A data distributed secure storage system and method in computer science and technology

By designing a distributed secure storage system for data, including data storage, transmission, security monitoring, fault repair and dynamic optimization modules, the problem of low data security during distributed storage is solved, and efficient, secure and reliable data storage and transmission is achieved.

CN118474124BActive Publication Date: 2025-06-13TIANJIN XINDU TECH CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202410633784.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-05-21
Publication Date
2025-06-13
Estimated Expiration
2044-05-21

AI Technical Summary

Technical Problem

The prior art cannot guarantee the security of data during distributed storage, especially in cases of node failure and low confidentiality.

Method used

A distributed secure storage system for data is designed, including data storage module, data transmission module, security monitoring module, fault repair module and dynamic optimization module. The system ensures the security and reliability of the data by identifying faulty nodes in real time, performing security verification and backup, repairing and proofreading data, and optimizing transmission policies and capacity expansion according to faulty conditions.

Benefits of technology

Improve the security and reliability of distributed data storage, and ensure the integrity and security of data in a distributed storage environment through real-time fault identification and repair, security verification and backup.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118474124B_ABST
    Figure CN118474124B_ABST
Patent Text Reader

Abstract

The present invention relates to the technical field of data storage, and particularly to a data distributed secure storage system and method in computer science and technology, including a data storage module for storing node data; a data transmission module for processing node data, performing data transmission and security verification, and backing up the target transmission data that passes the security verification; a security monitoring module for real-time identification of faulty nodes; a fault repair module for repairing faulty nodes and also for repairing and proofreading the repaired faulty nodes; and a dynamic optimization module for judging the fault situation, optimizing the transmission strategy of edge nodes according to the fault situation, and also for judging the expansion situation of edge nodes according to the single-point fault times of edge nodes and adjusting the optimization result of the transmission strategy according to the judgment result. The present invention improves the security of data distributed storage.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of data storage, and in particular, to a data distributed secure storage system and method in computer science and technology. Background Art

[0002] Chinese Patent Publication No.: CN115190135A discloses a distributed storage system and its replica selection method, belonging to the technical field of distributed storage. An Actor network is set in each edge server to quickly calculate the score of each edge server, and a Critic network is deployed in the cloud to comprehensively consider the information of all Actor networks for joint action evaluation; and the Actor network is trained based on the evaluation results output by the corresponding Critic network, and the Critic network is trained based on the data randomly sampled from the experience pool; the training processes of the Actor network and the Critic network are independent of each other and continue, and by maintaining a server ranking among the servers and distributing it to the clients. However, this solution only solves the latency problem during data distributed storage and cannot guarantee the secure storage of data. Summary of the Invention

[0003] Therefore, the present invention provides a data distributed secure storage system and method in computer science and technology to overcome the problem of low security of data distributed storage caused by node failures and low confidentiality during distributed storage in the prior art.

[0004] To achieve the above object, on the one hand, the present invention provides a data distributed secure storage system in computer science and technology, including:

[0005] A data storage module for storing node data;

[0006] A data transmission module for processing node data to obtain target transmission data, performing data transmission according to a data transmission strategy, and also performing security verification according to a sending key and backing up the target transmission data that passes the security verification;

[0007] A security monitoring module for real-time identification of faulty nodes;

[0008] A fault repair module for repairing faulty nodes according to the faulty conditions of peer adjacent nodes and upper connected nodes, and also performing repair verification on the repaired faulty nodes;

[0009] A dynamic optimization module is used to judge the fault situation according to the number of faults of the peer adjacent nodes of the edge node, optimize the transmission strategy of the edge node according to the fault situation, and is also used to judge the expansion situation of the edge node according to the number of single-point faults of the edge node, and adjust the optimization result of the transmission strategy according to the judgment result.

[0010] Further, the data transmission module is provided with a data processing unit for processing node data to obtain target transmission data;

[0011] When processing the node data, the data processing unit obtains the data generation location address and data content in the node data, performs text comparison on the data generation location and data content of each node data through the command-line tool of the cmp command, and identifies duplicate data according to the comparison result, where:

[0012] When the data generation location address and data content of each node data are the same, the each node data is identified as duplicate data;

[0013] When the data generation location address and data content of each node data are different, the each node data is identified as non-duplicate data;

[0014] The data processing unit selects one node data from the duplicate data as the deduplicated data, and every other data processing cycle, integrates the deduplicated data and non-duplicate data generated in this data processing cycle into a data packet, compresses the data packet, and uses the data packet after data compression as the target transmission data.

[0015] Further, the data transmission module is provided with a data sending unit for performing data transmission according to the data transmission strategy;

[0016] The data sending unit sets the data transmission strategy according to the data transmission object of the edge node, where:

[0017] When the data transmission object of the edge node is a peer adjacent node, the data transmission strategy is set to Strategy A;

[0018] When the data transmission object of the edge node is a superior connection node, the data transmission strategy is set to Strategy B;

[0019] The data transmission module is provided with a security verification unit for performing security verification on the target transmission data according to the sending key;

[0020] The security verification unit obtains the sending key R, decrypts the sending key R according to the base point T and the verification key Y, and performs security verification on the target transmission data according to the decryption result, where:

[0021] When R = T × Y, the security verification unit determines that the decryption of the sending key is successful, and the target transmission data passes the security verification;

[0022] When R ≠ T × Y, the security verification unit determines that the decryption of the sending key fails, and the target transmission data fails to pass the security verification;

[0023] The data transmission module is provided with a node backup unit for backing up the target transmission data that has passed the security verification;

[0024] The node backup unit performs node identity marking on the target transmission data that has passed the security verification, obtains data in the format of edge node name label - target transmission data, and stores it as marked data in the backup database of the data transmission object of the edge node.

[0025] Further, the security monitoring module obtains the heartbeat signal time interval T of each edge node, compares the heartbeat signal time interval T of each edge node with the preset heartbeat signal time interval T0, and identifies the faulty node in real time according to the comparison result, where:

[0026] When T ≤ T0, the security monitoring module determines that the edge node is not a faulty node;

[0027] When T > T0, the security monitoring module determines that the edge node is a faulty node.

[0028] Further, the fault repair module repairs the faulty node according to the fault conditions of the adjacent nodes at the same level, where:

[0029] When there are no faults in the adjacent nodes at the same level, the fault repair module selects any adjacent node at the same level as the auxiliary repair node, obtains the target transmission data stored in the backup database of the auxiliary repair node that is consistent with the edge node name label of the faulty node, and stores it as repair data in the repair node;

[0030] When one of the adjacent nodes at the same level has a fault, the fault repair module uses the other adjacent node at the same level without a fault as the auxiliary repair node, obtains the target transmission data stored in the backup database of the auxiliary repair node that is consistent with the edge node name label of the faulty node, and stores it as repair data in the repair node;

[0031] When all adjacent nodes at the same level have faults, the fault repair module repairs the faulty node according to the fault conditions of the upper-level connection nodes, where:

[0032] When the upper - level connection node has no fault, the fault repair module takes the upper - level connection node as an auxiliary repair node, obtains the target transmission data stored in the backup database of the auxiliary repair node that is consistent with the edge - node name tag of the fault node, and stores it as repair data in the repair node;

[0033] When the upper - level connection node has a fault, the fault repair module takes the most adjacent upper - level node that has no fault and is one level higher than the upper - level connection node as an auxiliary repair node, obtains the target transmission data stored in the backup database of the auxiliary repair node that is consistent with the edge - node name tag of the fault node, and stores it as repair data in the repair node.

[0034] Further, the fault repair module performs repair verification on the repaired fault node according to the fault conditions of the peer - adjacent nodes, where:

[0035] When all peer - adjacent nodes have no fault, the fault repair module takes another peer - adjacent node except the auxiliary repair node as a repair verification node, and uses the target transmission data stored in the backup database of the repair verification node that is consistent with the edge - node name tag of the fault node as repair verification data to compare with the repair data, and judges the repair verification situation of the fault node according to the comparison result, where:

[0036] If the repair verification data is consistent with the repair data, the fault repair module determines that no repair verification is performed on the fault node;

[0037] If the repair verification data is inconsistent with the repair data, the fault repair module determines that repair verification is performed on the fault node, and supplements the data in the repair verification data that is inconsistent with the repair data as verification data to the repair data;

[0038] When all peer - adjacent nodes have faults, the fault repair module determines that no repair verification is performed on the fault node.

[0039] Further, the dynamic optimization module obtains the number of faults z of the peer - adjacent nodes of the edge node during the optimization period, compares the number of faults z of the peer - adjacent nodes of the edge node with the preset number of faults z0 of the peer - adjacent nodes of the preset edge node, judges the fault situation according to the comparison result, and optimizes the transmission strategy of the edge node according to the fault situation, where:

[0040] When z ≤ z0, the dynamic optimization module determines that the fault situation is normal;

[0041] When z > z0, the dynamic optimization module determines that the fault situation is abnormal, and optimizes the transmission strategy of the edge node, and optimizes the strategy A when the data transmission object of the edge node is a peer - adjacent node to strategy B.

[0042] Further, the dynamic optimization module obtains the number of single - point failures F of the edge nodes during the optimization period, compares the number of single - point failures F of the edge nodes with the preset number of single - point failures F0 of the edge nodes, determines the expansion situation of the edge nodes according to the comparison result, and adjusts the optimization result of the transmission strategy according to the determination result, where:

[0043] When F ≤ F0, the dynamic optimization module determines not to expand the edge nodes;

[0044] When F > F0, the dynamic optimization module determines to expand the edge nodes, and adjusts the result of optimizing policy A to policy B when the data transmission object of the edge node is a peer - adjacent node to policy A.

[0045] Further, the data distributed security storage device includes:

[0046] Each peer - adjacent node, which is composed of each edge node, is an edge node with an adjacent relationship. The first edge node and the third edge node are peer - adjacent nodes of the second edge node, and they are located in the Kth layer of the data distributed security storage device. The fourth edge node and the sixth edge node are peer - adjacent nodes of the fifth edge node, and they are located in the (K - 1)th layer of the data distributed security storage device. The seventh edge node is a peer - adjacent node of the eighth edge node, and it is located in the second layer of the data distributed security storage device;

[0047] Each upper - level connection node, which is composed of each edge node, is an edge node in the (K - 1)th layer of the edge nodes in the Kth layer. The fourth edge node is the upper - level connection node of the first edge node and the second edge node, and the root node is the upper - level connection node of the seventh edge node and the eighth edge node;

[0048] The root node, which is an edge node located at the center of the data distributed security storage device and is an edge node in the first layer;

[0049] Each data transmission channel, which is a data transmission channel connecting each edge node and is used for data transmission between edge nodes.

[0050] On the other hand, the present invention also provides a data distributed security storage method in computer science and technology, including:

[0051] Step S1, storing node data through the data storage module;

[0052] Step S2: Process the node data through the data transmission module to obtain the target transmission data, perform data transmission according to the data transmission strategy, and also perform security verification according to the sending key through the data transmission module, and back up the target transmission data that passes the security verification;

[0053] Step S3: Real-time identify the faulty nodes through the security monitoring module;

[0054] Step S4: Repair the faulty nodes through the fault repair module according to the fault conditions of the adjacent nodes at the same level and the fault conditions of the upper-level connected nodes, and conduct repair verification on the repaired faulty nodes;

[0055] Step S5: Judge the fault conditions according to the number of faults of the adjacent nodes at the same level of the edge nodes through the dynamic optimization module, and optimize the transmission strategy of the edge nodes according to the fault conditions. Also, judge the expansion situation of the edge nodes according to the number of single-point faults of the edge nodes through the dynamic optimization module, and adjust the optimization result of the transmission strategy according to the judgment result.

[0056] Compared with the prior art, the beneficial effects of the present invention are as follows. The system stores the node data through the data storage module to facilitate edge computing, realizes the integration of computing and storage, and improves the efficiency of cloud computing. The system processes the node data through the data transmission module to obtain the target transmission data, which is convenient for data transmission, thereby improving the data transmission efficiency during data distributed storage. The system also performs data transmission according to the data transmission strategy and conducts security verification according to the sending key through the data transmission module, and backs up the target transmission data that passes the security verification to improve the security of data distributed storage. The system real-time identifies the faulty nodes through the security monitoring module, and repairs the faulty nodes according to the fault conditions of the adjacent nodes at the same level and the fault conditions of the upper-level connected nodes through the fault repair module to ensure the security of data distributed storage. The system also conducts repair verification on the repaired faulty nodes through the fault repair module to ensure the accuracy of data repair. The system judges the fault conditions according to the number of faults of the adjacent nodes at the same level of the edge nodes through the dynamic optimization module, and optimizes the transmission strategy of the edge nodes according to the fault conditions to optimize the fault conditions and reduce the occurrence of fault conditions, further improving the security of data distributed storage. The system judges the expansion situation of the edge nodes according to the number of single-point faults of the edge nodes through the dynamic optimization module, and adjusts the optimization result of the transmission strategy according to the judgment result to further judge the cause of the fault conditions and adopt a better transmission strategy optimization method, thereby further improving the security of data distributed storage. Description of the Drawings

[0057] Figure 1Schematic diagram of the data distributed security storage system for computer science and technology in this embodiment;

[0058] Figure 2 Schematic diagram of the data transmission module in this embodiment;

[0059] Figure 3 Schematic diagram of the data distributed security storage device in this embodiment;

[0060] Figure 4 Schematic flow chart of the data distributed security storage method for computer science and technology in this embodiment. Detailed implementation manners

[0061] In order to make the objectives and advantages of the present invention clearer and more understandable, the present invention will be further described below in conjunction with embodiments; it should be understood that the specific embodiments described herein are only used to explain the present invention and are not used to limit the present invention.

[0062] The preferred embodiments of the present invention will be described below with reference to the accompanying drawings. Those skilled in the art should understand that these embodiments are only used to explain the technical principles of the present invention and do not limit the protection scope of the present invention.

[0063] In addition, it should be noted that in the description of the present invention, unless otherwise clearly specified and limited, the terms "installation", "connection", and "connection" should be understood in a broad sense. For example, it can be a fixed connection, a detachable connection, or an integral connection; it can be a mechanical connection or an electrical connection; it can be directly connected or indirectly connected through an intermediate medium, and it can be the communication inside two components. For those skilled in the art, the specific meanings of the above terms in the present invention can be understood according to specific situations.

[0064] Please refer to Figure 1 as shown, which is a schematic diagram of the data distributed security storage system for computer science and technology in this embodiment. The system includes:

[0065] A data storage module for storing node data;

[0066] A data transmission module for processing node data to obtain target transmission data, performing data transmission according to a data transmission strategy, and also performing security verification according to a sending key and backing up the target transmission data that passes the security verification;

[0067] A security monitoring module for real-time identification of faulty nodes;

[0068] A fault repair module for repairing faulty nodes according to the fault conditions of peer adjacent nodes and the fault conditions of upper-level connected nodes, and also performing repair verification on the repaired faulty nodes;

[0069] A dynamic optimization module is used to judge the fault situation according to the number of faults of the peer adjacent nodes of the edge node, optimize the transmission strategy of the edge node according to the fault situation, and is also used to judge the expansion situation of the edge node according to the number of single-point faults of the edge node, and adjust the optimization result of the transmission strategy according to the judgment result.

[0070] Specifically, the system is set in a data distributed security storage device that distributes and stores data in computer science and technology. By storing and transmitting backups of the data of each edge node, the security of data transmission is guaranteed, and when a node fails, the node is repaired to ensure the data security of the node, thereby improving the security of data distributed storage. The system stores the node data through a data storage module for edge computing, realizes the integration of computing and storage, and improves the efficiency of cloud computing. The system processes the node data through a data transmission module to obtain target transmission data for data transmission, thereby improving the data transmission efficiency during data distributed storage. The system also transmits data according to the data transmission strategy through the data transmission module and performs security verification according to the sending key, and backs up the target transmission data that passes the security verification to improve the security of data distributed storage. The system uses a security monitoring module to identify faulty nodes in real time, and uses a fault repair module to repair the faulty nodes according to the fault situations of peer adjacent nodes and upper connection nodes to ensure the security of data distributed storage. The system also uses the fault repair module to repair and proofread the repaired faulty nodes to ensure the accuracy of data repair. The system uses a dynamic optimization module to judge the fault situation according to the number of faults of the peer adjacent nodes of the edge node, and optimize the transmission strategy of the edge node according to the fault situation to optimize the fault situation and reduce the occurrence of the fault situation, further improving the security of data distributed storage. The system uses a dynamic optimization module to judge the expansion situation of the edge node according to the number of single-point faults of the edge node, and adjust the optimization result of the transmission strategy according to the judgment result to further judge the cause of the fault situation and adopt a better transmission strategy optimization method, thereby further improving the security of data distributed storage.

[0071] Specifically, the data storage module obtains the edge node storage strategy of the edge node, and stores the node data generated by the edge node in the edge node database according to the edge node storage strategy.

[0072] Specifically, the edge node refers to the terminal for performing edge cloud computing, and the edge node storage policy refers to the method of storing the node data generated by the edge node. The edge storage policy in this embodiment refers to storing the node data generated by the edge node in the edge node database set within the edge node, and the node data refers to the data generated by the edge node during the process of cloud computing.

[0073] Specifically, the data storage module realizes the integration of computing and storage by storing the node data generated by the edge node in the edge node database, thereby improving the cloud computing speed.

[0074] Specifically, the security monitoring module obtains the heartbeat signal time interval T of each edge node, compares the heartbeat signal time interval T of each edge node with the preset heartbeat signal time interval T0, and identifies the faulty node in real time according to the comparison result, where:

[0075] When T ≤ T0, the security monitoring module determines that the edge node is not a faulty node;

[0076] When T > T0, the security monitoring module determines that the edge node is a faulty node.

[0077] Specifically, the heartbeat signal refers to the signal regularly sent by each edge node to other edge nodes in a large-scale distributed system. The heartbeat signal time interval refers to the duration elapsed from the time point of the last sent heartbeat signal to the current time. The preset heartbeat signal time interval refers to the preset duration value indicating that the edge node is a faulty node. For example, the preset heartbeat signal time interval can be set to 2 hours.

[0078] Specifically, the fault repair module repairs the faulty node according to the fault conditions of the adjacent nodes at the same level, where:

[0079] When there are no faults in the adjacent nodes at the same level, the fault repair module selects any adjacent node at the same level as the auxiliary repair node, obtains the target transmission data stored in the backup database of the auxiliary repair node that is consistent with the edge node name label of the faulty node, and stores it as the repair data in the repair node;

[0080] When one of the adjacent nodes at the same level has a fault, the fault repair module uses the other non-faulty adjacent node at the same level as the auxiliary repair node, obtains the target transmission data stored in the backup database of the auxiliary repair node that is consistent with the edge node name label of the faulty node, and stores it as the repair data in the repair node;

[0081] When adjacent nodes at the same level all have faults, the fault repair module repairs the faulty nodes according to the fault conditions of the upper-level connection nodes, where:

[0082] When the upper-level connection node has no fault, the fault repair module uses the upper-level connection node as an auxiliary repair node, obtains the target transmission data stored in the backup database of the auxiliary repair node that is consistent with the edge node name label of the faulty node, and stores it as repair data in the repair node;

[0083] When the upper-level connection node has a fault, the fault repair module uses the most adjacent upper-level node that has no fault and is one level higher than the upper-level connection node as an auxiliary repair node, obtains the target transmission data stored in the backup database of the auxiliary repair node that is consistent with the edge node name label of the faulty node, and stores it as repair data in the repair node.

[0084] Specifically, the repair node refers to a new node that is obtained after restarting or replacing the edge node after it is determined to be a faulty node and is used to replace the edge node for cloud computing.

[0085] Specifically, the fault repair module repairs and proofreads the repaired faulty nodes according to the fault conditions of adjacent nodes at the same level, where:

[0086] When adjacent nodes at the same level all have no faults, the fault repair module obtains another adjacent node at the same level except the auxiliary repair node as a repair proofreading node, compares the target transmission data stored in the backup database of the repair proofreading node that is consistent with the edge node name label of the faulty node with the repair data as repair proofreading data, and judges the repair proofreading situation of the faulty node according to the comparison result, where:

[0087] If the repair proofreading data is consistent with the repair data, the fault repair module determines not to repair and proofread the faulty node;

[0088] If the repair proofreading data is inconsistent with the repair data, the fault repair module determines to repair and proofread the faulty node, and supplements the data that is inconsistent with the repair data in the repair proofreading data to the repair data as proofreading data;

[0089] When adjacent nodes at the same level all have faults, the fault repair module determines not to repair and proofread the faulty node.

[0090] Specifically, the dynamic optimization module obtains the number of failures z of the sibling adjacent nodes of the edge node during the optimization period, compares the number of failures z of the sibling adjacent nodes of the edge node with the preset number of failures z0 of the sibling adjacent nodes of the edge node, judges the fault situation according to the comparison result, and optimizes the transmission strategy of the edge node according to the fault situation, where:

[0091] When z ≤ z0, the dynamic optimization module determines that the fault situation is normal;

[0092] When z > z0, the dynamic optimization module determines that the fault situation is abnormal, optimizes the transmission strategy of the edge node, and optimizes strategy A to strategy B when the data transmission object of the edge node is the sibling adjacent node.

[0093] Specifically, the optimization period refers to a preset interval period for optimizing the transmission strategy of the edge node. For example, the optimization period can be set to 7 days. The number of failures of the sibling adjacent nodes of the edge node refers to the number of times that the sibling adjacent nodes on both sides of the edge node also have failures when the edge node fails. In this embodiment, the acquisition method of the number of failures of the sibling adjacent nodes of the edge node during the optimization period is not limited, and those skilled in the art can freely set it according to the actual situation, as long as the acquisition requirement of the number of failures of the sibling adjacent nodes of the edge node during the optimization period is met. For example, it can be set to obtain the number of failures of the sibling adjacent nodes of the edge node during the optimization period by reading the system log during the optimization period. The preset number of failures of the sibling adjacent nodes of the edge node refers to the preset number of failures of the sibling adjacent nodes that reflects the abnormal fault situation, such as 5 times.

[0094] Specifically, the dynamic optimization module optimizes and adjusts the transmission strategy of the edge node with frequent chain failures to prevent data loss caused by frequent failures.

[0095] Specifically, the dynamic optimization module obtains the single-point failure number F of the edge node during the optimization period, compares the single-point failure number F of the edge node with the preset single-point failure number F0 of the edge node, judges the expansion situation of the edge node according to the comparison result, and adjusts the optimization result of the transmission strategy according to the judgment result, where:

[0096] When F ≤ F0, the dynamic optimization module determines not to expand the edge node;

[0097] When F > F0, the dynamic optimization module determines to expand the edge node, and adjusts the result of optimizing strategy A to strategy B when the data transmission object of the edge node is the sibling adjacent node to strategy A.

[0098] Specifically, the number of single-point failures of the edge node refers to the number of times when the edge node fails and the peer adjacent nodes on both sides of it do not fail. In this embodiment, the method for obtaining the number of single-point failures of the edge node is not limited, and those skilled in the art can freely set it according to the actual situation, as long as the requirement for obtaining the number of single-point failures of the edge node is satisfied. For example, it can be set to obtain the number of single-point failures of the edge node by reading the system log within the optimization period. The preset number of single-point failures of the edge node refers to a preset value representing the number of failures for expanding the edge node, such as 6 times. In this embodiment, the expansion method is not limited, and those skilled in the art can freely set it according to the actual situation, as long as the self-optimization requirement of the edge node is satisfied. For example, it can be set to expand the edge node by expanding the hard disk.

[0099] Specifically, the dynamic optimization module judges the expansion situation of the edge node, and adjusts the optimization result of the transmission strategy according to the judgment result to identify chain failures, eliminate the failure situations due to the self-condition of the edge node, and expand the edge node to optimize the transmission strategy when the data transmission object is a peer adjacent node, so as to improve the data distributed security storage security of computer science and technology.

[0100] Please refer to Figure 2 as shown, which is a schematic structural diagram of the data transmission module of this embodiment. The data transmission module includes:

[0101] A data processing unit for processing node data to obtain target transmission data;

[0102] A data sending unit for performing data transmission according to the data transmission strategy;

[0103] A security verification unit for performing security verification on the target transmission data according to the sending key;

[0104] A node backup unit for backing up the target transmission data that has passed the security verification.

[0105] Specifically, when the data processing unit processes the node data, it obtains the data generation location address and data content in the node data, performs text comparison on the data generation location and data content of each node data through the command-line tool of the cmp command, and identifies duplicate data according to the comparison result, where:

[0106] When the data generation location address and data content of each node data are the same, identify the each node data as duplicate data;

[0107] When the data generation location address and data content of each node data are different, identify the each node data as non-duplicate data;

[0108] The data processing unit selects one node data from the duplicate data as the deduplicated data. Every other data processing cycle, the deduplicated data and non-duplicate data generated during this data processing cycle are integrated into a data packet, and the data packet is compressed. The data packet after data compression is used as the target transmission data.

[0109] Specifically, the cmp command refers to a command-line tool for comparing the differences between two non-text document files. In this embodiment, the data integration method is not limited, and those skilled in the art can freely set it according to the actual situation as long as the data integration requirements are met. For example, Talend Open Studio can be set as the data integration method. In this embodiment, the data compression method is not limited, and those skilled in the art can freely set it according to the actual situation. For example, the WinRAR compression tool can be set as the data compression method.

[0110] Specifically, the data processing unit identifies the duplicate data to deduplicate the data, thereby saving resources and avoiding failures, so as to improve the security of data distributed storage.

[0111] Specifically, the data sending unit sets the data transmission strategy according to the data transmission object of the edge node, where:

[0112] When the data transmission object of the edge node is a peer adjacent node, the data transmission strategy is set to Strategy A;

[0113] When the data transmission object of the edge node is a superior connection node, the data transmission strategy is set to Strategy B.

[0114] The data transmission object of the edge node refers to the edge node that receives the target transmission data and the sending key sent by the edge node, including peer adjacent nodes and superior connection nodes. Strategy A means sending the target transmission data and the sending key as peer backup data. Strategy B means sending the subordinate backup data, the target transmission data and the sending key as superior backup data. When the superior connection node receives the superior backup data sent by the subordinate connection node, it is used as the subordinate backup data of this superior connection node.

[0115] Specifically, the data sending unit sets the data transmission strategy to achieve mutual backup of peer adjacent nodes and integrated backup of each subordinate connection node by the superior connection node.

[0116] Specifically, the security verification unit obtains the sending key R, decrypts the sending key R according to the base point T and the verification key Y, and performs security verification on the target transmission data, where:

[0117] When R = T × Y, the security verification unit determines that the decryption of the sending key is successful, and the target transmission data passes the security verification;

[0118] When R ≠ T × Y, the security verification unit determines that the decryption of the sending key fails, and the target transmission data fails to pass the security verification.

[0119] Specifically, the sending key refers to the plaintext value obtained after the product encryption of the preset private key point and the base point in the elliptic encryption function by the edge node, the verification key refers to the randomly preset private key point by the data transmission object of the edge node in the elliptic encryption function, the base point refers to the known point whose values obtained by multiplying with the preset private key point and multiplying with the verification key are the same in the elliptic encryption function, and the public key refers to the point obtained by multiplying with the preset private key point or the verification key in the elliptic encryption function.

[0120] Specifically, the security verification unit performs security verification on the target transmission data to ensure the security of the data transmission of the edge node, thereby realizing the decentralization of the edge node data management, improving the anti-tampering property of the data distributed storage, and thus ensuring the authenticity of the data.

[0121] Specifically, the node backup unit performs node identity marking on the target transmission data that has passed the security verification, obtains data in the format of edge node name tag - target transmission data, and stores it as the marked data in the backup database of the data transmission object of the edge node.

[0122] Please refer to Figure 3 as shown, which is a schematic structural diagram of the data distributed security storage device of this embodiment. The device includes:

[0123] Each peer adjacent node, which is composed of each edge node, is an edge node with an adjacent relationship. The first edge node 1 and the third edge node 3 are peer adjacent nodes of the second edge node 2, and they are located in the Kth layer of the data distributed security storage device. The fourth edge node 4 and the sixth edge node 6 are peer adjacent nodes of the fifth edge node 5, and they are located in the (K - 1)th layer of the data distributed security storage device. The seventh edge node 7 is a peer adjacent node of the eighth edge node 8, and it is located in the second layer of the data distributed security storage device;

[0124] Each upper-level connection node, which is composed of each edge node, is the edge node of the (K - 1)-th layer of each edge node of the K-th layer. The fourth edge node 4 is the upper-level connection node of the first edge node 1 and the second edge node 2, and the root node 9 is the upper-level connection node of the seventh edge node 7 and the eighth edge node 8;

[0125] The root node 9, which is an edge node located at the center of the data distributed security storage device and is an edge node of the first layer;

[0126] Each data transmission channel, which is a data transmission channel connecting each edge node and is used for data transmission between edge nodes.

[0127] Specifically, the total number of edge nodes in the K-th layer is H, and it is set that H = 2 K-1 , each pair of edge nodes is connected to each other and is also connected to the same upper-level connection node. The number of layers of edge nodes is not limited in this embodiment, and those skilled in the art can freely set it according to the actual situation. For example, the number of layers of edge nodes can also be set to (K + 1) layers. In this embodiment, if the second edge node fails, and the first edge node and the third edge node also fail, when all adjacent nodes at the same level fail, and when the second edge node fails but the fourth edge node does not fail, then the upper-level connection node does not fail. If the fourth edge node fails, but all edge nodes between the (K - 1)-th layer and the third layer fail, and the seventh edge node is the closest non-failing upper-level node that is more upper-level than the fourth edge node, and the seventh edge node does not fail, then the seventh edge node is used as the auxiliary repair node.

[0128] Please refer to Figure 4 as shown, which is a schematic flow chart of the data distributed security storage method of computer science and technology in this embodiment. The method includes:

[0129] Step S1, storing node data through the data storage module;

[0130] Step S2, processing node data through the data transmission module to obtain target transmission data, performing data transmission according to the data transmission strategy, and also performing security verification on the target transmission data through the data transmission module according to the sending key and backing up the target transmission data that passes the security verification;

[0131] Step S3, identifying faulty nodes in real time through the security monitoring module;

[0132] Step S4, repairing faulty nodes through the fault repair module according to the fault conditions of adjacent nodes at the same level and the fault conditions of upper-level connection nodes, and performing repair verification on the repaired faulty nodes;

[0133] Step S5: The dynamic optimization module determines the fault situation based on the number of faults of the peer adjacent nodes of the edge node, optimizes the transmission strategy of the edge node according to the fault situation, and also determines the expansion situation of the edge node based on the number of single-point faults of the edge node through the dynamic optimization module, and adjusts the optimization result of the transmission strategy according to the judgment result.

[0134] So far, the technical solution of the present invention has been described in conjunction with the preferred embodiments shown in the drawings. However, it is easy for those skilled in the art to understand that the protection scope of the present invention is obviously not limited to these specific embodiments. Without departing from the principle of the present invention, those skilled in the art can make equivalent changes or substitutions to the relevant technical features, and the technical solutions after these changes or substitutions will fall within the protection scope of the present invention.

Claims

1. A data distributed secure storage system for computer science and technology, characterized in that: include: A data storage module, used to store node data; The data transmission module is used to process the node data, obtain the target transmission data, and transmit the data according to the data transmission strategy. It is also used to perform security verification according to the sending key and back up the target transmission data that has passed the security verification; Safety monitoring module, used to identify faulty nodes in real time; A fault repair module is used to repair the faulty node according to the fault conditions of the adjacent nodes at the same level and the fault conditions of the upper-level connected nodes, and is also used to repair and proofread the repaired faulty node; A dynamic optimization module is used to judge the fault situation according to the number of faults of the same-level adjacent nodes of the edge node, and optimize the transmission strategy of the edge node according to the fault situation. It is also used to judge the expansion situation of the edge node according to the number of single-point failures of the edge node, and adjust the transmission strategy optimization result according to the judgment result; The safety monitoring module obtains the heartbeat signal time interval T of each edge node, and compares the heartbeat signal time interval T of each edge node with the preset heartbeat signal time interval T0, and identifies the faulty node in real time according to the comparison result, wherein: When T≤T0, the safety monitoring module determines that the edge node is not a faulty node; When T>T0, the safety monitoring module determines that the edge node is a faulty node; The fault repair module repairs the faulty node according to the fault condition of the adjacent node at the same level, wherein: When none of the adjacent nodes at the same level has any fault, the fault repair module selects any adjacent node at the same level as an auxiliary repair node, obtains the target transmission data stored in the backup database of the auxiliary repair node that is consistent with the edge node name label of the faulty node, and stores it in the repair node as repair data; When one of the adjacent nodes of the same level fails, the fault repair module uses another adjacent node of the same level that is not faulty as an auxiliary repair node, obtains the target transmission data stored in the backup database of the auxiliary repair node that is consistent with the edge node name label of the faulty node, and stores it in the repair node as repair data; When all adjacent nodes at the same level have faults, the fault repair module repairs the faulty node according to the fault condition of the upper-level connection node, wherein: When there is no fault in the upper connection node, the fault repair module uses the upper connection node as an auxiliary repair node, obtains the target transmission data stored in the backup database of the auxiliary repair node that is consistent with the edge node name label of the faulty node, and stores it in the repair node as repair data; When a fault occurs in an upper connection node, the fault repair module uses the uppermost node of the upper connection node that is not faulty as an auxiliary repair node, obtains target transmission data stored in a backup database of the auxiliary repair node that is consistent with the edge node name tag of the faulty node, and stores it in the repair node as repair data; The fault repair module performs repair and verification on the repaired faulty node according to the fault conditions of the adjacent nodes at the same level, wherein: When there are no faults in the adjacent nodes of the same level, the fault repair module obtains another adjacent node of the same level except the auxiliary repair node as a repair and proofreading node, and compares the target transmission data stored in the backup database of the repair and proofreading node with the edge node name label of the faulty node as the repair and proofreading data with the repair data, and judges the repair and proofreading status of the faulty node according to the comparison result, wherein: If the repair and proofreading data is consistent with the repair data, the fault repair module determines not to perform repair and proofreading on the faulty node; If the repair proofreading data is inconsistent with the repair data, the fault repair module determines to perform repair proofreading on the faulty node, and adds the data in the repair proofreading data that is inconsistent with the repair data as proofreading data to the repair data; When all adjacent nodes at the same level are faulty, the fault repair module determines not to repair and calibrate the faulty node; The dynamic optimization module obtains the number of failures z of the same-level adjacent nodes of the edge node within the optimization period, and compares the number of failures z of the same-level adjacent nodes of the edge node with the number of failures z0 of the same-level adjacent nodes of the preset edge node, and judges the failure situation according to the comparison result, and optimizes the transmission strategy of the edge node according to the failure situation, wherein: When z≤z0, the dynamic optimization module determines that the fault condition is normal; When z>z0, the dynamic optimization module determines that the fault condition is abnormal, and optimizes the transmission strategy of the edge node, optimizing strategy A when the data transmission object of the edge node is an adjacent node of the same level to strategy B; The dynamic optimization module obtains the number of single-point failures F of the edge node within the optimization period, and compares the number of single-point failures F of the edge node with the number of single-point failures F0 of the preset edge node, judges the expansion of the edge node according to the comparison result, and adjusts the transmission strategy optimization result according to the judgment result, wherein: When F≤F0, the dynamic optimization module determines not to expand the edge node; When F>F0, the dynamic optimization module determines to expand the capacity of the edge node, and adjusts the result of optimizing strategy A to strategy B when the data transmission object of the edge node is the same-level adjacent node to strategy A.

2. The data distributed secure storage system of computer science and technology according to claim 1 is characterized in that: The data transmission module is provided with a data processing unit for processing the node data to obtain target transmission data; When processing the node data, the data processing unit obtains the data generation location address and data content in the node data, performs text comparison on the data generation location and data content of each node data through the command line tool of the cmp command, and identifies duplicate data according to the comparison result, wherein: When the data generation location address and data content of each node data are the same, identifying the each node data as duplicate data; When the data generation location address and data content of each node data are different, identifying the data of each node as non-duplicate data; The data processing unit selects a node data in the duplicate data as deduplicated data, and integrates the deduplicated data and non-duplicate data generated in the data processing cycle into a data packet every other data processing cycle, compresses the data packet, and uses the compressed data packet as target transmission data.

3. The data distributed secure storage system of computer science and technology according to claim 2 is characterized in that: The data transmission module is provided with a data sending unit for performing data transmission according to the data transmission strategy; The data sending unit sets the data transmission strategy according to the data transmission object of the edge node, wherein: When the data transmission object of the edge node is the adjacent node at the same level, the data transmission strategy is set to strategy A; When the data transmission object of the edge node is the upper connection node, the data transmission strategy is set to strategy B; The data transmission module is provided with a security verification unit for performing security verification on the target transmission data according to the sending key; The security verification unit obtains the sending key R, decrypts the sending key R according to the base point T and the verification key Y, and performs security verification on the target transmission data according to the decryption result, wherein: When R=T×Y, the security verification unit determines that the sending key decryption is successful and the target transmission data passes the security verification; When R≠T×Y, the security verification unit determines that the sending key decryption fails and the target transmission data fails the security verification; The data transmission module is provided with a node backup unit for backing up target transmission data that has passed security verification; The node backup unit performs node identity tagging on the target transmission data that has passed the security verification, obtains data in the format of edge node name tag-target transmission data, and stores it as the marked data in the backup database of the data transmission object of the edge node.

4. The data distributed secure storage system of computer science and technology according to claim 1 is characterized in that: The data distributed secure storage device includes: Each peer adjacent node is composed of each edge node and is an edge node having an adjacent relationship. The first edge node and the third edge node are peer adjacent nodes of the second edge node and are located in the Kth layer in the data distributed secure storage device. The fourth edge node and the sixth edge node are peer adjacent nodes of the fifth edge node and are located in the K-1th layer in the data distributed secure storage device. The seventh edge node is a peer adjacent node of the eighth edge node and is located in the second layer in the data distributed secure storage device. Each upper connection node, which is composed of each edge node, is an edge node of the K-1th layer of each edge node of the Kth layer, the fourth edge node is the upper connection node of the first edge node and the second edge node, and the root node is the upper connection node of the seventh edge node and the eighth edge node; The root node is an edge node located at the center of the data distributed secure storage device and is an edge node of the first layer; Each data transmission channel is a data transmission channel connecting each edge node and is used for data transmission between edge nodes.

5. A method for a data distributed secure storage system applied to computer science and technology as claimed in any one of claims 1 to 4, characterized in that: include: Step S1, storing node data through a data storage module; Step S2, processing the node data through the data transmission module to obtain the target transmission data, and performing data transmission according to the data transmission strategy, and also performing security verification according to the sending key through the data transmission module, and backing up the target transmission data that passes the security verification; Step S3, real-time identification of faulty nodes through a safety monitoring module; Step S4, repairing the faulty node according to the fault conditions of the adjacent nodes at the same level and the fault conditions of the upper-level connected nodes through the fault repair module, and performing repair and proofreading on the repaired faulty node; Step S5, the dynamic optimization module is used to judge the fault situation according to the number of failures of the same-level adjacent nodes of the edge node, and the transmission strategy of the edge node is optimized according to the fault situation. The dynamic optimization module is also used to judge the expansion situation of the edge node according to the number of single-point failures of the edge node, and the transmission strategy optimization result is adjusted according to the judgment result.

Citation Information

Patent Citations

  • Distributed storage system and copy selection method thereof

    CN115190135A

  • Arrangement and method for handling failures in network

    CN101821990A

  • Remote disaster recovery backup system based on cloud server storage module

    CN117389793A