden on their respective mechanisms. Before data transmission, the data is split and encrypted. The user needs to perform corresponding decryption before using the downloaded data, thereby avoiding the situation of data leakage caused by data loss.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of data protection, and particularly relates to a cloud-based data storage protection system and method thereof. Background Art

[0002] Since IBM advocated cloud computing, the development of cloud computing has been in a rapid development state. The currently popular "cloud platform" will also be the main trend of future development.

[0003] When data is stored in the cloud, due to the transparent nature of cloud storage itself, there are certain hidden dangers in the data security protection of cloud storage. First, the current cloud data protection is provided by the cloud, and it is difficult for users to know which protection mechanisms are adopted and whether the mechanisms are correctly used. Second, there may be a possibility of information leakage if cloud data is lost. Therefore, in view of the current situation, it is necessary to improve it. Summary of the Invention

[0004] In view of the above situation, in order to overcome the defects of the prior art, the present invention provides a cloud-based data storage protection system and method thereof, which effectively solve the problems that when data is stored in the cloud, due to the transparent nature of cloud storage itself, there are certain hidden dangers in the data security protection of cloud storage. First, the current cloud data protection is provided by the cloud, and it is difficult for users to know which protection mechanisms are adopted and whether the mechanisms are correctly used. Second, there may be a possibility of information leakage if cloud data is lost.

[0005] To achieve the above object, the present invention provides the following technical solution: A cloud-based data storage protection system includes a data transmission system, which is used to transmit terminal data and cloud data, and the transmission directions include from the terminal to the cloud and from the cloud to the terminal, and the transmission link is encrypted during the transmission process;

[0006] A split encryption system: The split encryption system is arranged at the terminal and is used to split and encrypt the data that needs to be stored in the cloud, and transmit the split and encrypted data to the cloud. The split encryption system includes a random split unit, an encryption unit and a decryption unit, and the encryption unit and the decryption unit are matched;

[0007] A terminal verification system: The terminal verification system is arranged at the terminal and is used to verify the data protection unit in the cloud. The terminal verification system includes a user data unit, a data verification unit and a data protection unit;

[0008] Cloud protection system: The cloud protection system is set in the cloud. The cloud protection system is used to provide data protection for the data transmitted to the cloud. The content of the data protection includes the protection of the verified and proven security attributes of the data;

[0009] Monitoring and scanning system: The monitoring and scanning system is set in the cloud. The monitoring and scanning system is used to continuously monitor the status, scan for risks, and scan for vulnerabilities of cloud applications, so as to quickly judge whether the source of security risks is external or internal at the first time when a threat occurs, and analyze the source judgment result;

[0010] Operation record system: The operation record system is set in the cloud. The operation record system is used to collect, store, and analyze all behaviors and access content of accessing the cloud database, generate a compliance report at the same time, and send the report to the corresponding connected terminal;

[0011] Data verification system: The data verification system is set in the cloud and the terminal. The data verification system is used to perform integrity verification on the data transmitted to the cloud. The data verification system is specifically the data possession proxy proof verification technology. The data verification system includes a data verification unit and a data optimization unit. The data verification unit is used to verify the integrity of the data and re-transmit it when the data is missing; the data optimization unit is used to verify the redundancy of the transmitted data and delete duplicate data.

[0012] Preferably, when the data transmission system performs encryption processing, it specifically uses one or a combination of DES data encryption technology, one-way function data encryption technology, one-way Hash function data encryption technology, AES data encryption technology, or RSA data encryption technology.

[0013] Preferably, in the split encryption system, the random split unit is used to randomly split the data that needs to be stored in the cloud in a random order. The random split unit specifically uses the recipes balanced split technology and is equipped with the lars regression verification technology; the encryption unit specifically uses the encryption algorithm based on ciphertext attributes; the decryption unit specifically uses the decryption algorithm based on key attributes.

[0014] Preferably, the terminal verification system and the cloud protection system are specifically data integrity protection technology based on resistance to repudiation, full-text searchable encryption technology based on AONE and secret sharing, and search result verification technology based on the function redundancy decomposition model.

[0015] Preferably, the specific monitoring content of the monitoring and scanning system includes core database assets, security vulnerability attacks, SQL injection, and virus infections.

[0016] Preferably, the data verification system specifically adopts the provable retrievability method or the proof of data possession method.

[0017] Preferably, a data storage protection method based on the cloud includes the following steps:

[0018] S1: Data splitting and encryption: Randomly split the data to be stored in the cloud through the random splitting unit in the splitting and encryption system, and encrypt the split data through the encryption unit. After encryption, perform the upload operation;

[0019] S2: Cloud protection verification: On the basis of step S1, during the process of uploading data to the cloud, the cloud provides support for the protection system, that is, the cloud re-encrypts the data, generates a receipt for the encrypted file data and feedbacks it to the terminal. The terminal verification system of the terminal verifies the data security and correctness of this receipt and then confirms the upload;

[0020] S3: Data integrity verification: During the process of data entering the cloud, the data integrity is verified through the data verification system, that is, the hash function is used to generate a sentinel to perform matching verification on the cloud and terminal data to detect whether the data is damaged. If it is damaged, repair the damaged part. If not, the verification is completed. In the case where the data is not damaged, verify the redundancy of the data again, that is, detect whether there are duplicate data. If there are, delete the duplicate data. If not, the verification is completed;

[0021] S4: Cloud monitoring and recording: After the data enters the cloud storage, the cloud monitoring and scanning system continuously monitors the status, performs risk scanning and vulnerability scanning on the cloud applications, quickly judges whether the source of the security risk is external or internal at the first time when the cloud is threatened, analyzes the source judgment result, and collects, stores and analyzes all behaviors and access contents of accessing the cloud database. At the same time, a compliance report is generated and sent to the corresponding connected terminal.

[0022] Compared with the prior art, the beneficial effects of the present invention are: 1. By integrating the cloud and the terminal, the cloud performs the security protection work, and the terminal, that is, the user side, verifies the security protection of the cloud, so as to reasonably allocate the data security work to the cloud and the terminal, make full use of their respective advantages, form a more perfect security protection method with less burden on their respective mechanisms, and this setting enables the terminal to have a certain control over the cloud;

[0023] 2. Before data transmission, the data is split and encrypted. The user needs to decrypt the data accordingly after downloading it, thus avoiding the situation of data leakage caused by data loss;

[0024] 3. Scan the cloud space of Jianing for security monitoring. It can quickly determine whether the source of the security risk is external or internal at the first time of being threatened, and analyze the source judgment result to effectively identify and block interception. At the same time, collect, store and analyze all behaviors and access content of the cloud database, generate a compliance report, and send the report to the corresponding connected terminal for subsequent traceability use to improve data security. BRIEF DESCRIPTION OF THE DRAWINGS

[0025] The drawings are used to provide a further understanding of the present invention, and constitute a part of the specification. Together with the embodiments of the present invention, they are used to explain the present invention and do not constitute a limitation to the present invention.

[0026] In the drawings:

[0027] Figure 1 is a block diagram of a cloud-based data storage protection system of the present invention;

[0028] Figure 2 is a flowchart of a cloud-based data storage protection method of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0029] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments; based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.

[0030] As Figure 1 shown, the present invention provides a technical solution: a cloud-based data storage protection system, including a data transmission system, which is used to transmit terminal data and cloud data, and the transmission directions include from the terminal to the cloud and from the cloud to the terminal, and encrypt the transmission link during the transmission process;

[0031] A split encryption system: The split encryption system is set at the terminal and is used to split and encrypt the data that needs to be stored in the cloud, and transmit the split and encrypted data to the cloud. The split encryption system includes a random split unit, an encryption unit and a decryption unit, and the encryption unit and the decryption unit are matched;

[0032] A terminal verification system: The terminal verification system is set at the terminal and is used to verify the data protection unit in the cloud. The terminal verification system includes a user data unit, a data verification unit and a data protection unit;

[0033] Cloud protection system: The cloud protection system is set up in the cloud. It is used to provide data protection for the data transmitted to the cloud. The content of data protection includes the protection of the verified and proven security attributes of the data;

[0034] Monitoring and scanning system: The monitoring and scanning system is set up in the cloud. It is used to continuously monitor the status, scan for risks and vulnerabilities of cloud applications, so as to quickly judge whether the source of security risks is external or internal at the first time when a threat occurs, and analyze the source judgment result;

[0035] Operation record system: The operation record system is set up in the cloud. It is used to collect, store and analyze all behaviors and access content of accessing the cloud database, generate a compliance report at the same time, and send the report to the corresponding connected terminal;

[0036] Data verification system: The data verification system is set up in the cloud and the terminal. It is used to perform integrity verification on the data transmitted to the cloud. The data verification system is specifically the data possession proxy proof verification technology. The data verification system includes a data verification unit and a data optimization unit.

[0037] Among them, when the data transmission system performs encryption processing, it specifically uses one or a combination of several of DES data encryption technology, one-way function data encryption technology, one-way Hash function data encryption technology, AES data encryption technology or RSA data encryption technology; in the split encryption system, the random split unit is used to randomly split the data that needs to be stored in the cloud in a random order. The random split unit specifically uses the recipes balanced split technology and is equipped with the lars regression verification technology; the encryption unit specifically uses the encryption algorithm based on ciphertext attributes; the decryption unit specifically uses the decryption algorithm based on key attributes; the terminal verification system and the cloud protection system are specifically the data integrity protection technology based on resistance to repudiation, the full-text searchable encryption technology based on AONE and secret sharing, and the search result verification technology based on the function redundancy decomposition model; the specific monitoring content of the monitoring and scanning system includes core database assets, security vulnerability attacks, SQL injection and virus infection; the data verification system specifically uses the retrievability proof method or the data possession proof method. The data verification unit is used to verify the integrity of the data and re-transmit it when the data is missing; the data optimization unit is used to verify the redundancy of the transmitted data and delete duplicate data.

[0038] By integrating the cloud and the terminal, the cloud is responsible for security protection work, while the terminal, i.e., the user side, verifies the security protection of the cloud. Thus, the data security work is reasonably allocated to the cloud and the terminal, making full use of their respective advantages to form a more perfect security protection method with a smaller burden on their respective mechanisms. Moreover, this setting gives the terminal a certain degree of control over the cloud. Before data transmission, the data is split and encrypted. The user needs to decrypt and use the data after downloading it, thus avoiding the situation of data leakage caused by data loss.

[0039] As Figure 2 shown, a cloud-based data storage protection method includes the following steps:

[0040] S1: Data splitting and encryption: The data to be stored in the cloud is randomly split by the random splitting unit in the splitting and encryption system, and the split data is encrypted by the encryption unit. After encryption is completed, an upload operation is performed.

[0041] S2: Cloud protection verification: On the basis of step S1, during the process of uploading data to the cloud, the cloud provides support for the protection system, that is, the cloud re-encrypts the data and generates a receipt of the encrypted file data and feedbacks it to the terminal. The terminal verification system of the terminal verifies the data security and correctness of this receipt and then confirms the upload.

[0042] S3: Data integrity verification: During the process of data entering the cloud, the integrity of the data is verified through the data verification system, that is, a hash function is used to generate a sentinel to perform matching verification on the data in the cloud and the terminal to detect whether the data is damaged. If it is damaged, the damaged part is repaired. If not, the verification is completed. In the case where the data is not damaged, the redundancy of the data is verified again, that is, it is detected whether there are duplicate data. If there are, the duplicate data is deleted. If not, the verification is completed.

[0043] S4: Cloud monitoring and recording: After the data enters the cloud storage, the cloud monitoring and scanning system continuously monitors the status, scans for risks, and scans for vulnerabilities of the cloud applications. And it quickly judges whether the source of the security risk is external or internal at the first time when the cloud is threatened, and analyzes the source judgment result. At the same time, it collects, stores, and analyzes all behaviors and access contents of accessing the cloud database, generates a compliance report, and sends the report to the corresponding connected terminal.

[0044] Through the above steps, scanning the cloud space of Jianing for security monitoring can quickly determine whether the source of the security risk is external or internal at the first moment of being threatened, and analyze the source judgment result to effectively identify and block the interception. At the same time, collect, store and analyze all behaviors and access content of the cloud database, generate a compliance report, and send the report to the corresponding connected terminal for subsequent traceability use to improve data security.

[0045] It should be noted that in this article, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the term "comprising", "including" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, article or device comprising a series of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such process, method, article or device.

[0046] Although the embodiments of the present invention have been shown and described, those of ordinary skill in the art can understand that various changes, modifications, substitutions and variations can be made to these embodiments without departing from the principles and spirit of the present invention. The scope of the present invention is defined by the appended claims and their equivalents.

Claims

1. A data storage protection system based on the cloud, characterized in that: It includes a data transmission system for transmitting terminal data and cloud data. The transmission directions include from the terminal to the cloud and from the cloud to the terminal, and the transmission link is encrypted during the transmission process; Split encryption system: The split encryption system is set in the terminal. The split encryption system is used to split and encrypt the data that needs to be stored in the cloud, and transmit the split and encrypted data to the cloud. The split encryption system includes a random split unit, an encryption unit, and a decryption unit, and the encryption unit and the decryption unit are matched; Terminal verification system: The terminal verification system is set in the terminal. The terminal verification system is used to verify the data protection unit in the cloud. The terminal verification system includes a user data unit, a data verification unit, and a data protection unit; Cloud protection system: The cloud protection system is set in the cloud. The cloud protection system is used to provide data protection for the data transmitted to the cloud. The content of the data protection includes the protection of the verified and proven security attributes of the data; Monitoring and scanning system: The monitoring and scanning system is set in the cloud. The monitoring and scanning system is used to continuously monitor the status, scan for risks, and scan for vulnerabilities of cloud applications, so as to quickly judge whether the source of the security risk is external or internal at the first time when the threat occurs, and analyze the source judgment result; Operation record system: The operation record system is set in the cloud. The operation record system is used to collect, store, and analyze all behaviors and access content of accessing the cloud database, generate a compliance report at the same time, and send the report to the corresponding connected terminal; Data verification system: The data verification system is set in the cloud and the terminal. The data verification system is used to perform integrity verification on the data transmitted to the cloud. The data verification system is specifically the data possession proxy proof verification technology. The data verification system includes a data verification unit and a data optimization unit. The data verification unit is used to verify the integrity of the data and re-transmit it when the data is missing; the data optimization unit is used to verify the redundancy of the transmitted data and delete duplicate data.

2. The data storage protection system based on the cloud according to claim 1, wherein: When the data transmission system performs encryption processing, it specifically uses one or a combination of DES data encryption technology, one-way function data encryption technology, one-way Hash function data encryption technology, AES data encryption technology, or RSA data encryption technology.

3. A data storage protection system based on the cloud according to claim 1, characterized in that: In the split encryption system, the random split unit is used to randomly split the data that needs to be stored in the cloud. The random split unit specifically uses the recipes balanced split technology and is equipped with the lars regression verification technology; the encryption unit specifically uses an encryption algorithm based on ciphertext attributes; the decryption unit specifically uses a decryption algorithm based on key attributes.

4. A data storage protection system based on the cloud according to claim 1, characterized in that: The terminal verification system and the cloud protection system are specifically data integrity protection technologies based on resistance to reliance, full-text search encryption technologies based on AONE and secret sharing, and search result verification technologies based on function redundancy decomposition models.

5. A data storage protection system based on the cloud according to claim 1, characterized in that: The specific monitoring content of the monitoring and scanning system includes core database assets, security vulnerability attacks, SQL injection, and virus infections.

6. A data storage protection system based on the cloud according to claim 1, wherein: The data verification system specifically adopts the proof of retrievability method or the proof of data possession method.

7. A data storage protection method based on the cloud, which is applied to the data storage protection system based on the cloud according to any one of claims 1-6, and is characterized in that: It includes the following steps: S1: Data splitting and encryption: The data to be stored in the cloud is randomly split by the random splitting unit in the splitting and encryption system, and the split data is encrypted by the encryption unit. After encryption, the upload operation is performed. S2: Cloud protection verification: On the basis of step S1, during the process of uploading data to the cloud, the cloud provides support for the protection system, that is, the cloud re-encrypts the data, and generates a receipt of the encrypted file data and feedbacks it to the terminal. The terminal verification system of the terminal verifies the data security and correctness of this receipt and then confirms the upload. S3: Data integrity verification: During the process of data entering the cloud, the data integrity is verified by the data verification system, that is, a sentinel is generated using a hash function to perform a matching verification on the cloud and terminal data to detect whether the data is damaged. If it is damaged, the damaged part is repaired. If not, the verification is completed. In the case where the data is not damaged, the redundancy of the data is verified again, that is, to detect whether there are duplicate data. If there are, the duplicate data is deleted. If not, the verification is completed. S4: Cloud monitoring record: After the data enters the cloud storage, the cloud monitoring and scanning system continuously monitors the status, risks, and vulnerabilities of the cloud applications, and quickly determines whether the source of the security risk is external or internal at the first time when the cloud is threatened, and analyzes the source judgment result. At the same time, all behaviors and access contents of accessing the cloud database are collected, stored, and analyzed, and a compliance report is generated and sent to the corresponding connected terminal.

Citation Information

Patent Citations

  • Method and system for encrypting, decrypting and verifying cloud storage front end data

    CN104809407A

  • Cloud storage data authorization method and device based on terminal identity verification

    CN114070591A