Method, device and equipment for transforming encrypted data and storage medium

CN117592068BActive Publication Date: 2026-09-29JINAN INSPUR DATA TECH CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202311541174.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-11-17
Publication Date
2026-09-29
Estimated Expiration
2043-11-17

AI Technical Summary

Technical Problem

[0003]有鉴于此,本发明提供了一种加密数据转化方法、装置、设备及存储介质,以解决现有块存储只能提供加密功能,并不能提供加密数据转化功能,从而导致云主机对从其他云主机迁移或者挂载过来的加密盘中的数据无法进行正常使用的问题

Benefits of technology

[0003]有鉴于此,本发明提供了一种加密数据转化方法、装置、设备及存储介质,以解决现有块存储只能提供加密功能,并不能提供加密数据转化功能,从而导致云主机对从其他云主机迁移或者挂载过来的加密盘中的数据无法进行正常使用的问题。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN117592068B_ABST
    Figure CN117592068B_ABST
Patent Text Reader

Abstract

The application relates to the technical field of data processing, and discloses an encrypted data conversion method, device, equipment and storage medium, which comprises the following steps: obtaining an encrypted data conversion request initiated by a target user, the encrypted data conversion request comprising an original storage type and a target storage type of an encrypted data disk, and the original storage type and the target storage type carrying encryption information; creating a non-encrypted data disk corresponding to the encrypted data disk based on the encrypted data conversion request and mounting the non-encrypted data disk on a host computer; mounting the encrypted data disk on the host computer in a decrypted mode, and copying storage data in the encrypted data disk to the non-encrypted data disk; formatting the encrypted data disk, and updating encryption information of the encrypted data disk based on the target storage type; and encrypting and writing the storage data in the non-encrypted data disk into the encrypted data disk based on the updated encryption information of the encrypted data disk, so as to perform encrypted data conversion on the storage data; and the application can guarantee the security and integrity of encrypted data conversion.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of data processing technology, and specifically to an encrypted data conversion method, apparatus, device, and storage medium. Background Technology

[0002] Encrypted block storage volumes are block storage services in cloud platforms that allow users to create, build, and manage block storage volumes and connect them to virtual machine instances. When creating a volume, users can choose to enable encryption options and specify an encryption key. Once an encrypted volume is created, all data written to the volume is encrypted and automatically decrypted upon reading. Due to the irreversible and unconvertible nature of encrypted information, encrypted data in an encrypted volume cannot be changed once determined. However, current block storage only provides encryption functionality and does not offer encryption algorithm conversion capabilities. In actual production processes, different security requirements between cloud hosts lead to different encryption algorithm requirements, which can cause the current cloud host to be unable to use data in encrypted disks migrated or mounted from other cloud hosts normally. Summary of the Invention

[0003] In view of this, the present invention provides an encrypted data conversion method, apparatus, device and storage medium to solve the problem that existing block storage can only provide encryption function but cannot provide encrypted data conversion function, which leads to the cloud host being unable to use the data in the encrypted disk migrated or mounted from other cloud hosts normally.

[0004] Firstly, this invention provides an encrypted data conversion method, comprising: obtaining an encrypted data conversion request initiated by a target user, the encrypted data conversion request including the original storage type and target storage type of an encrypted data disk, both of which carry encrypted information; creating an unencrypted data disk corresponding to the encrypted data disk based on the encrypted data conversion request, and mounting the unencrypted data disk to a host machine; decrypting and mounting the encrypted data disk to the host machine, and copying the stored data in the encrypted data disk to the unencrypted data disk; formatting the encrypted data disk, and updating the encrypted information of the encrypted data disk based on the target storage type; and encrypting and writing the stored data in the unencrypted data disk to the encrypted data disk based on the updated encrypted information of the encrypted data disk, thereby performing encrypted data conversion on the stored data. Through the above process, cloud hosts can normally use data in encrypted disks migrated or mounted from other cloud hosts, while ensuring the security and integrity of the encrypted information conversion of the stored data in the encrypted data disk.

[0005] In some optional implementations, an unencrypted data disk corresponding to the encrypted data disk is created based on the encrypted data conversion request, and the unencrypted data disk is mounted on the host machine, including:

[0006] Retrieve the attribute information of the encrypted data disk;

[0007] Based on the attribute information of the encrypted data disk, create an unencrypted data disk and a data disk mount point with the same attribute information as the encrypted data disk;

[0008] Mount the unencrypted data disk to the host machine via the data disk mount point.

[0009] In some alternative implementations, the encrypted data disk is decrypted and mounted to the host machine, and the stored data in the encrypted data disk is copied to the unencrypted data disk, including:

[0010] Create the first decryption mount point;

[0011] The encrypted data disk is mounted to the host machine through the first decryption mount point;

[0012] Retrieve the stored data from the encrypted data disk, and decrypt the stored data based on the first decryption mount point before copying it to the unencrypted data disk.

[0013] In some optional implementations, the encrypted data disk is formatted, and the encryption information of the encrypted data disk is updated based on the target storage type, including:

[0014] Close the first decryption mount point and format the encrypted data disk to erase the stored and encrypted data on the encrypted data disk;

[0015] Update the encryption information of the encrypted data disk based on the encryption information carried in the target storage type.

[0016] In some optional implementations, based on the encrypted information updated by the encrypted data disk, the stored data in the unencrypted data disk is encrypted and written to the encrypted data disk, including:

[0017] Create a second decryption mount point;

[0018] The encrypted data disk is mounted to the host machine via the second decryption mount point;

[0019] Retrieve the stored data from the unencrypted data disk, encrypt the stored data based on the second decryption mount point, and then copy it to the encrypted data disk.

[0020] In some alternative implementations, the method further includes:

[0021] Based on the encryption information of the encrypted data disk, an encrypted version file of the data disk is generated. The encrypted version file of the data disk includes the first identifier and original storage type of the encrypted data disk, as well as the second identifier, name and target storage type of the corresponding unencrypted data disk.

[0022] The encrypted version files on the data disk are stored in the version database.

[0023] In some optional implementations, before creating an unencrypted data disk corresponding to the encrypted data disk based on the encrypted data conversion request, the following steps are included:

[0024] Retrieve the encrypted information carried in the target storage type;

[0025] When the encrypted information is empty, the request to convert the encrypted data is intercepted;

[0026] When the encrypted information is not empty, the original storage type and the target storage type are compared to obtain the type comparison result;

[0027] When the type comparison result indicates that the original storage type is the same as the target storage type, the encrypted data conversion request is intercepted;

[0028] When the type comparison result indicates that the original storage type and the target storage type are different, the storage backend of the original storage type and the storage backend of the target storage type are compared to obtain the backend comparison result;

[0029] When the backend comparison results indicate that the storage backend of the original storage type is different from the storage backend of the target storage type, the encrypted data conversion request is intercepted.

[0030] When the backend comparison result indicates that the storage backend of the original storage type is the same as the storage backend of the target storage type, the step of creating an unencrypted data disk corresponding to the encrypted data disk based on the encrypted data conversion request is executed.

[0031] Secondly, the present invention provides an encrypted data conversion device, which mainly includes: a request acquisition module, a data disk creation module, a data copy module, a data writing module, and an encrypted data conversion module; wherein, the request acquisition module is used to acquire an encrypted data conversion request initiated by a target user, the encrypted data conversion request including the original storage type and the target storage type of the encrypted data disk, the original storage type and the target storage type carrying encrypted information; the data disk creation module is used to create an unencrypted data disk corresponding to the encrypted data disk based on the encrypted data conversion request, and mount the unencrypted data disk to the host machine; the data copy module is used to decrypt the encrypted data disk and mount it to the host machine, and copy the stored data in the encrypted data disk to the unencrypted data disk; the information update module is used to format the encrypted data disk and update the encrypted information of the encrypted data disk based on the target storage type; the data writing module is used to encrypt and write the stored data in the unencrypted data disk to the encrypted data disk based on the updated encrypted information of the encrypted data disk, and delete the unencrypted data disk. Through the above process, cloud servers can use the data in the encrypted disks migrated or mounted from other cloud servers normally, and the security and integrity of the data stored in the encrypted data disks during the encryption information conversion are guaranteed.

[0032] Thirdly, the present invention provides a computer device, comprising: a memory and a processor, wherein the memory and the processor are communicatively connected to each other, the memory stores computer instructions, and the processor executes the computer instructions to perform the encrypted data conversion method of the first aspect or any corresponding embodiment described above.

[0033] Fourthly, the present invention provides a computer-readable storage medium storing computer instructions for causing a computer to execute the encrypted data conversion method of the first aspect or any corresponding embodiment thereof. Attached Figure Description

[0034] To more clearly illustrate the specific embodiments of the present invention or the technical solutions in the prior art, the drawings used in the description of the specific embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of the present invention. For those skilled in the art, other drawings can be obtained from these drawings without creative effort.

[0035] Figure 1 This is a schematic diagram of an application environment according to an embodiment of the present invention;

[0036] Figure 2 This is a flowchart illustrating the encrypted data conversion method according to an embodiment of the present invention;

[0037] Figure 3 This is a flowchart illustrating another encrypted data conversion method according to an embodiment of the present invention;

[0038] Figure 4 This is a flowchart illustrating another encrypted data conversion method according to an embodiment of the present invention;

[0039] Figure 5 This is a flowchart illustrating another encrypted data conversion method according to an embodiment of the present invention;

[0040] Figure 6 This is a data flow diagram of the encrypted data conversion method according to an embodiment of the present invention;

[0041] Figure 7 This is a structural block diagram of the encrypted data conversion device according to an embodiment of the present invention;

[0042] Figure 8 This is a schematic diagram of the hardware structure of a computer device according to an embodiment of the present invention. Detailed Implementation

[0043] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0044] The terms "first" and "second" in the specification, claims, and accompanying drawings of this invention are used to distinguish different objects, not to describe a specific order. Furthermore, the term "comprising" and any variations thereof are intended to cover non-exclusive protection. For example, a process, method, system, product, or apparatus that includes a series of steps or units is not limited to the listed steps or units, but may optionally include steps or units not listed, or may optionally include other steps or units inherent to these processes, methods, products, or apparatuses. The term "multiple" in this invention can mean at least two, for example, two, three, or more, and the embodiments of this invention are not limited thereto.

[0045] Please see Figure 1 , Figure 1 This is a schematic diagram of an application environment provided by an embodiment of the present invention. The schematic diagram includes a terminal device 100, which may include a display 101, a processor 102, and a memory 103. The terminal device 100 can communicate with a server 200 via a network 300. Multiple cloud hosts run on the terminal device, and each cloud host is equipped with one or more encrypted data disks. The server 200 can be used to provide services (such as data conversion services) to the cloud hosts installed on the terminal device. A database 201 can be set up on or independently of the server 200 to provide data storage services to the server 200. In addition, the server 200 is provided with a processing engine 202, which can be used to execute the steps performed by the server 200.

[0046] Optionally, the terminal device 100 may be, but is not limited to, a terminal capable of computing data, such as a mobile terminal (e.g., a tablet computer), a laptop computer, or a PC (Personal Computer). The aforementioned network may include, but is not limited to, a wireless network or a wired network. The wireless network includes Bluetooth, Wi-Fi (Wireless Fidelity), and other networks that enable wireless communication. The aforementioned wired network may include, but is not limited to, a wide area network (WAN), a metropolitan area network (MAN), and a storage area network (SLAN). The aforementioned server 200 may include, but is not limited to, any hardware device capable of computing.

[0047] Furthermore, in this embodiment, the above-described encrypted data conversion method can also be applied to, but is not limited to, a powerful independent processing device without requiring data interaction. For example, the processing device can be, but is not limited to, a powerful terminal device; that is, the various operations in the above-described encrypted data conversion method can be integrated into a single independent processing device. The above is merely an example, and this embodiment does not impose any limitations on it.

[0048] Optionally, in this embodiment, the above-described encrypted data conversion method can be executed by the server 200, by the terminal device 100, or by both the server 200 and the terminal device 100. Alternatively, the terminal device 100 can execute the encrypted data conversion method of this embodiment by a client installed on it.

[0049] According to an embodiment of the present invention, an embodiment of an encrypted data conversion method is provided. It should be noted that the steps shown in the flowchart in the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions. Furthermore, although a logical order is shown in the flowchart, in some cases, the steps shown or described may be executed in a different order than that shown here.

[0050] This embodiment provides an encrypted data conversion method, which can be used in the aforementioned terminal device. Figure 2 This is a flowchart of an encrypted data conversion method according to an embodiment of the present invention, such as... Figure 2 As shown, the process includes the following steps:

[0051] Step S201: Obtain the encrypted data conversion request initiated by the target user. The encrypted data conversion request includes the original storage type and the target storage type of the encrypted data disk. The original storage type and the target storage type carry encrypted information.

[0052] As shown above, by obtaining the encrypted data conversion request initiated by the target user, the original storage type of the encrypted data disk can be converted to the target storage type based on the original storage type and target storage request in the encrypted data conversion request initiated by the target user. Since the original storage type and target storage type carry encrypted information, the conversion of the encryption type of the encrypted data disk and the conversion of the encryption type of the data stored in the encrypted data disk are realized.

[0053] The aforementioned encrypted data disk is a block storage encrypted disk, essentially a masked data disk with block storage services, using encryption technology to protect the data stored within the volume. Block storage is a block storage service running on a cloud management platform on a server or client side, allowing users to create, build, and manage block storage data disks and connect them to virtual machine instances. The block storage encrypted disk provides encryption protection for these data disks, ensuring that data is stored and protected through encryption procedures. When creating a data disk, users can choose to enable encryption options and specify an encryption key. The encryption key can be a user-provided key or a system-generated key. Once the block storage encrypted disk (encrypted data disk) is created, all data written to the block storage encrypted disk is encrypted and automatically decrypted upon reading.

[0054] In some optional implementations, when acquiring an encrypted data conversion request initiated by a target user, the encrypted information carried in the target storage type of the encrypted data conversion request can be obtained; when the encrypted information is empty, the encrypted data conversion request is intercepted, thereby intercepting invalid encrypted data conversion requests and improving the reliability and efficiency of encrypted data conversion; when the encrypted information is not empty, the original storage type and the target storage type are compared to obtain a type comparison result; when the type comparison result indicates that the original storage type and the target storage type are the same, the encrypted data conversion request is intercepted, thereby further intercepting invalid encrypted data conversion requests and improving the reliability and efficiency of encrypted data conversion. The system ensures high reliability and efficiency in encrypted data conversion. When the type comparison result indicates that the original storage type and the target storage type are different, the system compares the backends of both the original and target storage types to obtain the backend comparison result. If the backend comparison result indicates that the backends of the original and target storage types are different, the encrypted data conversion request is intercepted to prevent reduced conversion efficiency of subsequent encrypted data due to current conversion failure. If the backend comparison result indicates that the backends of the original and target storage types are the same, the encrypted data conversion request initiated by the target user is obtained. The encrypted information carried in the original and target storage types includes the provider, control location, encryption algorithm, key level, and data disk attributes. Encryption algorithms include AES (Advanced Encryption Standard) and RSA (Rivest-Shamir-Adleman) algorithms. The storage backend is equipped with encryption keys to provide additional data security for the stored data.

[0055] Furthermore, in the process of comparing the original storage type and the target storage type to obtain the type comparison result, the number of encrypted information characters carried in the original storage type can be compared with the number of encrypted information characters carried in the target storage type. When the number of encrypted information characters carried in the original storage type is different from the number of encrypted information characters carried in the target storage type, it indicates that the original storage type and the target storage type are different; when the number of encrypted information characters carried in the original storage type is the same as the number of encrypted information characters carried in the target storage type, the encrypted information characters carried in the original storage type are retrieved. The character values ​​of each character in the encrypted information carried in the original storage type are compared with the character values ​​of each character in the encrypted information carried in the target storage type. When the character values ​​of each character in the encrypted information carried in the original storage type are the same as those in the encrypted information carried in the target storage type, it indicates that the original storage type and the target storage type are the same. When the character values ​​of each character in the encrypted information carried in the original storage type are different from those in the encrypted information carried in the target storage type, it indicates that the original storage type and the target storage type are different.

[0056] By verifying the original storage type and the target storage type, it is determined whether the target storage type carries encrypted information and whether the encrypted information is consistent with the original encrypted information and whether the backend storage of the two is consistent. If they are inconsistent, the encrypted data conversion is not allowed, thereby improving the reliability and efficiency of encrypted data conversion.

[0057] Step S202: Create an unencrypted data disk corresponding to the encrypted data disk based on the encrypted data conversion request, and mount the unencrypted data disk to the host machine.

[0058] As shown above, an unencrypted data disk corresponding to the encrypted data disk is created based on the encrypted data conversion request, and the unencrypted data disk is mounted on the host machine so that the stored data in the encrypted data disk can be temporarily stored in the unencrypted data disk.

[0059] In some optional implementations, the attribute information of the encrypted data disk can be obtained first; based on the attribute information of the encrypted data disk, an unencrypted data disk with the same attribute information and a data disk mount point are created; the unencrypted data disk is mounted to the host machine through the data disk mount point. By creating an unencrypted data disk with the same attribute information as the encrypted data disk, the consistency of the attributes and data structure between the unencrypted and encrypted data disks is maintained, providing the necessary conditions for the complete copying of the data stored in the encrypted data disk. The creation of the data disk mount point facilitates the mounting of the unencrypted data disk to the host machine, thereby copying the stored data from the encrypted data disk to the unencrypted data disk. In this embodiment, the host machine is the aforementioned terminal device; in other embodiments, it can also be a server.

[0060] Step S203: Decrypt and mount the encrypted data disk to the host machine, and copy the stored data in the encrypted data disk to the unencrypted data disk.

[0061] As shown above, by decrypting and mounting the encrypted data disk to the host machine, the stored data in the encrypted data disk can be decrypted and copied to the unencrypted data disk, providing the necessary conditions for subsequent encryption type conversion of encrypted data.

[0062] In some optional implementations, the encrypted data disk can be mounted to the host machine via a decryption mount point, and the stored data in the encrypted data disk can be decrypted and copied to the unencrypted data disk using the decryption mount point. Since the unencrypted and encrypted data disks have the same attributes, copying stored data from the unencrypted data disk to the encrypted data disk can greatly improve the efficiency and integrity of the data copy. This avoids the need to readjust the data storage structure due to differences in attributes between the encrypted and unencrypted data disks, and also avoids data copy failures caused by differences in attributes between the encrypted and unencrypted data disks.

[0063] Step S204: Format the encrypted data disk and update the encryption information of the encrypted data disk based on the target storage type.

[0064] As described above, formatting the encrypted data disk clears the stored data and encrypted data in the encrypted data disk, avoiding the situation where the encryption information update of the encrypted data disk fails due to incomplete data clearing. It also avoids the situation where data copying back from the unencrypted data disk fails due to incomplete data clearing in the encrypted data disk. By updating the encryption information of the encrypted data disk based on the target storage type, the encryption type of the encrypted data disk can be converted.

[0065] In some alternative implementations, the decryption mount point can be closed first, and the encrypted data disk can be formatted to erase the stored data and encrypted data on the encrypted data disk; then, the encryption information of the encrypted data disk can be updated based on the encryption information carried in the target storage type. If a copying failure occurs during the complete copying of stored data from the encrypted data disk to the unencrypted data disk, the unencrypted data disk needs to be destroyed to ensure the security of the stored data.

[0066] Step S205: Based on the encrypted information updated by the encrypted data disk, the stored data in the unencrypted data disk is encrypted and written to the encrypted data disk to perform encrypted data conversion on the stored data.

[0067] As shown above, by using encrypted information updated based on the encrypted data disk, the stored data in the unencrypted data disk is encrypted and written to the encrypted data disk, thereby realizing the encryption conversion of the stored data, eliminating the conversion differences between different encryption algorithms, and avoiding the need to use a dedicated algorithm conversion tool for each encryption algorithm.

[0068] In some alternative implementations, a new decryption mount point can be created first, and then the encrypted data disk can be mounted to the host machine through the new decryption mount point. This allows the host machine to copy the stored data, which is encrypted from the unencrypted data disk and uploaded through the new decryption mount point, to the encrypted data disk for data encryption conversion. When the data in the unencrypted data disk is completely copied back to the encrypted data disk, the data in the unencrypted data disk is cleared and the unencrypted data disk is deleted.

[0069] The encrypted data conversion method provided in this embodiment first obtains the encrypted data conversion request initiated by the target user. Based on the original storage type and target storage request in the request, the original storage type of the encrypted data disk is converted to the target storage type. Since both the original and target storage types carry encrypted information, this achieves the conversion of the encryption type of the encrypted data disk and the encryption type of the data stored on it. Next, an unencrypted data disk corresponding to the encrypted data disk is created based on the encrypted data conversion request, and this unencrypted data disk is mounted on the host machine to temporarily store the data stored on the encrypted data disk in the unencrypted data disk. Finally, the encrypted data disk is decrypted and mounted on the host machine to facilitate the conversion of the encrypted data into encrypted data. After decryption, the stored data in the data disk is copied to the unencrypted data disk, providing the necessary conditions for subsequent encryption type conversion of encrypted data. Formatting the encrypted data disk clears both the stored and encrypted data, preventing encryption information update failures due to incomplete data erasure and data copying failures from the unencrypted data disk. The encryption type of the encrypted data disk is converted by updating its encryption information based on the target storage type. Based on the updated encryption information, the stored data in the unencrypted data disk is encrypted and written to the encrypted data disk, thus achieving encryption conversion of the stored data. Therefore, this invention allows cloud hosts to use data from encrypted disks migrated or mounted from other cloud hosts normally, while ensuring the security and integrity of encryption information conversion of the stored data in the encrypted data disk.

[0070] This embodiment provides an encrypted data conversion method, which can be used in the aforementioned terminal device. Figure 3 This is a flowchart of an encrypted data conversion method according to an embodiment of the present invention, such as... Figure 3 As shown, the process includes the following steps:

[0071] Step S301: Obtain the encrypted data conversion request initiated by the target user. The encrypted data conversion request includes the original storage type and the target storage type of the encrypted data disk. The original storage type and the target storage type carry encrypted information.

[0072] Please see details Figure 2 Step S201 of the illustrated embodiment will not be described again here.

[0073] Step S302: Create an unencrypted data disk corresponding to the encrypted data disk based on the encrypted data conversion request, and mount the unencrypted data disk to the host machine.

[0074] Step S303: Decrypt and mount the encrypted data disk to the host machine, and copy the stored data in the encrypted data disk to the unencrypted data disk.

[0075] Specifically, step S303 above includes:

[0076] Step S3031: Create the first decryption mount point.

[0077] As shown above, by creating the first decryption mount point, a connection between the encrypted data disk and the host machine can be established based on the first decryption mount point, providing the necessary conditions for the subsequent decryption and transmission of data stored in the encrypted data disk.

[0078] Step S3032: Mount the encrypted data disk to the host machine through the first decryption mount point.

[0079] As shown above, the encrypted data disk is mounted to the host machine through the first decryption mount point, thereby realizing data communication between the encrypted data disk and the host machine.

[0080] Step S3033: Obtain the stored data in the encrypted data disk, and copy the decrypted data to the unencrypted data disk based on the first decryption mount point.

[0081] As shown above, by obtaining the stored data in the encrypted data disk and decrypting the stored data based on the first decryption mount point, the data is copied to the unencrypted data disk, providing the necessary conditions for the subsequent encryption type conversion of the encrypted data.

[0082] In some optional implementations, the encrypted data disk can be mounted to the host machine via a decryption mount point, and the stored data in the encrypted data disk can be decrypted and copied to the unencrypted data disk using the decryption mount point. Since the unencrypted and encrypted data disks have the same attributes, copying stored data from the unencrypted data disk to the encrypted data disk can greatly improve the efficiency and integrity of the data copy. This avoids the need to readjust the data storage structure due to differences in attributes between the encrypted and unencrypted data disks, and also avoids data copy failures caused by differences in attributes between the encrypted and unencrypted data disks.

[0083] Step S304: Format the encrypted data disk and update the encryption information of the encrypted data disk based on the target storage type.

[0084] In some optional implementations, the first decryption mount point can be closed first, and the encrypted data disk can be formatted to clear the stored data and encrypted data in the encrypted data disk. This avoids the situation where the encryption information update of the encrypted data disk fails due to incomplete clearing of related data in the encrypted data disk, and also avoids the situation where the data copying back from the unencrypted data disk fails due to incomplete clearing of the stored data in the encrypted data disk. Then, the encryption information of the encrypted data disk is updated based on the encryption information carried in the target storage type, thereby realizing the conversion of the encryption type of the encrypted data disk.

[0085] Please see details Figure 2 Step S204 of the illustrated embodiment will not be described again here.

[0086] Step S305: Based on the encrypted information updated by the encrypted data disk, the stored data in the unencrypted data disk is encrypted and written to the encrypted data disk to perform encrypted data conversion on the stored data.

[0087] Please see details Figure 2 Step S205 of the illustrated embodiment will not be described again here.

[0088] The encrypted data conversion method provided in this embodiment first obtains the encrypted data conversion request initiated by the target user. Based on the original storage type and target storage request in the request, the original storage type of the encrypted data disk is converted to the target storage type. Since both the original and target storage types carry encrypted information, this achieves the conversion of the encryption type of the encrypted data disk and the encryption type of the data stored on it. Next, an unencrypted data disk corresponding to the encrypted data disk is created based on the encrypted data conversion request, and this unencrypted data disk is mounted on the host machine to temporarily store the data stored on the encrypted data disk in the unencrypted data disk. Finally, the encrypted data disk is decrypted and mounted on the host machine to facilitate the conversion of the encrypted data into encrypted data. After decryption, the stored data in the data disk is copied to the unencrypted data disk, providing the necessary conditions for subsequent encryption type conversion of encrypted data. Formatting the encrypted data disk clears both the stored and encrypted data, preventing encryption information update failures due to incomplete data erasure and data copying failures from the unencrypted data disk. The encryption type of the encrypted data disk is converted by updating its encryption information based on the target storage type. Based on the updated encryption information, the stored data in the unencrypted data disk is encrypted and written to the encrypted data disk, thus achieving encryption conversion of the stored data. Therefore, this invention allows cloud hosts to use data from encrypted disks migrated or mounted from other cloud hosts normally, while ensuring the security and integrity of encryption information conversion of the stored data in the encrypted data disk.

[0089] This embodiment provides an encrypted data conversion method, which can be used in the aforementioned terminal device. Figure 4 This is a flowchart of an encrypted data conversion method according to an embodiment of the present invention, such as... Figure 4 As shown, the process includes the following steps:

[0090] Step S401: Obtain the encrypted data conversion request initiated by the target user. The encrypted data conversion request includes the original storage type and the target storage type of the encrypted data disk. The original storage type and the target storage type carry encrypted information.

[0091] Please see details Figure 2 Step S201 of the illustrated embodiment will not be described again here.

[0092] Step S402: Create an unencrypted data disk corresponding to the encrypted data disk based on the encrypted data conversion request, and mount the unencrypted data disk to the host machine.

[0093] Please see details Figure 2Step S202 of the illustrated embodiment will not be described again here.

[0094] Step S403: Decrypt and mount the encrypted data disk to the host machine, and copy the stored data in the encrypted data disk to the unencrypted data disk.

[0095] Please see details Figure 3 Step S303 of the illustrated embodiment will not be described again here.

[0096] Step S404: Format the encrypted data disk and update the encryption information of the encrypted data disk based on the target storage type.

[0097] Step S405: Based on the encrypted information updated by the encrypted data disk, the stored data in the unencrypted data disk is encrypted and written to the encrypted data disk to perform encrypted data conversion on the stored data.

[0098] Specifically, step S405 includes:

[0099] Step S4051: Create a second decryption mount point.

[0100] As shown above, by creating a second decryption mount point, a connection between the encrypted data disk and the host machine can be established based on the second decryption mount point, providing the necessary conditions for the subsequent decryption and transmission of data stored in the encrypted data disk.

[0101] Step S4052: Mount the encrypted data disk to the host machine through the second decryption mount point.

[0102] As shown above, the encrypted data disk is mounted to the host machine through the second decryption mount point, thereby realizing data communication between the encrypted data disk and the host machine.

[0103] Step S4053: Obtain the stored data in the unencrypted data disk, and encrypt the stored data based on the second decryption mount point before copying it to the encrypted data disk.

[0104] By acquiring the stored data from the unencrypted data disk and encrypting the stored data based on the second decryption mount point, the data is copied to the encrypted data disk, thereby achieving the encryption conversion of the stored data.

[0105] The encrypted data conversion method provided in this embodiment first obtains the encrypted data conversion request initiated by the target user. Based on the original storage type and target storage request in the request, the original storage type of the encrypted data disk is converted to the target storage type. Since both the original and target storage types carry encrypted information, this achieves the conversion of the encryption type of the encrypted data disk and the encryption type of the data stored on it. Next, an unencrypted data disk corresponding to the encrypted data disk is created based on the encrypted data conversion request, and this unencrypted data disk is mounted on the host machine to temporarily store the data stored on the encrypted data disk in the unencrypted data disk. Finally, the encrypted data disk is decrypted and mounted on the host machine to facilitate the conversion of the encrypted data into encrypted data. After decryption, the stored data in the data disk is copied to the unencrypted data disk, providing the necessary conditions for subsequent encryption type conversion of encrypted data. Formatting the encrypted data disk clears both the stored and encrypted data, preventing encryption information update failures due to incomplete data erasure and data copying failures from the unencrypted data disk. The encryption type of the encrypted data disk is converted by updating its encryption information based on the target storage type. Based on the updated encryption information, the stored data in the unencrypted data disk is encrypted and written to the encrypted data disk, thus achieving encryption conversion of the stored data. Therefore, this invention allows cloud hosts to use data from encrypted disks migrated or mounted from other cloud hosts normally, while ensuring the security and integrity of encryption information conversion of the stored data in the encrypted data disk.

[0106] This embodiment provides an encrypted data conversion method, which can be used in the aforementioned terminal device. Figure 5 This is a flowchart of an encrypted data conversion method according to an embodiment of the present invention, such as... Figure 5 As shown, the process includes the following steps:

[0107] Step S501: Obtain the encrypted data conversion request initiated by the target user. The encrypted data conversion request includes the original storage type and the target storage type of the encrypted data disk. The original storage type and the target storage type carry encrypted information.

[0108] Please see details Figure 2 Step S201 of the illustrated embodiment will not be described again here.

[0109] Step S502: Create an unencrypted data disk corresponding to the encrypted data disk based on the encrypted data conversion request, and mount the unencrypted data disk to the host machine.

[0110] Please see details Figure 2Step S202 of the illustrated embodiment will not be described again here.

[0111] Step S503: Decrypt and mount the encrypted data disk to the host machine, and copy the stored data in the encrypted data disk to the unencrypted data disk.

[0112] Please see details Figure 3 Step S303 of the illustrated embodiment will not be described again here.

[0113] Step S504: Based on the encryption information of the encrypted data disk, generate an encrypted version file of the data disk. The encrypted version file of the data disk includes the first identifier and original storage type of the encrypted data disk, as well as the second identifier, name and target storage type of the corresponding unencrypted data disk.

[0114] As shown above, an encrypted version file of the data disk is generated based on the encrypted information of the encrypted data disk, so that the encrypted information can be traced back based on the encrypted version file.

[0115] In some alternative implementations, an encrypted version file of the data disk can be generated based on the first identifier and original storage type of the encrypted data disk, and the second identifier, name and target storage type of the corresponding unencrypted data disk.

[0116] Step S505: Store the encrypted version file from the data disk into the version database.

[0117] As shown above, the encrypted version files of the data disk are stored in a version database, which can be a separate database relation table used to store historical versions of the encrypted data disk.

[0118] In some optional implementations, the aforementioned database table (volume_encryption_history) includes the following fields:

[0119] Old_type_id Varchar(255) Original encrypted storage type of the original hard drive New_type_id Varchar(255) New encrypted storage type Tmp_volume_id Varchar(255) temporary data disk Tmp_volume_name Varchar(255) temporary data disk Id Varchar(255) ID Create_time Date Creation time

[0120] As described above, by storing the historical encryption information (i.e., encryption versions) of the encrypted data disk separately, each encryption version records historical encryption information. Based on this information, it is possible to query, delete, and switch the historical encryption information of the encrypted data disk. This protects the integrity of data under different encryption algorithms, enabling the encrypted data disk to adapt to different encryption algorithms and scenarios, and providing a certain level of data security. Furthermore, since the algorithm transformation is independent of the cloud server, the cloud server is unaware of the entire process.

[0121] The encrypted data conversion method provided in this embodiment first obtains the encrypted data conversion request initiated by the target user. Based on the original storage type and target storage request in the encrypted data conversion request, the original storage type of the encrypted data disk is converted to the target storage type. Since the original storage type and target storage type carry encrypted information, the conversion of the encryption type of the encrypted data disk and the encryption type of the data stored in the encrypted data disk is realized. Next, an unencrypted data disk corresponding to the encrypted data disk is created based on the encrypted data conversion request and mounted on the host machine to temporarily store the data stored in the encrypted data disk in the unencrypted data disk. Then, the encrypted data disk is decrypted and mounted on the host machine to decrypt the data stored in the encrypted data disk and copy it to the unencrypted data disk, providing the necessary conditions for subsequent encryption type conversion of encrypted data. Based on the encryption information of the encrypted data disk, an encrypted version file of the data disk is generated to facilitate the backtracking of encrypted information. Finally, the encrypted version file of the data disk is stored in a version database, which can be a separate database relation table used to store historical versions of the encrypted data disk. Therefore, this invention enables cloud hosts to use data in encrypted disks migrated or mounted from other cloud hosts normally, while ensuring the security and integrity of the encrypted information conversion of data stored in the encrypted data disk. It also enables the backtracking of encrypted information, avoiding the need to update the encrypted information again when repeatedly switching between the original storage type and the target storage type, thereby improving the efficiency of encrypted data conversion.

[0122] In some alternative implementations, the process of converting encrypted data between encrypted and unencrypted data disks, such as... Figure 6As shown, when a user logs into the first cloud host through the host machine and wants to migrate the encrypted data disk mounted on the first cloud host to the second cloud host, the encryption method and encryption level of the encrypted data stored in the encrypted data disk are different due to the different cloud operating environments of the first cloud host and the second cloud host. At this point, it is necessary to first know the target storage type corresponding to the encrypted data disk when it is mounted on the second cloud host. Then, the first cloud host generates an encrypted data conversion request based on the original storage type of the encrypted data disk mounted on itself and the target storage type corresponding to the second cloud host. Next, the cloud platform where the first cloud host is located determines whether the encrypted information carried in the target storage type is empty. When the encrypted information is empty, the encrypted data conversion request is intercepted. When the encrypted information is not empty, the original storage type and the target storage type are compared to obtain a type comparison result. When the type comparison result indicates that the original storage type and the target storage type are the same, it means that the encrypted information is duplicated, and the encrypted data conversion request is intercepted. When the type comparison result indicates that the original storage type and the target storage type are different, the storage backend of the original storage type and the storage backend of the target storage type are compared to obtain a backend comparison result. When the backend comparison result indicates that the storage backend of the original storage type and the storage backend of the target storage type are different, the encrypted data conversion request is intercepted.

[0123] When the backend comparison results indicate that the storage backend of the original storage type is the same as the storage backend of the target storage type, a request is made to the corresponding backend storage on the host machine to create an unencrypted data disk of the same size, as well as a data disk mount point. The unencrypted data disk is mounted to the host machine through the data disk mount point. Simultaneously, a first decryption mount point is created. The encrypted data disk is mounted to the host machine through the first decryption mount point. Then, the stored data in the encrypted data disk is retrieved, and the stored data is decrypted based on the first decryption mount point and copied to the unencrypted data disk. The first decryption mount point is closed, and the encrypted data disk is formatted to clear the stored data and encrypted data in the encrypted data disk. The encryption information of the encrypted data disk is updated based on the encryption information carried in the target storage type. After updating the encryption information of the encrypted data disk, a second decryption mount point is created. The encrypted data disk is mounted to the host machine through the second decryption mount point. The stored data in the unencrypted data disk is retrieved, and the stored data is encrypted based on the second decryption mount point and copied to the encrypted data disk. Then, the second decryption mount point is closed, and the unencrypted data disk is unmounted and deleted from the host machine. At the same time, the encrypted version files on the data disk are organized and stored in the version database.

[0124] This embodiment also provides an encrypted data conversion device for implementing the above embodiments and preferred embodiments; details already described will not be repeated. As used below, the term "module" can refer to a combination of software and / or hardware that performs a predetermined function. Although the device described in the following embodiments is preferably implemented in software, hardware implementation, or a combination of software and hardware, is also possible and contemplated.

[0125] This embodiment provides an encrypted data conversion device, such as... Figure 7 As shown, it includes:

[0126] The request acquisition module 701 is used to acquire the encrypted data conversion request initiated by the target user. The encrypted data conversion request includes the original storage type and the target storage type of the encrypted data disk. The original storage type and the target storage type carry encrypted information.

[0127] The data disk creation module 702 is used to create an unencrypted data disk corresponding to the encrypted data disk based on the encrypted data conversion request, and to mount the unencrypted data disk to the host machine.

[0128] The data copy module 703 is used to decrypt and mount the encrypted data disk to the host machine, and copy the stored data in the encrypted data disk to the unencrypted data disk.

[0129] The information update module 704 is used to format the encrypted data disk and update the encryption information of the encrypted data disk based on the target storage type.

[0130] The data writing module 705 is used to encrypt and write stored data in the unencrypted data disk to the encrypted data disk based on the encrypted information updated by the encrypted data disk, and then delete the unencrypted data disk.

[0131] In some optional implementations, the request acquisition module 701 is specifically used for:

[0132] Retrieve the encrypted information carried in the target storage type;

[0133] When the encrypted information is empty, the request to convert the encrypted data is intercepted;

[0134] When the encrypted information is not empty, the original storage type and the target storage type are compared to obtain the type comparison result;

[0135] When the type comparison result indicates that the original storage type is the same as the target storage type, the encrypted data conversion request is intercepted;

[0136] When the type comparison result indicates that the original storage type and the target storage type are different, the storage backend of the original storage type and the storage backend of the target storage type are compared to obtain the backend comparison result;

[0137] When the backend comparison results indicate that the storage backend of the original storage type is different from the storage backend of the target storage type, the encrypted data conversion request is intercepted.

[0138] When the backend comparison result indicates that the storage backend of the original storage type is the same as the storage backend of the target storage type, the step of creating an unencrypted data disk corresponding to the encrypted data disk based on the encrypted data conversion request is executed.

[0139] In some alternative implementations, the data disk creation module 702 includes:

[0140] The attribute acquisition unit is used to acquire attribute information of the encrypted data disk;

[0141] The data disk creation unit is used to create an unencrypted data disk and a data disk mount point with the same attribute information as the encrypted data disk, based on the attribute information of the encrypted data disk.

[0142] The data disk mounting unit is used to mount an unencrypted data disk to the host machine via a data disk mount point.

[0143] In some alternative implementations, the data copy module 703 includes:

[0144] Create the first decryption mount point;

[0145] The encrypted data disk is mounted to the host machine through the first decryption mount point;

[0146] Retrieve the stored data from the encrypted data disk, and decrypt the stored data based on the first decryption mount point before copying it to the unencrypted data disk.

[0147] In some alternative implementations, the information update module 704 includes:

[0148] Close the first decryption mount point and format the encrypted data disk to erase the stored and encrypted data on the encrypted data disk;

[0149] Update the encryption information of the encrypted data disk based on the encryption information carried in the target storage type.

[0150] In some alternative implementations, the data writing module 705 includes:

[0151] Create a second decryption mount point;

[0152] The encrypted data disk is mounted to the host machine via the second decryption mount point;

[0153] Retrieve the stored data from the unencrypted data disk, encrypt the stored data based on the second decryption mount point, and then copy it to the encrypted data disk.

[0154] In some alternative implementations, the data writing module 705 is also used for:

[0155] Based on the encryption information of the encrypted data disk, an encrypted version file of the data disk is generated. The encrypted version file of the data disk includes the first identifier and original storage type of the encrypted data disk, as well as the second identifier, name and target storage type of the corresponding unencrypted data disk.

[0156] The encrypted version files on the data disk are stored in the version database.

[0157] Further functional descriptions of the above modules and units are the same as those in the corresponding embodiments described above, and will not be repeated here.

[0158] In this embodiment, the encrypted data conversion device is presented in the form of a functional unit. Here, a unit refers to an ASIC (Application Specific Integrated Circuit) circuit, a processor and memory that execute one or more software or fixed programs, and / or other devices that can provide the above functions.

[0159] This invention also provides a computer device having the above-described features. Figure 7 The encrypted data conversion device shown.

[0160] Please see Figure 8 , Figure 8 This is a schematic diagram of the structure of a computer device provided in an optional embodiment of the present invention, such as... Figure 8 As shown, the computer device includes one or more processors 10, memory 20, and interfaces for connecting the components, including high-speed interfaces and low-speed interfaces. The components communicate with each other via different buses and can be mounted on a common motherboard or otherwise installed as needed. The processors can process instructions executed within the computer device, including instructions stored in or on memory to display graphical information of a GUI on external input / output devices (such as display devices coupled to the interfaces). In some alternative implementations, multiple processors and / or multiple buses can be used with multiple memories and multiple memory modules, if desired. Similarly, multiple computer devices can be connected, each providing some of the necessary operations (e.g., as a storage server array, a group of blade storage servers, or a multiprocessor system). Figure 8 Take a processor 10 as an example.

[0161] Processor 10 may be a central processing unit, a network processor, or a combination thereof. Processor 10 may further include a hardware chip. The hardware chip may be an application-specific integrated circuit (ASIC), a programmable logic device (PLD), or a combination thereof. The programmable logic device may be a complex programmable logic device (CAMP), a field-programmable gate array (FPGA), a general-purpose array logic (GDA), or any combination thereof.

[0162] The memory 20 stores instructions executable by at least one processor 10 to cause at least one processor 10 to perform the method shown in the above embodiments.

[0163] The memory 20 may include a program storage area and a data storage area. The program storage area may store the operating system and applications required for at least one function; the data storage area may store data created based on the use of the computer device as shown by a landing page for an app. Furthermore, the memory 20 may include high-speed random access memory and may also include non-transient memory, such as at least one disk storage device, flash memory device, or other non-transient solid-state storage device. In some alternative embodiments, the memory 20 may optionally include memory remotely located relative to the processor 10, which can be connected to the computer device via a network. Examples of such networks include, but are not limited to, the Internet, corporate intranets, server clusters, mobile communication networks, and combinations thereof.

[0164] The memory 20 may include volatile memory, such as random access memory; the memory may also include non-volatile memory, such as flash memory, hard disk or solid-state drive; the memory 20 may also include a combination of the above types of memory.

[0165] The computer device also includes a communication interface 30 for communicating with other devices or communication networks.

[0166] This invention also provides a computer-readable storage medium. The methods described above according to embodiments of the invention can be implemented in hardware or firmware, or implemented as computer code that can be recorded on a storage medium, or implemented as computer code downloaded via a network and originally stored on a remote storage medium or a non-transitory machine-readable storage medium and then stored on a local storage medium. Thus, the methods described herein can be processed by software stored on a storage medium using a general-purpose computer, a dedicated processor, or programmable or dedicated hardware. The storage medium can be a magnetic disk, optical disk, read-only memory, random access memory, flash memory, hard disk, or solid-state drive, etc.; further, the storage medium can also include combinations of the above types of memory. It is understood that computers, processors, microprocessor controllers, or programmable hardware include storage components capable of storing or receiving software or computer code, which, when accessed and executed by the computer, processor, or hardware, implements the methods shown in the above embodiments.

[0167] Although embodiments of the invention have been described in conjunction with the accompanying drawings, those skilled in the art can make various modifications and variations without departing from the spirit and scope of the invention, and such modifications and variations all fall within the scope defined by the appended claims.

Claims

1. A method for converting encrypted data, characterized in that, The method, applied to an encrypted data disk for block storage services, includes: Obtain the encrypted data conversion request initiated by the target user. The encrypted data conversion request includes the original storage type and the target storage type of the encrypted data disk. The original storage type and the target storage type carry encrypted information, which includes the provider, control location, encryption algorithm, key level, and data disk attributes. The system retrieves the encrypted information carried in the target storage type; when the encrypted information is empty, it intercepts the encrypted data conversion request; when the encrypted information is not empty, it compares the original storage type and the target storage type to obtain a type comparison result; when the type comparison result indicates that the original storage type and the target storage type are the same, it intercepts the encrypted data conversion request; when the type comparison result indicates that the original storage type and the target storage type are different, it compares the storage backend of the original storage type and the storage backend of the target storage type to obtain a backend comparison result; when the backend comparison result indicates that the storage backend of the original storage type and the storage backend of the target storage type are different, it intercepts the encrypted data conversion request; when the backend comparison result indicates that the storage backend of the original storage type and the storage backend of the target storage type are the same, it creates an unencrypted data disk corresponding to the encrypted data disk based on the encrypted data conversion request and mounts the unencrypted data disk to the host machine. The encrypted data disk is decrypted and mounted to the host machine, and the stored data in the encrypted data disk is copied to the unencrypted data disk; if the copying fails during the copying process, the unencrypted data disk is destroyed. Format the encrypted data disk and update the encryption information of the encrypted data disk based on the target storage type; Based on the encrypted information updated by the encrypted data disk, the stored data in the unencrypted data disk is encrypted and written to the encrypted data disk to perform encrypted data conversion on the stored data.

2. The method according to claim 1, characterized in that, The step of creating an unencrypted data disk corresponding to the encrypted data disk based on the encrypted data conversion request, and mounting the unencrypted data disk to the host machine, includes: Obtain the attribute information of the encrypted data disk; Based on the attribute information of the encrypted data disk, create an unencrypted data disk and a data disk mount point with the same attribute information as the encrypted data disk; The unencrypted data disk is mounted to the host machine through the data disk mount point.

3. The method according to claim 1, characterized in that, The step of decrypting and mounting the encrypted data disk to the host machine, and copying the stored data in the encrypted data disk to the unencrypted data disk includes: Create the first decryption mount point; The encrypted data disk is mounted to the host machine through the first decryption mount point; The stored data in the encrypted data disk is obtained, and the stored data is decrypted based on the first decryption mount point and then copied to the unencrypted data disk.

4. The method according to claim 3, characterized in that, The process of formatting the encrypted data disk and updating the encryption information of the encrypted data disk based on the target storage type includes: Close the first decryption mount point and format the encrypted data disk to clear the stored data and encrypted data in the encrypted data disk; The encryption information of the encrypted data disk is updated based on the encryption information carried in the target storage type.

5. The method according to claim 4, characterized in that, The step of encrypting and writing stored data from the unencrypted data disk to the encrypted data disk based on the encrypted information updated by the encrypted data disk includes: Create a second decryption mount point; The encrypted data disk is mounted to the host machine through the second decryption mount point; The stored data in the unencrypted data disk is obtained, and the stored data is encrypted and copied to the encrypted data disk based on the second decryption mount point.

6. The method according to any one of claims 1 to 5, characterized in that, The method further includes: Based on the encryption information of the encrypted data disk, an encrypted version file of the data disk is generated. The encrypted version file of the data disk includes the first identifier and original storage type of the encrypted data disk, as well as the second identifier, name and target storage type of the corresponding unencrypted data disk. The encrypted version file of the data disk is stored in the version database.

7. An encrypted data conversion device, characterized in that, The device includes: The request acquisition module is used to acquire the encrypted data conversion request initiated by the target user. The encrypted data conversion request includes the original storage type and the target storage type of the encrypted data disk. The original storage type and the target storage type carry encrypted information, which includes the provider, control location, encryption algorithm, key level and data disk attributes. A data disk creation module is used to obtain encrypted information carried in the target storage type; when the encrypted information is empty, the encrypted data conversion request is intercepted; when the encrypted information is not empty, the original storage type and the target storage type are compared to obtain a type comparison result; when the type comparison result indicates that the original storage type and the target storage type are the same, the encrypted data conversion request is intercepted; when the type comparison result indicates that the original storage type and the target storage type are different, the storage backend of the original storage type and the storage backend of the target storage type are compared to obtain a backend comparison result; when the backend comparison result indicates that the storage backend of the original storage type and the storage backend of the target storage type are different, the encrypted data conversion request is intercepted; when the backend comparison result indicates that the storage backend of the original storage type and the storage backend of the target storage type are the same, an unencrypted data disk corresponding to the encrypted data disk is created based on the encrypted data conversion request, and the unencrypted data disk is mounted on the host machine; The data copy module is used to decrypt and mount the encrypted data disk to the host machine, and to copy the stored data in the encrypted data disk to the unencrypted data disk. An information update module is used to format the encrypted data disk and update the encryption information of the encrypted data disk based on the target storage type; The data writing module is used to encrypt and write the stored data in the unencrypted data disk to the encrypted data disk based on the encrypted information updated by the encrypted data disk, and then delete the unencrypted data disk.

8. A computer device, characterized in that, include: A memory and a processor, the memory and the processor being communicatively connected to each other, the memory storing computer instructions, the processor executing the computer instructions to perform the method of any one of claims 1 to 6.

9. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer instructions for causing a computer to perform the method of any one of claims 1 to 6.

Citation Information

Patent Citations

  • Storage system, data migration method and management computer

    US20060182281A1