File storage method, device, equipment, storage medium and computer program product
By combining periodic data determination, encryption processing, decryption module pool, and network security monitoring model in the cloud disk, the problem of data leakage during cloud disk data backup is solved, and the security and integrity of data during transmission and decryption are achieved.
Patent Information
- Application Number
- CN202411037098.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-07-31
- Publication Date
- 2025-11-28
- Estimated Expiration
- 2044-07-31
AI Technical Summary
Existing cloud storage services have security issues related to data leakage during the data backup process, especially during data transmission and decryption, which are vulnerable to cyberattacks, resulting in insufficient data security.
The system uses a preset cycle to determine the data to be backed up, encrypts the target data with a public key, and uses an execution pool composed of decryption modules to decrypt the data. Combined with a network security monitoring model and a secret sharing strategy, the system ensures the security of the data during cloud disk upload and internal decryption.
It effectively prevents data tampering, improves the security of cloud disk backup storage data, ensures the integrity and security of data during transmission and decryption, and enhances the ability to resist attacks.
Smart Images

Figure CN119071019B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of file storage, and in particular to a file storage method, device, equipment, storage medium and computer program product. BACKGROUND
[0002] A cloud disk is a professional Internet storage tool and a product of Internet cloud technology. It provides information storage, reading and downloading services for enterprises and individuals through the Internet. Meanwhile, under the support of cluster systems, grid technology, file systems and other technologies, a storage system based on a cloud disk can provide massive storage services externally and has the characteristics of safety, stability and massive storage.
[0003] Compared with a traditional physical disk, a cloud disk storage is more convenient and fast. A user does not need to carry a physical disk storing important information, but can easily read the information stored by himself from the cloud through the Internet, thereby solving the problems related to file storage, such as small storage capacity of a single computer hard disk, low management efficiency and poor network transmission capacity.
[0004] However, in addition to convenience, security is also a major problem that needs to be considered for cloud disk storage. Ordinary data backup is only to backup data to the local and does not need to consider security problems, and even can ensure the security of data through physical isolation. However, since the cloud disk is set in the cloud, the backup of local data to the cloud disk will inevitably involve data network transmission, and the data transmission process is extremely vulnerable to network attacks, thereby causing the leakage of backup data and affecting the security of user data.
[0005] Therefore, how to ensure the security of cloud disk backup data has become a problem to be solved at present. SUMMARY
[0006] The embodiments of the present application provide a file storage method to solve the problem of data leakage that may exist when the existing cloud disk performs data backup.
[0007] The embodiments of the present application also provide a file storage device to solve the problem of data leakage that may exist when the existing cloud disk performs data backup.
[0008] The embodiments of the present application also provide a file storage device to solve the problem of data leakage that may exist when the existing cloud disk performs data backup.
[0009] The embodiments of the present application also provide a computer readable storage medium to solve the problem of data leakage that may exist when the existing cloud disk performs data backup.
[0010] The embodiments of the present application also provide a computer program product to solve the problem of data leakage that may exist when the existing cloud disk performs data backup.
[0011] The embodiment of the application adopts the technical scheme below.
[0012] A file storage method comprises: determining target data to be uploaded to cloud disk backup storage in a to-be-backed-up application according to a pre-device backup period; receiving encrypted target data uploaded by the to-be-backed-up application; determining at least two decryption modules to form an execution pool from a decryption module pool, and decrypting the encrypted target data through the execution pool to obtain decrypted data; determining a check value of the decrypted data corresponding to each decryption module in the execution pool respectively according to the decrypted data, and determining target data according to the check value; and updating a first file corresponding to the to-be-backed-up application in the cloud disk according to the target data, to complete data backup storage of the to-be-backed-up application.
[0013] A file storage device comprises: a backup data determination unit configured to determine target data to be uploaded to cloud disk backup storage in a to-be-backed-up application according to a pre-device backup period; a backup data receiving unit configured to receive encrypted target data uploaded by the to-be-backed-up application; a decryption unit configured to determine at least two decryption modules to form an execution pool from a decryption module pool, and decrypt the encrypted target data through the execution pool to obtain decrypted data; a data identification unit configured to determine a check value of the decrypted data corresponding to each decryption module in the execution pool respectively according to the decrypted data, and determine target data according to the check value; and a backup storage unit configured to update a first file corresponding to the to-be-backed-up application in the cloud disk according to the target data, to complete data backup storage of the to-be-backed-up application.
[0014] A file storage device comprises: a processor; and a memory arranged to store computer executable instructions that, when executed, cause the processor to perform the following operations: determining target data to be uploaded to cloud disk backup storage in a to-be-backed-up application according to a pre-device backup period; receiving encrypted target data uploaded by the to-be-backed-up application; determining at least two decryption modules to form an execution pool from a decryption module pool, and decrypting the encrypted target data through the execution pool to obtain decrypted data; determining a check value of the decrypted data corresponding to each decryption module in the execution pool respectively according to the decrypted data, and determining target data according to the check value; and updating a first file corresponding to the to-be-backed-up application in the cloud disk according to the target data, to complete data backup storage of the to-be-backed-up application.
[0015] A computer readable storage medium stores one or more programs, which when executed by an electronic device comprising a plurality of applications, cause the electronic device to: determine target data to be uploaded to a cloud disk backup storage in a to-be-backed-up application according to a pre-device backup period; receive encrypted target data uploaded by the to-be-backed-up application; determine at least two decryption modules from a decryption module pool to form an execution pool, and decrypt the encrypted target data through the execution pool to obtain decrypted data; determine a check value of the decrypted data corresponding to each decryption module in the execution pool according to the decrypted data, and determine target data according to the check value; update a first file corresponding to the to-be-backed-up application in the cloud disk according to the target data, and complete data backup storage of the to-be-backed-up application.
[0016] A computer program product comprises a computer program, which when executed by a processor, implements: determining target data to be uploaded to a cloud disk backup storage in a to-be-backed-up application according to a pre-device backup period; receiving encrypted target data uploaded by the to-be-backed-up application; determining at least two decryption modules from a decryption module pool to form an execution pool, and decrypting the encrypted target data through the execution pool to obtain decrypted data; determining a check value of the decrypted data corresponding to each decryption module in the execution pool according to the decrypted data, and determining target data according to the check value; updating a first file corresponding to the to-be-backed-up application in the cloud disk according to the target data, and completing data backup storage of the to-be-backed-up application.
[0017] The above at least one technical solution adopted by the embodiments of the present application can achieve the following beneficial effects:
[0018] The file storage method provided in the embodiment of the application can be used to determine target data to be uploaded to a cloud disk backup storage in a to-be-backed-up application according to a backup period, and after the target data is determined, the data backup system can broadcast an encryption public key to the to-be-backed-up application, receive encrypted target data uploaded by the to-be-backed-up application, determine at least two decryption modules to form an execution pool from a decryption module pool, and decrypt the encrypted target data through the execution pool to obtain decrypted data. According to the decrypted data, a check value of the decrypted data corresponding to each decryption module in the execution pool is determined, and according to the check value, the target data is determined. According to the target data, a first file corresponding to the to-be-backed-up application in the cloud disk is updated, and the data backup storage of the to-be-backed-up application is completed. The file storage method provided in the embodiment of the application can ensure the security of the to-be-backed-up data in the process of uploading the cloud disk through encryption means. On the other hand, through the mode that at least two decryption modules form an execution pool to execute together, the security of the data in the process of decryption in the cloud disk is ensured, the data tampering can be effectively avoided, and the security of the data backup storage in the cloud disk is greatly improved. BRIEF DESCRIPTION OF DRAWINGS
[0019] The accompanying drawings, which are included to provide a further understanding of the application and are incorporated in and constitute a part of this application, illustrate embodiments of the application and serve to explain the application without imposing undue limitation thereon. In the drawings:
[0020] Figure 1 A specific flowchart of a file storage method provided in the embodiment of the application is shown in the figure.
[0021] Figure 2 A specific structure diagram of a file storage device provided in the embodiment of the application is shown in the figure.
[0022] Figure 3 A specific structure diagram of a file storage device provided in the embodiment of the application is shown in the figure. DETAILED DESCRIPTION
[0023] To make the purpose, technical scheme and advantages of the application clearer, the technical scheme of the application will be described in detail below with reference to the specific embodiments of the application and the corresponding drawings. Obviously, the described embodiments are only part of the embodiments of the application, not all the embodiments. Based on the embodiments in the application, all other embodiments obtained by those skilled in the art without creative labor fall within the scope of protection of the application.
[0024] The technical scheme provided by the embodiments of the application will be described in detail below with reference to the drawings.
[0025] The file storage method provided in the embodiments of the present application is used to solve the problem of data leakage that may exist when the existing network disk performs data backup.
[0026] The execution subject of the file storage method provided in the embodiments of the present application may be, but is not limited to, at least one of a cloud disk server, a cloud disk management server, a backup server, a data management server, and the like. In addition, the execution subject of the method may also be an application (APP) or a system itself running on the servers.
[0027] For ease of description, the implementation of the method is described below by taking the execution subject of the method as a data backup storage system installed on a cloud disk. It can be understood that the execution subject of the method as the data backup storage system is only an exemplary description, and should not be understood as a limitation on the method.
[0028] The specific implementation flowchart of the file storage method provided in the present application is shown in Figure 1 The method mainly includes the following steps:
[0029] Step 11: According to a preset backup period, determining target data to be uploaded to the cloud disk for backup storage in the to-be-backed-up application;
[0030] In the embodiments of the present application, the data backup storage system can determine whether new to-be-backed-up data is generated in the to-be-backed-up application within the backup period by comparing the data already backed up in the cloud disk with the data files saved in the data storage area of the to-be-backed-up application according to the preset backup period.
[0031] It should be noted that, in order to avoid the problem of low processing efficiency and high computing resource occupation caused by the data backup storage system needing to compare the full amount of data files each time to determine the to-be-backed-up data, in the embodiments of the present application, the data backup storage system can preset a file segmentation method to segment the data files already backed up in the cloud disk to obtain a plurality of data file segments already backed up. Meanwhile, the to-be-backed-up application can also segment the data files saved in the data storage area according to the same file segmentation method to obtain a plurality of data file segments corresponding to the data file segments already backed up. The checksums of the plurality of data file segments already backed up and the plurality of data file segments are calculated respectively, and then the checksums of the data file segments can be compared directly in the subsequent process to determine which data file segments in the data storage area of the to-be-backed-up application have data modification (data addition, deletion, reduction, or modification, etc.), and then the data file segments with data modification can be determined as the target data to be uploaded to the cloud disk for backup storage.
[0032] Specifically, in an embodiment, the data backup storage system can specifically determine the target data to be uploaded to the cloud disk backup storage according to the following sub-steps, including:
[0033] Sub-step 1101, according to a first segmentation method, performing file segmentation on the first file and the second file to be backed up to obtain at least one first file segment corresponding to the first file and at least one second file segment corresponding to the second file;
[0034] It should be noted that when the pre-backup period is reached, the data backup storage system can perform file segmentation on the backed-up data file (hereinafter referred to as the first file for convenience of description) to obtain at least one first file segment corresponding to the first file.
[0035] Meanwhile, the data backup storage system can issue a file segmentation instruction to the application to be backed up, so that the application to be backed up uses the same file segmentation method to perform file segmentation on the data file (hereinafter referred to as the second file for convenience of description) saved in the data storage area to obtain at least one second file segment corresponding to the second file.
[0036] Sub-step 1102, respectively determining a first check value corresponding to each of the first file segments;
[0037] The first check value includes a first weak check value, a first strong check value, and a first hash value corresponding to each of the first file segments.
[0038] In an embodiment, the data backup storage system can calculate the hash value, the weak check value, and the strong check value of each file segment based on the unique identifier (such as the file segment serial number) of each file segment.
[0039] Specifically, in the embodiment of the present application, the weak check value can be a CRC-32 value (A cyclic redundancy check 32) or an Adler-32 value, that is, a check value calculated by the CRC-32 or Adler-32 algorithm. Such a weak check algorithm has the advantage of fast matching speed. The strong check value can be an MD5 value or an SHA-1 value, that is, a check value calculated by the MD5 or SHA-1 algorithm. Such a strong check algorithm has the advantage of high matching accuracy. The weak check value and the strong check value of the present application are not limited to the above algorithms, but can also use other existing check algorithms. The hash value can be obtained by hashing the string contained in the file segment.
[0040] Sub-step 1103, respectively determining a second check value corresponding to each of the second file segments;
[0041] The second check value includes a second weak check value, a second strong check value and a second hash value corresponding to each second file chunk.
[0042] In an embodiment, the application to be backed up can calculate the hash value, the weak check value and the strong check value of each file chunk according to the unique identifier (for example, the file chunk serial number) of each second file chunk in the same way as the sub-step 1102.
[0043] The sub-step 1104 determines the second file chunk corresponding to each first file chunk in sequence.
[0044] In the embodiment of the present application, the data backup storage system can determine the second file chunk corresponding to each first file chunk according to the serial number of the data file chunk.
[0045] The sub-step 1105 compares the first check value of each first file chunk with the second check value of the corresponding second file chunk respectively to determine the second file chunk to be backed up which is modified in the backup period.
[0046] Specifically, the data backup storage system can first determine whether the first hash value of the first file chunk is the same as the second hash value of the corresponding second file chunk, and when the determination result is no, the second file chunk is determined to be the second file chunk to be backed up.
[0047] When the determination result is yes, it is further determined whether the first weak check value of the first file chunk is the same as the second weak check value of the corresponding second file chunk, and when the determination result is no, the second file chunk is determined to be the second file chunk to be backed up.
[0048] When the determination result is yes, it is further determined whether the first strong check value of the first file chunk is the same as the second strong check value of the corresponding second file chunk, and when the determination result is no, the second file chunk is determined to be the second file chunk to be backed up, otherwise, it is determined that the application to be backed up does not generate data to be backed up in the backup period.
[0049] Step 12 receives the encrypted target data uploaded by the application to be backed up.
[0050] After determining the target data to be uploaded to the cloud disk backup storage in the application to be backed up through the above steps, the data backup storage system broadcasts the corresponding encryption public key and the second file chunk identifier corresponding to the target data to the application to be backed up, so that the application to be backed up encrypts the target data to be backed up according to the received encryption public key to obtain encrypted target data, and uploads the encrypted target data to the data backup storage system of the cloud disk.
[0051] In addition, it should be noted that, in order to ensure data security and avoid data tampering during transmission, in the embodiment of the application, the target data to be backed up can calculate a target hash value of the target data according to a preset hash algorithm, embed the target hash value at the tail of the target data, then encrypt the target data with the embedded target hash value using an encryption public key to obtain encrypted target data, and upload the encrypted target data to the data backup storage system of the cloud disk.
[0052] Step 13, obtaining network traffic characteristics of the cloud disk, identifying the network traffic characteristics according to a pre-trained network security monitoring model, and determining a network security monitoring result;
[0053] It should be noted that, in addition to the need for security protection of the data transmission process, in the embodiment of the application, the decryption process on the cloud disk also needs to be monitored to avoid network intrusion during data processing, thereby further improving the security of the data.
[0054] In one embodiment, the network security monitoring model can be trained through the following sub-steps, comprising:
[0055] Sub-step 1301, constructing an original network security monitoring model according to a convolutional neural network;
[0056] Sub-step 1302, randomly initializing network parameters of the original network security monitoring model to obtain a network parameter vector of the original network security monitoring model, and generating a network parameter population according to the network parameter vector;
[0057] Sub-step 1303, obtaining fitness values of each network parameter vector in the network parameter population;
[0058] The fitness value can be set as 1 / (output error+0.00001).
[0059] Sub-step 1304, selecting at least two network parameter vectors from the network parameter population as an optimal solution population in descending order of the fitness values, and selecting the remaining network parameter vectors in the network parameter population as an updating population;
[0060] Sub-step 1305, obtaining a network parameter vector with the maximum fitness value in the optimal solution population as a global optimal value;
[0061] Sub-step 1306, obtaining historical optimal values of each network parameter vector in the updating population;
[0062] Sub-step 1307, updating each network parameter vector in the updating population using a nonlinear optimization method according to the global optimal value and the historical optimal values to obtain a trained network security monitoring model.
[0063] In an embodiment, the network parameter vector can be updated according to the following formulas [1] to [4]:
[0064]
[0065] wherein, represents the jthdimensional parameter of the ithnetwork parameter vector in the population to be updated at the tthupdate, i = 1, 2, …, A1; A1represents the total number of network parameter vectors in the population to be updated, j = 1, 2, …, A2; A2represents the total number of dimensions of the network parameter vector, represents the jthdimensional parameter of the ithnetwork parameter vector in the population to be updated at the t+1thupdate, represents the increment at the t-1thupdate, represents the increment at the tthupdate, ω represents the inertia weight, represents the first learning factor at the tthupdate, r1represents a first random number between (0, 1), represents the global optimal value, represents the second learning factor at the tthupdate, r2represents a second random number between (0, 1), represents the historical optimal value of the ithnetwork parameter vector at the tthupdate, represents the first learning factor at the t-1thupdate, η represents the adjustment coefficient, T represents the maximum number of updates, σ represents the variance of the learning factor, r3represents a third random number between (0, 1), and γ represents a decay coefficient between (0, 1).
[0066] By adjusting the second learning factor, the influence of the individual historical optimal position on the update can be gradually reduced, so that the influence of the better global optimal value is greater, which can effectively improve the accuracy of the search. In addition, in order to avoid falling into a local optimum, the local optimum can be jumped out, thereby preliminarily ensuring the training effect.
[0067] After the update, when the fitness value of a network parameter vector in the population to be updated is greater than a certain optimal solution, the optimal solution is deleted, and the network parameter vector in the population to be updated is copied to the optimal solution population, thereby completing the update of the optimal solution.
[0068] According to the dispersion degree of the optimal solution population, the probability that the optimal solution in the optimal solution population is updated is determined according to the following formula [5]:
[0069]
[0070] wherein, dd i' represents the Euclidean distance between the ithoptimal solution and the i+1thoptimal solution, dk represents the average value of the Euclidean distance between the i'th optimal solution and the i'+1'th optimal solution and the i'-1'th optimal solution, and K represents the total number of optimal solutions.
[0071] According to the updated probability, it is determined by a roulette mechanism whether the optimal solution needs to be updated. If yes, the optimal solution is updated by using a greedy algorithm, otherwise, the optimal solution is not updated.
[0072] Specifically, in the embodiment of the present application, the updated value of the optimal solution can be determined according to the following formula [6] and formula [7]:
[0073]
[0074] wherein, x i'j represents the jth dimension parameter of the i'th optimal solution, represents the updated x i'j , and represents an intermediate parameter, represents the upper limit of the jth dimension parameter, represents the lower limit of the jth dimension parameter, represents the average value of all dd i' .
[0075] It is determined whether the fitness value corresponding to the updated value is greater than the fitness value of the original optimal solution. If yes, the update is performed, otherwise, the update is not performed.
[0076] Through the above algorithm, the model update training can be performed with a larger step size at the initial stage of the algorithm, and the global optimization effect can be ensured. Meanwhile, only the optimal solution is updated, and the intermediate parameter θ changes with the interval difference between the single optimal solution and the two adjacent optimal solutions and the average distance of all optimal solutions, so that the optimal solution in the crowded interval has a larger running range to increase the ability to jump out of the crowded interval, and the optimal solution in the discrete distribution interval enhances the ability of local precise search, and the speed of local search is accelerated.
[0077] Through the above algorithm, a well-trained network security monitoring model can be obtained, so as to more accurately identify whether the network is safe and ensure the safety in the data backup process.
[0078] Step 14, determining at least two decryption module groups from the decryption module pool to form an execution pool, and decrypting the encrypted target data through the execution pool to obtain decrypted data;
[0079] In the embodiment of the present application, the data backup storage system can schedule multiple decryption modules in the decryption module pool, perform decryption and verification operations on the encrypted target data through the multiple decryption modules, obtain multiple verification results, verify the multiple verification results through the scheduling judge, make a decision on the verification results using the majority consensus decision algorithm, and then obtain the correct decryption data.
[0080] Specifically, in an implementation, the data backup storage system can schedule at least two decryption modules from the decryption module pool to form an execution pool according to the following sub-steps, including:
[0081] Sub-step 1401, determine the confidence degree corresponding to each decryption module in the decryption module pool;
[0082] In the embodiment of the present application, an initial confidence degree is assigned to each decryption module at the most initial time, and the confidence degree of each decryption module is updated in real time according to the following formula [8] as the random scheduling proceeds:
[0083]
[0084] Wherein, λ' represents the updated confidence degree, λ represents the confidence degree before updating, α represents the confidence degree updating coefficient, q represents the number of correct target slices corresponding to the output, Q represents the number of outputs of the selected isomer, χ' represents the decision result, and χ represents the result output by the decryption module.
[0085] Sub-step 1402, determine the decryption module with a confidence degree greater than a first preset threshold as a target decryption module according to the determined confidence degree;
[0086] Sub-step 1403, determine the data heterogeneity between any two target decryption modules respectively;
[0087] A target decryption module m with a confidence degree greater than a first preset threshold is randomly selected to join the execution pool, and then another target decryption module n is randomly selected, and the data heterogeneity between the target decryption module n and the target decryption module m already in the execution pool is determined according to the following formula [9], if the heterogeneity is greater than a set threshold, the target decryption module n is added to the execution pool. Repeat the selection of the target decryption module and perform the above operation until the number of target decryption modules in the execution pool meets the preset requirement.
[0088] dif(m,n)=γ(m,n)*ln(ξ m gξ n )[9]
[0089] Wherein, dif(m,n) represents the data heterogeneity between the target decryption module m and the target decryption module n, γ(i,j) represents the difference degree between the target decryption module m and the target decryption module n, and ξm denotes the complexity of the target decryption module m, ξ n denotes the complexity of the target decryption module n.
[0090] Specifically, the data heterogeneity between the target decryption module m and the target decryption module n can be determined by the following formula
[10] :
[0091]
[0092] wherein A m denotes the feature vector of the target decryption module m, A n denotes the feature vector of the target decryption module n.
[0093] In an embodiment, the complexity of the target decryption module m can be determined according to the following formula
[11] :
[0094]
[0095] wherein c mk denotes the kth complexity index corresponding to the mth target decryption module, w mk denotes the weight corresponding to the kth complexity index, k = 1, 2, …, K, K denotes the total number of complexity indexes.
[0096] Sub-step 1404: According to the target decryption module whose data heterogeneity is greater than the second preset threshold, a performing pool is formed.
[0097] Through each decryption module in the performing pool, the encrypted target data is respectively decrypted to obtain decrypted data.
[0098] By using the above method to perform data decryption, the correctness and security of the final data processed on the cloud disk can be effectively ensured, even if a decryption module is attacked or invaded, data tampering can be avoided. And by introducing the confidence of each decryption module, a relatively secure decryption module can be selected to perform data decryption processing, thereby increasing the difficulty of attack and ensuring the security of data.
[0099] Step 15: According to the decrypted data, the check value of the decrypted data corresponding to each decryption module in the performing pool is respectively determined, and according to the check value, the target data is determined.
[0100] Specifically, in the embodiment of the present application, after obtaining the decrypted data, the data backup storage system can verify the decrypted data according to the target hash value at the tail of the decrypted data. The specific verification method is to perform hash operation on the decrypted data using the same hash algorithm to obtain a decrypted data hash value, and then compare the decrypted data hash value with the target hash value at the tail of the decrypted data. If they are the same, the check value is 1, which means that the decrypted data has not been tampered with. If the comparison result is different, the check value is 0, which means that the decrypted data has been tampered with.
[0101] In the embodiment of the present application, the data backup storage system can schedule the judge to make a decision on the check value using the majority decision algorithm, take the check value with the largest number as the correct check value, and take the decrypted data corresponding to the correct check value as the target data.
[0102] In addition, it should be noted that when the value detection disk determines that there is no correct result, it is determined that an error occurs in the data transmission process or the data is attacked, and then the data backup storage system ends the entire backup process and feeds back abnormal information to the application to be backed up.
[0103] Step 16: updating the first file corresponding to the application to be backed up in the cloud disk according to the target data, and completing the data backup storage of the application to be backed up.
[0104] In the embodiment of the present application, in order to ensure the safety of the data stored in the cloud disk, after completing the processing of the encrypted data uploaded by the application to be backed up by executing the above steps 14-15 and obtaining the target data to be stored, the network security monitoring result obtained by executing step 13 is used to determine whether the network environment of the cloud disk is safe during the processing of the encrypted data. Only when it is determined that the network environment of the cloud disk is safe during the processing, the data backup storage system can store the obtained target data into the cloud disk.
[0105] It should be noted that in order to further ensure the safety of the data stored in the cloud disk, in the embodiment of the present application, before storing the target data in the cloud disk, the data backup storage system can perform encryption processing on the target data using the following method, which specifically includes: performing encryption processing on the target data according to a secret sharing strategy to obtain encrypted target data; and updating the first file corresponding to the application to be backed up in the cloud disk according to the encrypted target data.
[0106] In an embodiment, the data backup storage system can randomly generate a prime number, and determine an encryption public key according to the randomly generated prime number; then encrypt the target data according to the encryption public key to obtain encrypted target data corresponding to the target data and at least two secret values; and determine the same number of physical servers according to the number of secret values, and then store the secret values in the physical servers respectively to complete the encryption of the target data.
[0107] Specifically, the embodiment of the application can encrypt the target data and store the encrypted target data in the cloud disk according to the following sub-steps, including:
[0108] Sub-step 1601, randomly generating a prime number and determining an encryption public key based on the prime number obtaining a public key P=dG;
[0109] wherein G represents an n-order base point of an elliptic curve E, the elliptic curve E is located on a finite field Fp, and 1<ζ<n-1.
[0110] Sub-step 1602, constructing an n-order polynomial on a finite field, as shown in the following formula
[12] :
[0111]
[0112] wherein p(x) represents an n-order polynomial, a0 represents a first coefficient, a1 represents a second coefficient, an represents an n-th coefficient, and x represents a variable of the polynomial.
[0113] Let x0 be an element on the finite field, then randomly take R elements x r , r=1, 2, …, R; and calculate y r =p(x r ), x r be an element on the finite field;
[0114] After the data is encrypted by the public key P, the R secret values (x r , y r ) are respectively stored in R physical servers or R user systems.
[0115] Sub-step 1603, determining two mirror physical servers, and storing the encrypted data in the two mirror physical servers to realize data backup.
[0116] At this time, when the data is attacked or the physical server is damaged, the original data can still be recovered, having stronger anti-damage capability, and even if the attacker obtains the data, obtains less than a certain number of sub-key values, the original data cannot be recovered so as to realize decryption.
[0117] Sub-step 1604, when decryption is needed, first acquire the encrypted data, and acquire n+1 secret values, n>1 / 2R, then the polynomial can be solved according to the n+1 secret values Thus, we get To decrypt.
[0118] By mirroring the physical server and adding multiple storage keys, data backup can be achieved with strong anti-loss risk at a small cost, even if some secret values are lost or damaged, decryption can still be performed, and certain fault tolerance is provided.
[0119] According to the file storage method provided by the embodiment of the application, the data backup system can determine the target data to be uploaded to the cloud disk backup storage in the application to be backed up according to a predetermined backup period. After the target data is determined, the data backup system can broadcast an encryption public key to the application to be backed up, receive the encrypted target data uploaded by the application to be backed up, determine at least two decryption modules to form an execution pool from a decryption module pool, and decrypt the encrypted target data through the execution pool to obtain decrypted data. According to the decrypted data, the check value of the decrypted data corresponding to each decryption module in the execution pool is determined, and the target data is determined according to the check value. According to the target data, the first file corresponding to the application to be backed up in the cloud disk is updated, and the data backup storage of the application to be backed up is completed. According to the file storage method provided by the embodiment of the application, on the one hand, the security of the data to be backed up in the process of uploading the cloud disk is ensured through encryption; on the other hand, the security of the data in the cloud disk during decryption is ensured through the execution of the execution pool by at least two decryption modules, which can effectively avoid data tampering and greatly improve the security of the cloud disk backup storage data.
[0120] In an embodiment, the file storage device provided by the embodiment of the application also provides a file storage device to solve the problem of data leakage that may exist when the existing cloud disk performs data backup. The specific structure diagram of the file storage device is shown in Figure 2 The file storage device includes a backup data determination unit 21, a backup data receiving unit 22, a decryption unit 23, a data identification unit 24, and a backup storage unit 25.
[0121] The backup data determination unit 21 is configured to determine the target data to be uploaded to the cloud disk backup storage in the application to be backed up according to a predetermined backup period.
[0122] The backup data receiving unit 22 is configured to receive the encrypted target data uploaded by the application to be backed up.
[0123] The decryption unit 23 is configured to determine at least two decryption modules from the decryption module pool to form an execution pool, and decrypt the encrypted target data through the execution pool to obtain decrypted data.
[0124] The data identification unit 24 is configured to determine a check value of the decrypted data corresponding to each decryption module in the execution pool respectively according to the decrypted data, and determine the target data according to the check value.
[0125] The backup storage unit 25 is configured to update the first file corresponding to the application to be backed up in the cloud disk according to the target data, to complete the data backup storage of the application to be backed up.
[0126] In an embodiment, the backup data determination unit 21 is specifically configured to: perform file segmentation on the first file and a second file of the application to be backed up according to a first segmentation method to obtain at least one first file segment corresponding to the first file and at least one second file segment corresponding to the second file; determine a first check value corresponding to each first file segment respectively; determine a second check value corresponding to each second file segment respectively; determine the second file segment corresponding to each first file segment in sequence; compare the first check value of each first file segment with the second check value of the corresponding second file segment respectively to determine a second file segment to be backed up which is modified in the backup period; and determine the target data according to the second file segment to be backed up.
[0127] In an embodiment, the first check value includes a first weak check value, a first strong check value and a first hash value, and the second check value includes a second weak check value, a second strong check value and a second hash value. The backup data determination unit 21 is specifically configured to: determine whether the first hash value of the first file segment is the same as the second hash value of the corresponding second file segment, and when the determination result is no, determine that the second file segment is the second file segment to be backed up; when the determination result is yes, determine whether the first weak check value of the first file segment is the same as the second weak check value of the corresponding second file segment, and when the determination result is no, determine that the second file segment is the second file segment to be backed up; and when the determination result is yes, determine whether the first strong check value of the first file segment is the same as the second strong check value of the corresponding second file segment, and when the determination result is no, determine that the second file segment is the second file segment to be backed up.
[0128] In an implementation, the decryption unit 23 is specifically configured to: determine the confidence degree corresponding to each decryption module in the decryption module pool; determine, according to the determined confidence degree, a decryption module with a confidence degree greater than a first preset threshold as a target decryption module; determine the data heterogeneity between any two target decryption modules respectively; and form an execution pool according to target decryption modules with data heterogeneity greater than a second preset threshold.
[0129] In an implementation, the network security detection unit is further configured to: acquire a network traffic feature of the cloud disk; identify the network traffic feature according to a pre-trained network security monitoring model, to determine a network security monitoring result; and when the network security monitoring result obtained through the network security monitoring model is safe, update a first file corresponding to the application to be backed up in the cloud disk according to the target data, to complete data backup storage of the application to be backed up.
[0130] In an implementation, the network security detection unit is specifically configured to: construct an original network security monitoring model according to a convolutional neural network; randomly initialize network parameters of the original network security monitoring model, to obtain a network parameter vector of the original network security monitoring model, and generate a network parameter population according to the network parameter vector; and train the network security monitoring model according to the network parameter population.
[0131] In an implementation, the network security detection unit is specifically configured to: acquire an adaptability value of each network parameter vector in the network parameter population; select at least two network parameter vectors from the network parameter population as an optimal solution population in a descending order of the adaptability value, and select the remaining network parameter vectors in the network parameter population as an updating population; acquire a network parameter vector with the largest adaptability value in the optimal solution population as a global optimal value; acquire a historical optimal value of each network parameter vector in the updating population; and update each network parameter vector in the updating population according to the global optimal value and the historical optimal value, to obtain a trained network security monitoring model.
[0132] In an implementation, the backup storage unit 25 is specifically configured to: encrypt the target data according to a secret sharing strategy, to obtain encrypted target data; and update a first file corresponding to the application to be backed up in the cloud disk according to the encrypted target data, to complete data backup storage of the application to be backed up.
[0133] In an implementation, the backup storage unit 25 is specifically configured to: determine an encryption public key according to a randomly generated prime number; perform encryption processing on the target data according to the encryption public key to obtain encrypted target data corresponding to the target data and at least two secret values; and determine a same number of physical servers as the number of secret values, and store the secret values in the physical servers respectively.
[0134] According to the file storage device provided in the embodiment of the present application, the data backup system can determine target data to be uploaded to the cloud disk backup storage in the application to be backed up according to a backup period, and after the target data is determined, the data backup system can broadcast an encryption public key to the application to be backed up, and receive encrypted target data uploaded by the application to be backed up. The data backup system determines at least two decryption modules to form an execution pool from a decryption module pool, and decrypts the encrypted target data through the execution pool to obtain decrypted data. According to the decrypted data, a check value of the decrypted data corresponding to each decryption module in the execution pool is determined, and according to the check value, the target data is determined. According to the target data, a first file corresponding to the application to be backed up in the cloud disk is updated, and the data backup storage of the application to be backed up is completed. According to the file storage method provided in the embodiment of the present application, on the one hand, the security of the data to be backed up in the process of uploading the cloud disk is ensured through encryption means; on the other hand, the security of the data in the cloud disk during the decryption process is ensured through the execution of the execution pool composed of at least two decryption modules, which can effectively avoid data tampering and greatly improve the security of the data backup storage of the cloud disk.
[0135] Figure 3 is a structural schematic diagram of an electronic device according to an embodiment of the present application. Please refer to Figure 3 At the hardware level, the electronic device includes a processor, and optionally further includes an internal bus, a network interface, and a memory. The memory can include a memory such as a random-access memory (RAM), and can also include a non-volatile memory such as at least one disk memory. Of course, the electronic device can also include other hardware required by the business.
[0136] The processor, the network interface and the memory can be connected with each other through an internal bus, which can be an ISA (Industry Standard Architecture) bus, a PCI (Peripheral Component Interconnect) bus or an EISA (Extended Industry Standard Architecture) bus, etc. The bus can be divided into an address bus, a data bus, a control bus, etc. For the convenience of representation, Figure 3 Only one bidirectional arrow is used to represent the bus, but it does not mean that there is only one bus or only one type of bus.
[0137] The memory is used to store programs. Specifically, the programs can include program codes including computer operation instructions. The memory can include an internal memory and a non-volatile memory, and provide instructions and data for the processor.
[0138] The processor reads the corresponding computer program from the non-volatile memory into the internal memory and then runs, and forms a file storage device at a logical level. The processor executes the programs stored in the memory, and is specifically used for: determining target data to be uploaded to a cloud disk backup storage in a to-be-backed-up application according to a preset backup period; receiving encrypted target data uploaded by the to-be-backed-up application; determining at least two decryption modules to form an execution pool from a decryption module pool, and decrypting the encrypted target data through the execution pool to obtain decrypted data; determining a check value of the decrypted data corresponding to each decryption module in the execution pool according to the decrypted data, and determining target data according to the check value; updating a first file corresponding to the to-be-backed-up application in the cloud disk according to the target data, and completing data backup storage of the to-be-backed-up application.
[0139] The above as described in the present application Figure 3The method executed by the file storage electronic device disclosed by the embodiment can be applied to a processor or implemented by the processor. The processor can be an integrated circuit chip with signal processing capability. In the implementation process, each step of the above method can be completed by integrated logic circuits of hardware in the processor or instructions in the form of software. The above processor can be a general processor, including a central processing unit (CPU), a network processor (NP), etc.; can also be a digital signal processor (DSP), an application specific integrated circuit (ASIC), a field programmable gate array (FPGA) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components. Each method, step and logic block disclosed in the embodiment of the present application can be implemented or executed. The general processor can be a microprocessor or the processor can also be any conventional processor. The steps of the method disclosed in combination with the embodiment of the present application can be directly embodied as a hardware decoding processor for execution, or executed by a combination of hardware and software modules in the decoding processor. The software module can be located in a random access memory, a flash memory, a read only memory, a programmable read only memory, an electrically erasable programmable memory, a register, or other mature storage media in the art. The storage medium is located in the memory, and the processor reads the information in the memory and combines the hardware to complete the steps of the above method.
[0140] Of course, in addition to the software implementation, the electronic device of the present application does not exclude other implementation manners, such as logic devices or a combination of software and hardware, etc., that is, the execution subject of the following processing flow is not limited to each logic unit, but can also be hardware or logic devices.
[0141] The embodiment of the present application also proposes a computer readable storage medium, the computer readable storage medium stores one or more programs, the one or more programs include instructions, when the instructions are executed by the portable electronic device including a plurality of application programs, the portable electronic device can execute Figure 1 The method of the embodiment, and specifically for executing the following operations:
[0142] According to a pre-device backup period, target data to be uploaded to a cloud disk backup storage in an application to be backed up is determined; encrypted target data uploaded by the application to be backed up is received; at least two decryption modules are determined to form an execution pool from a decryption module pool, and the encrypted target data is decrypted by the execution pool to obtain decrypted data; according to the decrypted data, a check value of the decrypted data corresponding to each decryption module in the execution pool is determined respectively, and the target data is determined according to the check value; and according to the target data, a first file corresponding to the application to be backed up in the cloud disk is updated to complete data backup storage of the application to be backed up.
[0143] Those skilled in the art will appreciate that embodiments of the application can be provided as methods, systems, or computer program products. Accordingly, the application can be embodied in the form of an entirely hardware embodiment, an entirely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, the application can be embodied in the form of a computer program product on one or more computer-usable storage media (including, but not limited to, disk memory, CD-ROM, optical memory, etc.) having computer usable program code embodied therein.
[0144] The application is described with reference to flowcharts and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the application. It should be understood that each flow and / or block in the flowcharts and / or block diagrams, as well as combinations of flows and / or blocks in the flowcharts and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general purpose computer, a special purpose computer, an embedded processor, or other programmable data processing apparatus to produce a machine, so that the instructions, which are executed via the processor of the computer or other programmable data processing apparatus, generate a means for implementing the functions specified in the flowcharts and / or block diagrams. Figure 1 one or more flows and / or blocks Figure 1 means for carrying out the functions specified in the flowchart
[0145] These computer program instructions can also be stored in a computer readable memory that can direct a computer or other programmable data processing apparatus to work in a specific manner, so that the instructions stored in the computer readable memory produce a manufactured product including instruction means, which implement the functions specified in the flowcharts and / or block diagrams. Figure 1 one or more flows and / or blocks Figure 1 means for carrying out the functions specified in the flowchart
[0146] These computer program instructions can also be loaded onto a computer or other programmable data processing apparatus, so that a series of operation steps are performed on the computer or other programmable data processing apparatus to produce a computer implemented process, so that the instructions executed on the computer or other programmable data processing apparatus provide a means for implementing the functions specified in the flowcharts and / or block diagrams. Figure 1 one or more flows and / or blocksFigure 1 The functions described can be implemented in hardware, software, firmware or any combination thereof. If implemented in software, the functions can be stored as one or more instructions on a computer-readable medium, such as a non-transitory computer-readable medium. Any of the steps, operations, or processes described herein can be performed or implemented by a processor, such as a multi-core processor.
[0147] In a typical configuration, a computing device includes one or more processors (CPUs), input / output interfaces, network interfaces, and memory.
[0148] Memory can include non-persistent memory and / or persistent memory, both of which can be volatile and / or non-volatile. Non-persistent memory can include, for example, a random access memory (RAM), which can be a volatile memory unit commonly used as a primary storage for programs during their execution. Non-persistent memory can also include a cache, which is typically used to increase the performance of a storage device. Persistent memory can include, for example, a read-only memory (ROM), a flash memory, or a hard disk, which is a non-volatile memory unit that retains content even when power is turned off. Memory is an example of computer-readable media.
[0149] Computer-readable media includes permanent and non-permanent, removable and non-removable media implemented in any method or technology for storage of information such as computer-readable instructions, data structures, program modules or other data. Examples of computer storage media include, but are not limited to, phase-change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technology, compact disc read-only memory (CD-ROM), digital versatile disc (DVD), or other optical storage, magnetic cassette, magnetic tape disk storage or other magnetic storage devices, or any other non-transmission medium that can be used to store information accessible to a computing device. According to the definition herein, computer-readable media does not include transitory media such as modulated data signals and carriers.
[0150] It should also be noted that the terms "comprising", "containing", or any other variant thereof, are intended to cover a non-exclusive inclusion, such that a process, method, article or apparatus that comprises a list of elements does not include only those elements recited, but can also include other elements not expressly listed or inherent to such process, method, article or apparatus. Without more limitations, an element defined by the phrase "comprising a" does not exclude the presence of additional identical elements in the process, method, article or apparatus that includes the element.
[0151] Those skilled in the art will appreciate that embodiments of the present application can be supplied as a method, a system or a computer program product. Therefore, the present application can take the form of an entirely hardware embodiment, an entirely software embodiment or an embodiment combining software and hardware aspects. Moreover, the present application can take the form of a computer program product implemented on one or more computer-usable storage media (including, but not limited to, disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0152] The above merely provides an example of the present application, but is not intended to limit the present application. The present application can have various modifications and changes for those skilled in the art. Any modification, equivalent replacement, improvement, etc. within the spirit and principle of the present application shall be included in the scope of claims of the present application.
Claims
1. A file storage method characterized by comprising: The application comprises the following steps: determining target data to be uploaded to a cloud disk backup storage in an application to be backed up according to a pre-device backup period; receiving encrypted target data uploaded by the application to be backed up; determining at least two decryption modules from a decryption module pool to form an execution pool, and decrypting the encrypted target data through the execution pool to obtain decrypted data; determining a check value of the decrypted data corresponding to each decryption module in the execution pool according to the decrypted data, and determining target data according to the check value; updating a first file corresponding to the application to be backed up in the cloud disk according to the target data, and completing data backup storage of the application to be backed up.
2. The method of claim 1, wherein, The application further comprises the following steps: performing file segmentation on a first file and a second file of the application to be backed up according to a first segmentation method to obtain at least one first file segment corresponding to the first file and at least one second file segment corresponding to the second file; determining a first check value corresponding to each first file segment; determining a second check value corresponding to each second file segment; determining a second file segment corresponding to each first file segment in sequence; comparing the first check value of each first file segment with the second check value of the corresponding second file segment to determine a second file segment to be backed up that is modified within the backup period; determining target data according to the second file segment to be backed up.
3. The method of claim 2, wherein, The first check value comprises a first weak check value, a first strong check value and a first hash value. The second check value comprises a second weak check value, a second strong check value and a second hash value.
4. The method of claim 3, wherein, The comparison of the first check value of each first file segment with the second check value of the corresponding second file segment to determine a second file segment to be backed up that is modified within the backup period comprises the following steps: determining whether the first hash value of the first file segment is the same as the second hash value of the corresponding second file segment, and determining the second file segment to be a second file segment to be backed up when the determination result is no; determining whether the first weak check value of the first file segment is the same as the second weak check value of the corresponding second file segment when the determination result is yes, and determining the second file segment to be a second file segment to be backed up when the determination result is no; determining whether the first strong check value of the first file segment is the same as the second strong check value of the corresponding second file segment when the determination result is yes, and determining the second file segment to be a second file segment to be backed up when the determination result is no.
5. The method of claim 1, wherein, The determination of at least two decryption modules from the decryption module pool to form an execution pool comprises the following steps: determining a confidence degree corresponding to each decryption module in the decryption module pool; determining a target decryption module with a confidence degree greater than a first preset threshold according to the determined confidence degree; determining data heterogeneity between any two target decryption modules; forming an execution pool according to target decryption modules with data heterogeneity greater than a second preset threshold.
6. The method of claim 1, wherein, The receiving the encrypted target data uploaded by the application to be backed up further comprises: Obtaining network traffic characteristics of the cloud disk; According to the pre-trained network security monitoring model, the network traffic characteristics are identified to determine the network security monitoring result; When the network security monitoring result obtained by the network security monitoring model is safe, the first file corresponding to the application to be backed up in the cloud disk is updated according to the target data, and the data backup storage of the application to be backed up is completed.
7. The method of claim 6, wherein, The network security monitoring model is pre-trained, specifically including: According to the convolutional neural network, an original network security monitoring model is constructed; Randomly initialize the network parameters of the original network security monitoring model to obtain the network parameter vector of the original network security monitoring model; According to the network parameter vector, a network parameter population is generated; The network security monitoring model is trained according to the network parameter population.
8. The method of claim 7, wherein, The network security monitoring model is trained according to the network parameter population, specifically including: Obtaining the fitness value of each network parameter vector in the network parameter population; According to the order from large to small of the fitness value, at least two network parameter vectors are selected from the network parameter population as the optimal solution population, and the remaining network parameter vectors in the network parameter population are selected as the updating population; The network parameter vector with the maximum fitness value in the optimal solution population is obtained as the global optimal value; The historical optimal value of each network parameter vector in the updating population is obtained; According to the global optimal value and the historical optimal value, the nonlinear optimization method is used to update each network parameter vector in the updating population to obtain the trained network security monitoring model.
9. The method of claim 6, wherein, According to the target data, the first file corresponding to the application to be backed up in the cloud disk is updated, and the data backup storage of the application to be backed up is completed, specifically including: According to the secret sharing strategy, the target data is encrypted to obtain encrypted target data; According to the encrypted target data, the first file corresponding to the application to be backed up in the cloud disk is updated, and the data backup storage of the application to be backed up is completed.
10. The method of claim 9, wherein, According to the secret sharing strategy, the target data is encrypted to obtain encrypted target data, specifically including: According to the randomly generated prime number, the encryption public key is determined; According to the encryption public key, the target data is encrypted to obtain the encryption target data corresponding to the target data and at least two secret values; According to the number of secret values, the same number of physical servers are determined, and the secret values are stored in the physical servers.
Citation Information
Patent Citations
Protective method and apparatus for electronic device
CN107273769A
Encrypted data consistency checking method and device, computer equipment and storage medium
CN110069939A