A system for centrally storing encryption

CN117195303BActive Publication Date: 2026-08-11BEIJING INST OF COMP TECH & APPL
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-09-26
Publication Date
2026-08-11

AI Technical Summary

Technical Problem

[0010]本发明要解决的技术问题是如何提供一种数据集中存储加密的系统,以解决当前涉密数据集中存储的加密保护方法需要区分结构化数据和非结构化数据两种类型分别设计加密存储方案,存在投资成本大、管理维护复杂、能耗较大等问题

Benefits of technology

[0019]本发明提出一种数据集中存储加密的系统,本发明的关键:本发明针对非结构化数据,不采用直接进行数据集中存储加密的方式,而是由文件应用系统统一管理、处理、存储数据,优化了非结构化数据可以采用存储加密设备的“扇区加密”工作模式进行数据集中存储加密保护,从而实现了结构化数据和非结构化数据统一由一套集中存储系统,部署一台存储加密设备或者一个数据加密存储集群,进行数据集中存储加密保护。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN117195303B_ABST
    Figure CN117195303B_ABST
Patent Text Reader

Abstract

This invention relates to a system for centralized data storage encryption, belonging to the field of data security. For unstructured data, this invention does not employ direct centralized data storage encryption. Instead, it uses a file application system to uniformly manage, process, and store the data. It optimizes the centralized storage encryption protection of unstructured data by utilizing the "sector encryption" working mode of the storage encryption device. This allows both structured and unstructured data to be uniformly protected by a single centralized storage system, deploying a single storage encryption device or a data encryption storage cluster. This invention optimizes the design of centralized storage encryption protection technology, saving costs, simplifying operation, and reducing energy consumption.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the field of data security, and specifically relates to a system for centralized encrypted data storage. Background Technology

[0002] For information systems that meet certain levels of graded protection, encrypted protection measures are required for centrally stored classified data. Generally, classified data includes structured and unstructured data. Currently, the encryption protection measure used for centralized storage of structured classified data is to use a "sector encryption" working mode on the storage encryption device. This achieves both data encryption protection and ensures data read and write speeds. For centralized storage of unstructured data, the encryption protection measure used is to use a "file encryption" working mode on the storage encryption device. This allows for encryption protection of each individual file, but because each file is encrypted, the read and write speeds are relatively slower.

[0003] Under current technological conditions, only one type of storage encryption device can achieve centralized storage and encryption protection for classified data. Although this type of storage encryption device has two working modes, namely "sector encryption" and "file encryption," a single storage encryption device or a data encryption storage cluster can only select one working mode when providing data encryption services; it cannot support both working modes simultaneously. This necessitates designing separate centralized storage and encryption protection methods for structured and unstructured data, requiring two storage encryption devices or two data encryption storage clusters to provide centralized storage and encryption protection for structured and unstructured data respectively.

[0004] In summary, classified information systems typically store both structured and unstructured data. Under current technological conditions, the planning and design of such systems requires the simultaneous design of two centralized storage and encryption protection methods: one centralized storage scheme and one set of encryption devices for structured data, and another centralized storage scheme and one set of encryption devices for unstructured data. However, in practice, only one storage scheme is often designed during the planning phase, with the problem addressed through changes during implementation. This not only impacts project schedule and increases costs but also creates a series of problems during project implementation.

[0005] Current methods for encrypting and protecting centrally stored classified data require separate encryption schemes for structured and unstructured data, which leads to problems such as high investment costs, complex management and maintenance, and high energy consumption. A detailed analysis follows:

[0006] (1) High investment cost. When planning and designing an information system, it is necessary to design separate encryption storage schemes for structured and unstructured data, build two storage systems, and deploy two storage encryption devices or two data encryption storage clusters. If the two systems are combined into one, the cost can be greatly reduced.

[0007] (2) Complex management and maintenance. Generally speaking, disk arrays are used for centralized storage of structured data, while NAS systems are used for centralized storage of unstructured data. The two storage systems have different working mechanisms and maintenance methods. Management and maintenance personnel need to master the management and maintenance methods of both storage systems in order to provide good operation and maintenance services, which increases the skill requirements, time costs and energy required of management and maintenance personnel.

[0008] (3) High energy consumption. Building two storage systems and deploying two storage encryption devices or two data encryption storage clusters requires more equipment resources, and the corresponding energy consumption of the equipment also increases. Summary of the Invention

[0009] (a) Technical problems to be solved

[0010] The technical problem this invention aims to solve is how to provide a system for centralized encrypted data storage, in order to address the current encryption protection methods for centralized storage of classified data, which require different encryption storage schemes for structured and unstructured data, resulting in high investment costs, complex management and maintenance, and high energy consumption.

[0011] (II) Technical Solution

[0012] To address the aforementioned technical problems, this invention proposes a data centralized storage encryption system, which includes: user groups 1-n, switches, service areas, storage switch 1, data encryption storage cluster, storage switch 2, and a centralized storage system.

[0013] User groups 1-n include: each user group represents a relatively concentrated group of users;

[0014] The business service area includes the following business systems: a file application system and other business application systems. The other business application systems are various application systems that provide services, including application system 1 to application system K. Each business system is deployed on a server, wherein the file application system is used for unified management and processing of unstructured data.

[0015] A data encryption storage cluster includes: a single storage encryption device or a cluster consisting of M storage encryption devices;

[0016] A centralized storage system includes: a set of disk arrays or a group of disk arrays that provide centralized storage services;

[0017] The connection relationship between the components is as follows: user groups 1-n access the switch, the switch connects to the server in the service area, the server in the service area connects to storage switch 1, storage switch 1 connects to the data encryption storage cluster, the data encryption storage cluster connects to storage switch 2, and storage switch 2 connects to the centralized storage system.

[0018] (III) Beneficial Effects

[0019] This invention proposes a centralized data storage encryption system. The key to this invention is that, for unstructured data, instead of directly performing centralized data storage encryption, the file application system uniformly manages, processes, and stores the data. This optimizes the centralized storage encryption protection of unstructured data by using the "sector encryption" working mode of the storage encryption device. Thus, both structured and unstructured data are uniformly protected by a single centralized storage system, deploying a single storage encryption device or a data encryption storage cluster.

[0020] The advantages of this invention are: The design of this invention involves unified management, processing, and storage of unstructured data by a file application system, rather than users directly storing and encrypting file data. Technically, it transforms the centralized storage and encryption requirements for unstructured data into those for structured data, optimizing the design of centralized storage and encryption protection technology, saving costs, simplifying operations, and reducing energy consumption.

[0021] Although the present invention adds a file server and a file application system, it is much cheaper and simpler to operate than a centralized storage system and storage encryption device, and the overall energy consumption is reduced. Attached Figure Description

[0022] Figure 1 This is an architecture diagram of the system for centralized data storage encryption according to the present invention. Detailed Implementation

[0023] To make the objectives, contents, and advantages of the present invention clearer, the specific embodiments of the present invention will be described in further detail below with reference to the accompanying drawings and examples.

[0024] To address the aforementioned problems, this invention provides an optimized solution for centralized data storage encryption technology. This solution logically treats unstructured data as structured data, storing it on a file server. The file server then centrally encrypts and stores this data using a storage encryption device. Thus, the centralized storage encryption protection method for classified data logically eliminates the need to distinguish between structured and unstructured data. In terms of implementation, deploying a single storage encryption device or a data encryption storage cluster, mapping to a single storage system, allows for centralized encryption and storage of all classified data. This saves costs, simplifies operations, and reduces energy consumption.

[0025] To make the objectives, contents, and advantages of the present invention clearer, the specific implementation methods of the present invention will be further described in detail below with reference to the accompanying drawings.

[0026] like Figure 1 As shown, the specific solution of the present invention is as follows:

[0027] A centralized data storage encryption system includes: user groups 1-n, switches, service areas, storage switch 1, data encryption storage cluster, storage switch 2, and a centralized storage system.

[0028] User groups 1-n include: each user group represents a relatively concentrated group of users, such as the personnel of a certain department; and so on, there are a total of n user groups;

[0029] The business service area includes the following business systems: the file application system and other business application systems. The other business application systems are various application systems that provide services, including: application system 1 to application system K. Each business system is deployed on a server, and each business system may have more than one deployment server. For example, the file application system has L file servers. The file application system is used for unified management and processing of unstructured data.

[0030] A data encryption storage cluster includes: a single storage encryption device or a cluster consisting of M storage encryption devices;

[0031] A centralized storage system includes a set of disk arrays or a group of disk arrays that provide centralized storage services. The size and number of disk arrays depend on the amount and speed of data generated by the business system.

[0032] The connection relationship between the components is as follows: user groups 1-n access the switch, the switch connects to the server in the service area, the server in the service area connects to storage switch 1, storage switch 1 connects to the data encryption storage cluster, the data encryption storage cluster connects to storage switch 2, and storage switch 2 connects to the centralized storage system.

[0033] User groups 1-n access the file application system and other business application systems in the business service area through the switch. The file application system and other business application systems are collectively referred to as business systems. The data generated by the business systems is encrypted by the data encryption storage cluster through storage switch 1, and then the encrypted data is stored in the centralized storage system through storage switch 2, thereby realizing centralized storage encryption of data.

[0034] If user groups 1-n need to read encrypted data that has been saved in the centralized storage system, they access the business system through the switch. The business system then extracts the encrypted data from the centralized storage system through storage switch 1, the data encryption storage cluster, and storage switch 2. The encrypted data is decrypted as it passes through the data encryption storage cluster, and the plaintext data is returned to user groups 1-n through the business system, thus enabling data reading.

[0035] Typically, the classified data centrally stored by a user includes both structured and unstructured data. In this invention, the data encryption storage cluster that implements centralized storage and encryption protection of classified data adopts a "sector encryption" working mode. This means that the centralized storage system is divided into different storage spaces by sectors. Each storage space is mapped by the data encryption storage cluster to a server in a unique business system. This storage space only allows the mapped server to access and read / write data. Data encryption or decryption is achieved during the business system's data writing or reading process through the data encryption storage cluster. Simultaneously, the centralized storage system is configured to only allow access and data reading / writing by the business system, and user terminals cannot directly access the centralized storage system's security policy, thus achieving centralized storage and encryption security protection for classified data.

[0036] The deployment of a file application system enables unified management and centralized storage encryption protection of unstructured data. Centralized storage encryption of unstructured data can be achieved using the "sector encryption" working mode of the storage encryption device, eliminating the need for a "file encryption" working mode. Therefore, during the design phase, there is no need to differentiate between centralized storage encryption protection for structured and unstructured data; instead, a unified centralized storage system and storage encryption device can be designed. This allows a single centralized storage system, deploying one storage encryption device or a data encryption storage cluster, to centrally store and encrypt all confidential data.

[0037] The added file application system and file server for deployment in this invention result in a cost increase far less than the cost of a centralized storage system and storage encryption equipment, resulting in significant overall cost savings. In terms of management and maintenance, the file server in the file application system can utilize older servers or employ virtual machines. For operations and maintenance personnel, the management focus remains on the maintenance and management of servers and business systems, without adding complexity. Regarding energy consumption, the reduced equipment resources will lead to a corresponding decrease in energy consumption.

[0038] Key to this invention:

[0039] This invention targets unstructured data. Instead of directly encrypting the data through centralized storage, it manages, processes, and stores the data uniformly through a file application system. It optimizes the use of the "sector encryption" working mode of storage encryption devices for centralized storage encryption protection of unstructured data. This enables both structured and unstructured data to be uniformly protected by a single centralized storage system, deploying a storage encryption device or a data encryption storage cluster.

[0040] Effects of the invention:

[0041] The design of this invention involves unified management, processing, and storage of unstructured data by a file application system, rather than users directly storing and encrypting their file data. Technically, it transforms the centralized storage and encryption requirements for unstructured data into those for structured data, optimizing the design of centralized storage and encryption protection technology, saving costs, simplifying operations, and reducing energy consumption.

[0042] Although the present invention adds a file server and a file application system, it is much cheaper and simpler to operate than a centralized storage system and storage encryption device, and the overall energy consumption is reduced.

[0043] The above description is only a preferred embodiment of the present invention. It should be noted that for those skilled in the art, several improvements and modifications can be made without departing from the technical principles of the present invention, and these improvements and modifications should also be considered within the scope of protection of the present invention.

Claims

1. A system for centralized encrypted data storage, characterized in that, The system includes: user groups 1-n, switches, service areas, storage switch 1, data encryption storage cluster, storage switch 2, and a centralized storage system; User groups 1-n include: each user group represents a relatively concentrated group of users; The business service area includes the following business systems: a file application system and other business application systems. The other business application systems are various application systems that provide services, including application system 1 to application system K. Each business system is deployed on a server, wherein the file application system is used for unified management and processing of unstructured data. A data encryption storage cluster includes: a single storage encryption device or a cluster consisting of M storage encryption devices; A centralized storage system includes: a set of disk arrays or a group of disk arrays that provide centralized storage services; The connection relationship between the components is as follows: user groups 1-n access the switch, the switch connects to the server in the service area, the server in the service area connects to storage switch 1, storage switch 1 connects to the data encryption storage cluster, the data encryption storage cluster connects to storage switch 2, and storage switch 2 connects to the centralized storage system. in, User groups 1-n access the file application system and other business application systems in the business service area through the switch. The file application system and other business application systems are collectively referred to as business systems. The data generated by the business systems is encrypted by the data encryption storage cluster through storage switch 1, and then the encrypted data is stored in the centralized storage system through storage switch 2, thereby realizing centralized storage encryption of data. If user groups 1-n need to read encrypted data that has been saved in the centralized storage system, they access the business system through the switch. The business system then extracts the encrypted data from the centralized storage system through storage switch 1, the data encryption storage cluster, and storage switch 2. The encrypted data is decrypted as it passes through the data encryption storage cluster, and the plaintext data is returned to user groups 1-n through the business system, thus enabling data reading. The data encryption storage cluster that achieves centralized storage and encryption protection of classified data adopts the "sector encryption" working mode, that is, the centralized storage system is divided into different storage spaces by sectors. Each storage space is mapped by the data encryption storage cluster to a server in a unique business system. This storage space only allows the mapped server to access and read / write data. Data encryption or decryption is achieved during the process of the business system writing or reading business data through the data encryption storage cluster. The centralized storage encryption of unstructured data is also implemented using the "sector encryption" working mode of the storage encryption device.

2. The data central storage encryption system as described in claim 1, characterized in that, The user group consists of people from a certain department.

3. The data central storage encryption system as described in claim 1, characterized in that, Each business system may have more than one deployment server; for example, the file application system has L file servers.

4. The data central storage encryption system as described in claim 1, characterized in that, The size and number of disk arrays depend on the amount and speed of data generated by the business system.

5. The data central storage encryption system as described in claim 1, characterized in that, The centralized storage system is configured to allow only business systems to access and read / write data, while user terminals cannot directly access the centralized storage system's security policy, thereby achieving centralized and encrypted security protection for confidential data.

6. The system for centralized data storage encryption as described in claim 1, characterized in that, In file application systems, file servers may utilize older servers or virtual machines. For operations and maintenance personnel, the management objects remain the maintenance and management of servers and business systems.

Citation Information

Patent Citations

  • Special memory system for business data

    CN105224889A

  • Data file fragment encryption type uplink method

    CN114117504A