An information security storage device

By differentiating and encrypting information and monitoring intrusion behavior, the problem of low overall information encryption effectiveness is solved, achieving high-security storage and enhanced security.

CN116185295BActive Publication Date: 2026-04-07JIANGSU AONUO POWER TECH CO LTD
View PDF 5 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-02-23
Publication Date
2026-04-07

AI Technical Summary

Technical Problem

Existing technologies do not differentiate between different information segments within the information stream for encryption, resulting in poor overall encryption effectiveness and making it easy for external personnel to decrypt.

Method used

The information is divided into several segments of node information to be encrypted, encrypted according to capacity and ranking parameters, and a terminal encryption value is set at the back end of each segment. The segments are then merged into a single data packet for storage. The number of times and duration of intrusion attempts are monitored to determine the danger level and improve the security of storage.

Benefits of technology

By differentiating between encryption and monitoring intrusion behavior, the security of information storage is improved, preventing information from being stolen by external personnel and enhancing security effectiveness.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116185295B_ABST
    Figure CN116185295B_ABST
Patent Text Reader

Abstract

This invention discloses an information security storage device, relating to the field of information security storage technology. It solves the technical problem that the overall encryption effect of information is not high due to the lack of differentiation and encryption of different information segments within the information. The invention pre-enters the information to be stored, dividing the entered information into several segments to be encrypted. Then, based on the capacity and ranking parameters of the segments to be encrypted, different segments are encrypted. End-to-end encryption values ​​are set at the end of different groups of segments to be encrypted. Subsequently, the segments to be encrypted are mixed and merged into a single data packet, which is then transmitted to the storage unit for storage. When external personnel intrude into the corresponding storage unit, it is difficult to merge the segments to be encrypted, thus improving the security of storing different information and preventing information from being stolen by external personnel.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The application belongs to the technical field of information security storage, and specifically relates to an information security storage device. BACKGROUND

[0002] Information security, the definition of ISO, is that the technology and management security protection established and adopted for data processing systems are used to protect computer hardware, software and data from being damaged, changed and leaked due to accidents.

[0003] The application disclosed in Patent Publication No. CN112732193B discloses an information security storage system based on big data, which is used to solve the problem of safe transfer of security information after being attacked under the condition of big data; when the central server in the big data platform is attacked, the information migration module will generate pseudo data, and send the pseudo data to the second screening server, the preferred second screening server and the preferred third screening server, and transfer the first data to the escape server through the transfer server; the first data is sent to the escape server through the progressive method, which ensures the safety of information in the transmission process due to the selection of adjacent servers for transmission, reduces the transmission delay caused by long transmission distance, and ensures the safety of information in the transmission process, and since the trajectory of data migration changes in real time according to the big data platform, the final escape server is randomly selected, which greatly increases the security of information storage and avoids the re-theft of data transfer after being tracked.

[0004] During the safe storage of information, a corresponding encryption key is generally set during the storage process, and the stored information is decrypted through the encryption key subsequently, but this method is easy to be decrypted by external personnel to the stored information, and the overall encryption method is not high, because different information segment flows in the information are not distinguished and encrypted, so that the overall encryption effect of the information is not high. SUMMARY

[0005] The present application aims to at least solve one of the technical problems existing in the prior art; for this purpose, the present application proposes an information security storage device to solve the technical problem that the overall encryption effect of information is not high because different information segment flows in the information are not distinguished and encrypted.

[0006] To achieve the above-mentioned purpose, according to the embodiment of the first aspect of the present application, an information security storage device is provided, which comprises an information input unit, a security storage center and a display terminal;

[0007] The security storage center comprises an input analysis unit, a node encryption unit, a storage unit, a recording unit, a monitoring analysis unit and a capacity reduction unit;

[0008] The information input unit is configured to input information to be stored and transmit the input information to the secure storage center.

[0009] The input analysis unit is configured to analyze and record the real-time input information, and divide the input information into a plurality of groups of node information to be encrypted.

[0010] The node encryption unit is configured to receive the plurality of groups of node information to be encrypted, encrypt different groups of node information to be encrypted according to the capacity parameter and the ranking parameter of the node information to be encrypted, and set an end encryption value at the back end of each group of node information to be encrypted.

[0011] The capacity reduction unit is configured to analyze and combine a plurality of groups of single data packets stored in the storage unit, replace the same data in the plurality of groups of single data packets with different repetition marks, and reduce the overall capacity of the single data packets.

[0012] The monitoring analysis unit is configured to monitor the intrusion object of the secure storage center, monitor the number of times and the total intrusion time of the intrusion object in different storage intervals, and analyze and combine the monitoring results, and take different measures according to the analysis results.

[0013] Preferably, the input analysis unit analyzes and records the real-time input information in the following manner:

[0014] The capacity of the input information is recorded in real time, the time of real-time recording is recorded, and the recorded time parameter is marked as SJ i , wherein i represents different times, and the real-time recording time parameter SJ i is compared with a preset parameter Y1 until the time parameter SJ i reaches the preset parameter Y1, and the input information is determined as a first group of node information to be encrypted.

[0015] Subsequently, the capacity of the subsequent information is recorded until the recorded time parameter SJ i reaches the preset parameter Y1, and the capacity of the subsequent information is determined as a second group of node information to be encrypted.

[0016] In this way, the real-time input information is determined as a plurality of groups of node information to be encrypted, and the input time of each group of node information to be encrypted is the same.

[0017] Preferably, the node encryption unit encrypts different groups of node information to be encrypted in the following manner:

[0018] Mark the overall capacity of different node information segments to be encrypted as RL k , where k represents different node information segments to be encrypted, further acquire the overall ranking information of the corresponding node information segments to be encrypted, and mark the ranking information as PM k ;

[0019] Adopt JM k = RL k × C1+ PM k × C2 to obtain the end encryption value JM k of different node information segments to be encrypted, where C1 and C2 are both preset fixed coefficient factors, and the end encryption value JM k is arranged at the rear end position of the corresponding node information segment to be encrypted.

[0020] Bundle the several groups of node information segments to be encrypted after processing into a single group of data packets, and transmit the single group of data packets to the storage unit for storage processing.

[0021] Preferably, the capacity reduction unit specifically adopts the following manner for the merging analysis of the several groups of single group of data packets:

[0022] Extract the repeated data replacement table from the storage unit, where the repeated data replacement table is prepared by external operators according to personal experience, and the corresponding single group of data packets is extracted;

[0023] Compare and analyze the data in the single group of data packets with the repeated data replacement table, and adopt the repeated marker CF t Replace the repeated data existing in the single group of data packets, and fill the corresponding repeated marker CF t at the position where the repeated data appears.

[0024] Transmit the single group of data packets replaced by the repeated marker CF t to the storage unit again for storage, for extraction by external operators.

[0025] Preferably, the monitoring and analyzing unit specifically adopts the following manner for the monitoring and merging analysis of the number of times of intervention of the intrusion object into different storage intervals and the total intervention time length:

[0026] Mark the number of times of intervention of the intrusion into different storage intervals as CSm, and mark the total intervention time length as SCm, where m represents different intrusion objects;

[0027] Adopt XDm = CSm × A1+ SCm × A2 to obtain the limited comparison parameter XDm, where A1 and A2 are both preset fixed coefficient factors;

[0028] The comparison parameter XDm is compared with the preset parameter Y2, where Y2 is the preset value. When XDm < Y2, no processing is performed; otherwise, a danger signal is generated. The recording unit records the IP address of the intrusion target based on the danger signal and directly blacklists the IP address, preventing the terminal device with the corresponding IP address from accessing the secure storage center.

[0029] Preferably, the information is extracted by an external operator on the display terminal, and then, according to the restoration rules within the secure storage center, the stored single data packets are merged and converted back into the original entered information. The specific method for entering and restoring the information is as follows:

[0030] Extract the corresponding single data packet, compare the duplicate markers inside the single data packet with the duplicate data replacement table according to the duplicate data replacement table, extract the corresponding duplicate data, and fill the duplicate data into the single data packet;

[0031] After a single data packet is transmitted, extract the end-to-end encryption value JM from the end of the information segments of different nodes to be encrypted within the packet. k Extract the data and obtain the overall capacity parameter RL of the information segment of this node to be encrypted. k ,use Obtain the ranking information PM corresponding to the information segment to be encrypted k ;

[0032] Then, based on the ranking information of different segments of information to be encrypted, PM k Several groups of information segments to be encrypted are integrated. During the integration process, the terminal encryption value JM added at the end is extracted. k The original input information is obtained and displayed through a display terminal.

[0033] Compared with the prior art, the beneficial effects of the present invention are as follows: the information to be stored is pre-entered, and then the information entered in real time is analyzed and recorded. According to the preset time parameters, the entered information is divided into several nodes to be encrypted. Then, according to the capacity parameters and ranking parameters of the nodes to be encrypted, different nodes to be encrypted are encrypted. End encryption values ​​are set at the back end of different groups of nodes to be encrypted. Subsequently, several nodes to be encrypted are mixed and merged into a single data packet and transmitted to the storage unit for storage. When external personnel invade the corresponding storage unit, it is difficult to merge several groups of nodes to be encrypted, thereby improving the security storage effect of different information and preventing information from being stolen by external personnel.

[0034] Furthermore, the intrusion targets in the secure storage center are monitored, including the number of times the intrusion targets intervened in different storage areas and the total duration of intervention. These are then combined and analyzed to determine the danger level of the intrusion targets, thereby improving the overall security effect of this secure storage device. Attached Figure Description

[0035] Figure 1 This is a schematic diagram of the principle framework of the present invention. Detailed Implementation

[0036] The technical solution of the present invention will be clearly and completely described below with reference to the embodiments. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0037] Please see Figure 1 This application provides an information security storage device, including an information input unit, a secure storage center, and a display terminal;

[0038] The information input unit is electrically connected to the input terminal of the secure storage center, and the secure storage center is electrically connected to the input terminal of the display terminal;

[0039] The secure storage center includes an input analysis unit, a node encryption unit, a storage unit, a recording unit, a monitoring analysis unit, and a capacity reduction unit;

[0040] The input analysis unit is electrically connected to the input terminal of the node encryption unit, the node encryption unit is electrically connected to the input terminal of the storage unit, the capacity reduction unit is bidirectionally connected to the storage unit, the recording unit is bidirectionally connected to the monitoring analysis unit, and the monitoring analysis unit is electrically connected to the input terminal of the storage unit.

[0041] The information entry unit is used to enter information that needs to be stored. The operator performs the operation and transmits the entered information to the secure storage center.

[0042] The input analysis unit is used to analyze and record the information entered in real time, dividing the entered information into several node information segments to be encrypted. The specific method of analysis and recording is as follows:

[0043] The amount of information entered is recorded in real time, and the time of real-time recording is also recorded. The recorded time parameter is marked as SJ. i Where i represents different times, and the real-time recorded time parameter SJ i The comparison is performed with the preset parameter Y1 until the time parameter SJ is reached. i When the preset parameter Y1 is reached, the entered information is designated as the first group of node information segments to be encrypted;

[0044] Subsequently, the amount of information is recorded until the recorded time parameter SJ is reached.i When the preset parameter Y1 is reached, the subsequent information capacity is set as the second group of node information segments to be encrypted;

[0045] Similarly, the real-time entered information is set as a plurality of groups of node information segments to be encrypted, and the entry time of each group of node information segments to be encrypted is the same.

[0046] The node encryption unit is configured to receive the plurality of groups of node information segments to be encrypted set by the entry analysis unit, encrypt different node information segments to be encrypted according to the capacity parameters and ranking parameters of the node information segments to be encrypted, and set an end encryption value at the back end of different groups of node information segments to be encrypted, wherein the encryption processing is performed in the following manner:

[0047] The overall capacity of different node information segments to be encrypted is marked as RL k , wherein k represents different node information segments to be encrypted, the overall ranking information of the corresponding node information segment to be encrypted is obtained, and the ranking information is marked as PM k ;

[0048] The end encryption value JM k of different node information segments to be encrypted is obtained by using JM k = RL k × C1 + PM k × C2, wherein C1 and C2 are preset fixed coefficient factors, the specific values of which are set by an operator according to experience, and the end encryption value JM k is set at the back end position of the corresponding node information segment to be encrypted.

[0049] The plurality of groups of node information segments to be encrypted processed are bundled into a single group of data packets, and the single group of data packets is transmitted to the storage unit for storage processing.

[0050] The capacity reduction unit is configured to perform merging analysis on a plurality of groups of single group of data packets according to the single group of data packets stored in the storage unit, replace the same data existing in the plurality of groups of single group of data packets with different repetition marks, so as to reduce the overall capacity of the corresponding single group of data packets, wherein the merging analysis is performed in the following manner:

[0051] A repetition data replacement table is extracted from the storage unit, wherein the repetition data replacement table is set by an external operator according to personal experience, and the corresponding single group of data packets is extracted.

[0052] The data in the single group of data packets is compared and analyzed with the repetition data replacement table, and the repetition mark CF t is used to replace the repeated data existing in the single group of data packets, and the corresponding repetition mark CF t is filled in the position where the repeated data appears.

[0053] CF will be used for repeating marking t The replaced single data packet is transmitted to the storage unit for storage again, so that it can be retrieved by external operators.

[0054] The monitoring and analysis unit is used to monitor intrusion targets in the secure storage center, monitor the number of times an intrusion target enters different storage areas and the total duration of the entry, and perform combined analysis to determine the danger level of the intrusion target. The specific method of performing combined analysis is as follows:

[0055] The number of times an intrusion occurs in different storage regions is denoted as CSm, and the total duration of the intrusion is denoted as SCm, where m represents different intrusion targets;

[0056] The comparison parameter XDm is obtained by using XDm = CSm × A1 + SCm × A2, where A1 and A2 are preset fixed coefficient factors, and their specific values ​​are determined by the operator based on experience.

[0057] The comparison parameter XDm is compared with the preset parameter Y2, where Y2 is a preset value, the specific value of which is determined by the operator based on experience. When XDm < Y2, no processing is performed; otherwise, a danger signal is generated. The recording unit records the IP address of the intrusion target based on the danger signal and directly blacklists this IP address, preventing the terminal device corresponding to the IP address from accessing this secure storage center.

[0058] The display terminal allows external operators to extract information and then, according to the restoration rules within the secure storage center, merge the stored single data packets into the original entered information. The specific method for entering and restoring the information is as follows:

[0059] Extract the corresponding single data packet, compare the duplicate markers inside the single data packet with the duplicate data replacement table according to the duplicate data replacement table, extract the corresponding duplicate data, and fill the duplicate data into the single data packet;

[0060] After a single data packet is transmitted, extract the end-to-end encryption value JM from the end of the information segments of different nodes to be encrypted within the packet. k Extract the data and obtain the overall capacity parameter RL of the information segment of this node to be encrypted. k (This capacity parameter does not take into account the terminal encryption value JM) k (The occupied capacity) Obtain the ranking information PM corresponding to the information segment to be encrypted k ;

[0061] Then, based on the ranking information of different segments of information to be encrypted, PM kSeveral groups of information segments to be encrypted are integrated. During the integration process, the terminal encryption value JM added at the end is extracted. k The original input information is obtained and displayed through a display terminal.

[0062] The data in the above formula are all calculated by removing the dimensions and taking the numerical values. The formula is the closest to the real situation obtained by software simulation of a large amount of collected data. The preset parameters and preset thresholds in the formula are set by those skilled in the art according to the actual situation or obtained through simulation of a large amount of data.

[0063] The working principle of this invention is as follows: Information to be stored is pre-entered, and then the real-time entered information is analyzed and recorded. According to preset time parameters, the entered information is divided into several segments of information to be encrypted. Then, according to the capacity parameters and ranking parameters of the segments of information to be encrypted, different segments of information to be encrypted are encrypted. End encryption values ​​are set at the end of different groups of segments of information to be encrypted. Subsequently, several segments of information to be encrypted are mixed and merged into a single data packet, which is then transmitted to the storage unit for storage. When external personnel intrude into the corresponding storage unit, it is difficult to merge several groups of segments of information to be encrypted, thereby improving the secure storage effect of different information and preventing information from being stolen by external personnel.

[0064] Furthermore, the intrusion targets in the secure storage center are monitored, including the number of times the intrusion targets intervened in different storage areas and the total duration of intervention. These are then combined and analyzed to determine the danger level of the intrusion targets, thereby improving the overall security effect of this secure storage device.

[0065] The above embodiments are only used to illustrate the technical methods of the present invention and are not intended to limit it. Although the present invention has been described in detail with reference to preferred embodiments, those skilled in the art should understand that modifications or equivalent substitutions can be made to the technical methods of the present invention without departing from the spirit and scope of the technical methods of the present invention.

Claims

1. An information security storage device, characterized in that, It includes an information input unit, a secure storage center, and a display terminal; The secure storage center includes an input analysis unit, a node encryption unit, a storage unit, a recording unit, a monitoring analysis unit, and a capacity reduction unit; The information input unit is used to input the information that needs to be stored and to transmit the input information to the secure storage center. The input analysis unit is used to analyze and record the information entered in real time, and to divide the entered information into several node information segments to be encrypted. The node encryption unit is used to receive several groups of node information segments to be encrypted as specified by the input analysis unit, encrypt different node information segments according to their capacity and ranking parameters, and set end-to-end encryption values ​​at the end of different groups of node information segments. Specifically: The overall capacity of different data segments to be encrypted is denoted as RL. k Where k represents different information segments of nodes to be encrypted, then the overall ranking information of the corresponding information segments of nodes to be encrypted is obtained, and the ranking information is marked as PM. k ; use Obtain the end-encrypted value JM of different node information segments to be encrypted k C1 and C2 are both preset fixed coefficient factors, and the end encrypted value JM k It is set at the back end of the corresponding node information segment to be encrypted; After processing, several groups of node information segments to be encrypted are bundled into a single data packet, and the single data packet is transmitted to the storage unit for storage processing. The capacity reduction unit merges and analyzes several sets of single data packets based on the single data packets stored in the storage unit, and replaces the same data in the several sets of single data packets with different duplicate tags, thereby reducing the overall capacity of the corresponding single data packet. The monitoring and analysis unit is used to monitor intrusion targets in the secure storage center, monitor the number of times the intrusion targets intervene in different storage areas and the total intervention time, and perform combined analysis. Based on the analysis results, different countermeasures are taken.

2. The information security storage device according to claim 1, characterized in that, The input analysis unit analyzes and records the information entered in real time in the following specific way: The amount of information entered is recorded in real time, and the time of real-time recording is also recorded. The recorded time parameter is marked as SJ. i Where i represents different times, and the real-time recorded time parameter SJ i The comparison is performed with the preset parameter Y1 until the time parameter SJ is reached. i When the preset parameter Y1 is reached, the entered information is designated as the first group of node information segments to be encrypted; Subsequently, the amount of information is recorded until the recorded time parameter SJ is reached. i When the preset parameter Y1 is reached, the subsequent information capacity will be set as the second group of node information segments to be encrypted; Similarly, the information entered in real time is divided into several groups of node information segments to be encrypted, and the entry time for each group of node information segments to be encrypted is the same.

3. The information security storage device according to claim 1, characterized in that, The capacity reduction unit performs the merging and analysis of several groups of single data packets in the following specific manner: The deduplication table is extracted from the storage unit. The deduplication table is formulated by external operators based on their personal experience. The corresponding single data packets are then extracted. The data within a single data packet is compared and analyzed with a duplicate data replacement table, using a duplicate tagging function (CF). t Replace duplicate data within a single data packet by filling in the corresponding duplicate marker (CF) at the location where the duplicate data appears. t ; CF will be used for repeating marking t The replaced single data packet is transmitted to the storage unit for storage again, so that it can be retrieved by external operators.

4. The information security storage device according to claim 3, characterized in that, The monitoring and analysis unit monitors and analyzes the number of times the intrusion target intervenes in different storage areas and the total intervention time in the following specific way: The number of times an intrusion occurs in different storage regions is denoted as CSm, and the total duration of the intrusion is denoted as SCm, where m represents different intrusion targets; The comparison parameter XDm is obtained by using XDm=CSm×A1+SCm×A2, where A1 and A2 are preset fixed coefficient factors; The comparison parameter XDm is compared with the preset parameter Y2, where Y2 is the preset value. When XDm < Y2, no processing is performed; otherwise, a danger signal is generated. The recording unit records the IP address of the intrusion target based on the danger signal and directly blacklists the IP address, preventing the terminal device with the corresponding IP address from accessing the secure storage center.

5. The information security storage device according to claim 4, characterized in that, The display terminal allows external operators to extract information and then, according to the restoration rules within the secure storage center, merge the stored single data packets into the original entered information. The specific method for entering and restoring the information is as follows: Extract the corresponding single data packet, compare the duplicate markers inside the single data packet with the duplicate data replacement table according to the duplicate data replacement table, extract the corresponding duplicate data, and fill the duplicate data into the single data packet; After a single data packet is transmitted, extract the end-to-end encryption value JM from the end of the information segments of different nodes to be encrypted within the packet. k Extract the data and obtain the overall capacity parameter RL of the information segment of this node to be encrypted. k ,use Obtain the ranking information PM corresponding to the information segment to be encrypted k ; Then, based on the ranking information of different segments of information to be encrypted, PM k Several groups of information segments to be encrypted are integrated. During the integration process, the terminal encryption value JM added at the end is extracted. k The original input information is obtained and displayed through a display terminal.

Citation Information

Patent Citations

  • A data security storage system

    CN112732193B

  • Risk management and control system based on AIoT intelligent edge gateway

    CN114710353A

  • Enterprise operation management information storage system

    CN114997843A

  • Industrial internet platform data transmission security protection system

    CN115174255A

  • Vehicle-mounted data encryption method and device, computer equipment and communication system

    CN115361669A