A shared file transparent encryption method

By establishing a virtual data layer for shared files and dividing risk levels, the problems of security risks and log audit risks during data transmission are solved, and efficient and secure data transmission and auditing are achieved.

CN119232429BActive Publication Date: 2025-06-06BEIJING SHENZHOU ANFU TECH CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202411160525.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-08-22
Publication Date
2025-06-06
Estimated Expiration
2044-08-22

AI Technical Summary

Technical Problem

In the prior art, the stay during data transmission leads to an increase in data security risks, and log audit risks are prone to abnormal access during audit updates.

Method used

By creating virtual data on shared files and encrypting the actual data for the first time, the virtual data layer isolates the actual data from the operating environment. The risk level is divided according to the number of accesses to virtual data, the decryption area of ​​encrypted data is determined, the abnormal data is filtered, and the security risks and log audit risks are adjusted.

Benefits of technology

It has achieved the reduction of the risk of data leakage or abuse, reduced security risks during data transmission, reduced log audit risks, and ensured the security and integrity of data.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119232429B_ABST
    Figure CN119232429B_ABST
Patent Text Reader

Abstract

The present invention relates to the technical field of transparent file encryption, and in particular to a method for transparent shared file encryption, comprising: encrypting and saving basic data in a shared file, and establishing virtual data for the basic data; identifying data to be encrypted in the virtual data, and dividing the risk level of the data to be encrypted; determining the decryption area of ​​the data to be encrypted; screening abnormal data based on feature points in the data to be encrypted; transmitting the screened data to be encrypted; determining a transmission label in the transmission process; judging whether the security risk meets the requirements according to the packet loss rate of the data to be encrypted; if the security risk does not meet the requirements, adjusting the number of data packets in transmission, or adjusting the update and training ratio of the basic data log according to the number of abnormal accesses to the audited log. The present invention achieves the reduction of data security risks and log audit risks.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of transparent file encryption, and in particular to a shared file transparent encryption method. Background Art

[0002] In the prior art, transparent encryption technology refers to encrypting data without changing the user's operating habits, so that the data is always in an encrypted state during transmission and storage, thereby ensuring data security. It generally adopts cryptographic standards issued by the National Cryptography Administration, which are designed to ensure the security of information transmission and storage, symmetric encryption algorithms such as SM1 and SM4, which are used for data encryption and decryption to ensure the confidentiality of data during transmission and storage; such as SM2 asymmetric encryption algorithm, which is usually used for key exchange and digital signature to ensure the security of data exchange and data integrity. At the same time, the processes of key generation, storage, distribution and destruction also need to be strictly controlled. By controlling file access rights, it is ensured that only authorized users can access and operate encrypted files. During file access, the system will automatically perform encryption and decryption operations without manual intervention.

[0003] Chinese Patent Publication No.: CN115550058A discloses a shared file transparent encryption method and system, including several user terminals, several user USB-KEYs, encryption and decryption auxiliary modules, hook programs and certificate management platforms; the certificate management platform is used to store the certificate list of authorized users, each certificate contains a user USB-KEY public key; each user USB-KEY contains a user USB-KEY private key, each user USB-KEY public key and the corresponding user USB-KEY private key cooperate with each other to form a user USB-KEY public / private key pair; the certificate management platform is also provided with a key management function module, and the key management function module is used to generate a user USB-KEY public / private key pair; each of the user terminals is respectively provided with a hook program, an application, an operating system, an encryption and decryption auxiliary module and a storage auxiliary module; the hook program is used to monitor the application execution action of the user terminal, and suspend it when the application executes the save and / or read action, so as to give priority to the execution action of the hook program action; the execution actions of the hook program include public key query, certificate query, public key asymmetric encryption and private key asymmetric decryption, symmetric encryption, and symmetric decryption through the user USB-KEY; the hook program is also used to asymmetrically encrypt and decrypt the symmetric key of the document through the encryption and decryption auxiliary module, and perform SM4 symmetric encryption and decryption on the original document through the symmetric key; the application is used to create, save and / or read the original document; the operating system is used to support the normal operation of the user terminal; the storage auxiliary module is used to store operating system functions; each user USB-KEY is provided with an asymmetric encryption interface, an asymmetric decryption interface, a symmetric encryption interface, a symmetric decryption interface, a random number generator and a USB-KEY container, the asymmetric encryption interface is used for asymmetric encryption, the asymmetric decryption interface is used for asymmetric decryption, the symmetric encryption interface is used for symmetric encryption, the symmetric decryption interface is used for symmetric decryption, the random number generator is used to generate random numbers, and the USB-KEY container is used to store the user USB-KEY public / private key pair and the user CA certificate. It can be seen that the shared file transparent encryption method and system have the problems of increased data security risk due to the pause in the data transmission process and increased log audit risk due to abnormal access during the audit update of the log. Summary of the invention

[0004] To this end, the present invention provides a shared file transparent encryption method to overcome the problems in the prior art of increased data security risk due to retention during data transmission and increased log audit risk due to abnormal access during log audit updates.

[0005] To achieve the above object, the present invention provides a shared file transparent encryption method, comprising:

[0006] Performing basic encryption and storage on basic data in a shared file, and duplicating the basic data to form virtual data;

[0007] Classifying the risk level of the virtual data according to the number of times the virtual data is accessed;

[0008] determining a decryption area for encrypted data according to the risk level of the virtual data;

[0009] Screening abnormal data based on feature points in the virtual data;

[0010] Encrypting the filtered virtual data to generate a key, and using the key to convert the filtered virtual data into the encrypted data;

[0011] transmitting the encrypted data to a target user;

[0012] Determine the transmission label of the transmission process based on the distance between the user's operation and the risk point;

[0013] Determining whether the security risk meets the requirements according to the packet loss rate of the encrypted data;

[0014] If the security risk does not meet the requirements, the number of data packets in transmission is adjusted, or the update and training ratio of the basic data log is adjusted according to the number of abnormal accesses to the audited log;

[0015] The encrypted data received by the target user is decrypted into the decryption area.

[0016] Furthermore, classifying the risk level of the virtual data includes:

[0017] Obtaining the number of accesses to the virtual data;

[0018] The risk levels of the virtual data are sorted in ascending order of the number of accesses to the virtual data.

[0019] Further, determining the decryption area of ​​the encrypted data according to the risk level of the virtual data includes:

[0020] Dividing the storage space of the decryption area into a plurality of unit storage spaces;

[0021] Determining a risk level of the unit storage space according to the number of accesses per unit time to the unit storage space;

[0022] Decrypting the encrypted data into corresponding unit storage spaces in order of risk level from high to low;

[0023] The risk level of the virtual data is negatively correlated with the risk level of the corresponding storage space.

[0024] Furthermore, determining the transmission label of the transmission process based on the operation distance between the user's operation and the risk point includes:

[0025] Collect the user's target operation location of the data to be transmitted and the risk point location in the data to be transmitted;

[0026] Calculating the operation distance between the user's operation and the risk point according to the number of clicks from the target operation position to the risk point position;

[0027] A transmission tag for the data to be transmitted is generated according to the operation distance and the number of risk points of the data to be transmitted.

[0028] Furthermore, the operation distance between the user's operation and the risk point is the number of file clicks required to click from the target operation position to the risk point position.

[0029] Further, judging whether the security risk meets the requirement according to the packet loss rate of the encrypted data includes:

[0030] Obtaining the packet loss data amount of the encrypted data and the total data amount of the data to be encrypted to calculate the packet loss rate of the encrypted data;

[0031] Comparing the packet loss rate of the encrypted data with a preset first packet loss rate and a preset second packet loss rate respectively;

[0032] If the packet loss rate of the encrypted data is greater than a preset second packet loss rate, it is determined whether the security risk meets the requirements.

[0033] Further, adjusting the number of data packets in transmission includes:

[0034] Comparing the packet loss rate of the encrypted data with the preset second packet loss rate;

[0035] If the packet loss rate of the encrypted data is greater than the preset second packet loss rate, the number of the data packets in the transmission is adjusted.

[0036] Furthermore, the number of data packets in transmission is positively correlated with the packet loss rate.

[0037] Further, adjusting the update and training ratio of the basic data log according to the number of abnormal accesses to the audited log includes:

[0038] Comparing the packet loss rate with the preset first packet loss rate and the preset second packet loss rate respectively;

[0039] If the packet loss rate is greater than the preset first packet loss rate and less than or equal to the preset second packet loss rate, it is preliminarily determined that the log audit risk does not meet the requirements, and the number of abnormal accesses to the audited logs is obtained;

[0040] Comparing the number of abnormal accesses of the log with a preset number of abnormal accesses;

[0041] If the number of abnormal accesses to the log is greater than or equal to the preset number of abnormal accesses, it is determined that the log audit risk does not meet the requirements for a second time, and the update and training ratio of the log of the basic data is adjusted.

[0042] Furthermore, the update and training ratio of the basic data log is negatively correlated with the number of abnormal accesses to the log;

[0043] The calculation formula for the update and training ratio of the log is:

[0044]

[0045] Wherein, n is the update and training ratio of the log, N is the data volume of the log update, and T is the data volume of the log training.

[0046] Compared with the prior art, the beneficial effect of the present invention lies in that the method of the present invention establishes virtual data for shared files and encrypts the actual data for the first time. The virtual data layer isolates the actual data from the operating environment. Even if the virtual environment is attacked or fails, it will not directly affect the security of the actual data. Through the virtual data layer, it is easier to implement fine-grained access control policies to ensure that only authorized users can access and modify data, and directly manage the data copies of shared files to avoid repeated storage of the same data between different users or systems, thereby saving storage space; by dividing the data into risk levels and determining the decryption area, the data that needs to be protected can be clearly identified so that more stringent security measures can be taken, thereby reducing data security risks. The risk of leakage or abuse; by screening abnormal data, it may lead to misjudgment or misleading conclusions, which will affect the data quality. By screening abnormal data, the risk of affecting the accuracy and reliability of data analysis results can be reduced; by determining whether the security risk meets the requirements, since the stay during the data transmission process will lead to the risk of attack, by increasing the number of data packets, thereby reducing the size of the transmitted data packets, and transparently encrypting them a second time during the transmission process, the residence time is reduced, thereby reducing the risk of attack and reducing security risks. Although the underlying data of the shared file is encrypted for the first time, the security risk increases during the log audit update process. By adjusting the log update and training ratio, the log audit risk is reduced.

[0047] Furthermore, the method of the present invention sets a preset risk level. Since data with fewer access times is trained less times, it has a higher risk when attacked. By establishing risk levels, it helps to quickly locate the scope and extent of affected data when data leakage or other security incidents occur. Since data with higher risk levels is more likely to be compromised, transferring it to a specific decryption area helps to enhance the security of the data's peripheral storage area, thereby further improving data security.

[0048] Furthermore, the method of the present invention generates a specific transmission tag. Since external risks may launch decryption attacks on data during the transmission process, resulting in data loss or cracking, or there may be multiple access requests on the user side leading to confusion between data packets, confusion between data packets can be effectively avoided by setting a unique tag, thereby improving the accuracy of data transmission.

[0049] Furthermore, the method of the present invention sets a preset second packet loss rate. Since data loss will lead to a decline in data quality, which will affect the integrity of the data and thus increase the data security risk, by increasing the number of data packets in transmission, the risk of data packets being tampered with, lost or reorganized incorrectly during transmission is reduced, thereby further improving the data security risk.

[0050] Furthermore, the method of the present invention sets a preset number of abnormal accesses. Since the audit and log contents need to be updated according to new situations during the log audit update process, there is an update risk. By reducing the update and training ratio of the log, the log audit risk is reduced. BRIEF DESCRIPTION OF THE DRAWINGS

[0051] Figure 1 This is an overall flow chart of the shared file transparent encryption method according to an embodiment of the present invention;

[0052] Figure 2 A specific flow chart of a transmission tag for determining a transmission process of a shared file transparent encryption method according to an embodiment of the present invention;

[0053] Figure 3 A specific flow chart of adjusting the update and training ratio of a log in a shared file transparent encryption method according to an embodiment of the present invention;

[0054] Figure 4 The figure is a logic flow chart of a shared file transparent encryption method according to an embodiment of the present invention. DETAILED DESCRIPTION

[0055] In order to make the objects and advantages of the present invention more clearly understood, the present invention is further described below in conjunction with embodiments; it should be understood that the specific embodiments described herein are only used to explain the present invention and are not used to limit the present invention.

[0056] The preferred embodiments of the present invention are described below with reference to the accompanying drawings. It should be understood by those skilled in the art that these embodiments are only used to explain the technical principles of the present invention and are not intended to limit the protection scope of the present invention.

[0057] It should be noted that, in the description of the present invention, terms such as "up", "down", "left", "right", "inside" and "outside" indicating directions or positional relationships are based on the directions or positional relationships shown in the drawings. This is merely for the convenience of description and does not indicate or imply that the device or element must have a specific orientation, be constructed and operated in a specific orientation. Therefore, it cannot be understood as a limitation on the present invention.

[0058] In addition, it should be noted that in the description of the present invention, unless otherwise clearly specified and limited, the terms "installed", "connected", and "connected" should be understood in a broad sense, for example, it can be a fixed connection, a detachable connection, or an integral connection; it can be a mechanical connection or an electrical connection; it can be a direct connection, or it can be indirectly connected through an intermediate medium, or it can be the internal communication of two components. For those skilled in the art, the specific meanings of the above terms in the present invention can be understood according to specific circumstances.

[0059] See also Figure 1 , Figure 2 , Figure 3 as well as Figure 4 As shown, they are respectively an overall flow chart of a shared file transparent encryption method according to an embodiment of the present invention, a specific flow chart of determining a transmission tag during a transmission process, a specific flow chart of adjusting the update and training ratio of a log, and a logic flow chart. A shared file transparent encryption method according to the present invention comprises:

[0060] Performing basic encryption and storage on basic data in a shared file, and duplicating the basic data to form virtual data;

[0061] Classifying the risk level of the virtual data according to the number of times the virtual data is accessed;

[0062] determining a decryption area for encrypted data according to the risk level of the virtual data;

[0063] Screening abnormal data based on feature points in the virtual data;

[0064] Encrypting the filtered virtual data to generate a key, and using the key to convert the filtered virtual data into the encrypted data;

[0065] transmitting the encrypted data to a target user;

[0066] Determine the transmission label of the transmission process based on the distance between the user's operation and the risk point;

[0067] Determining whether the security risk meets the requirements according to the packet loss rate of the encrypted data;

[0068] If the security risk does not meet the requirements, the number of data packets in transmission is adjusted, or the update and training ratio of the basic data log is adjusted according to the number of abnormal accesses to the audited log;

[0069] The encrypted data received by the target user is decrypted into the decryption area.

[0070] Specifically, the basic data refers to the data in the shared files that need to be saved and encrypted, such as company financial information and corporate confidential information.

[0071] Specifically, both the basic encryption and encryption processes generate keys, use the keys to convert basic data into encrypted data, and automatically decrypt during the log audit process. For example, the AES or RSA algorithm is used to generate keys to convert file plaintext into ciphertext and save it as an encrypted file. When someone tries to access an encrypted file, if the access request permissions meet the requirements, the decryption key is obtained to decrypt the encrypted file and restore the ciphertext to plaintext.

[0072] Specifically, virtual data is virtual data created by copying basic data.

[0073] Specifically, the decryption area is the space in the memory where the decrypted data is stored or the storage space occupied by the decrypted data.

[0074] Specifically, the characteristic points of the data to be encrypted include data change rate, data source, and data usage frequency.

[0075] Specifically, abnormal data refers to data that does not conform to the standard data format and standard data operation, including numerical abnormal data and behavioral pattern abnormal data. For example, a preferred embodiment of numerical abnormality is data that is more than three times the standard deviation away from the mean; a preferred embodiment of behavioral pattern abnormality is data where the number of clicks or sliding operations of a user exceeds the historical average; data is of low quality due to incorrect or incomplete entry, such as missing data or duplicate data records.

[0076] Specifically, the packet loss rate of the data to be encrypted is the ratio of the amount of data lost during the data transmission process to the total amount of data transmitted.

[0077] Specifically, the number of abnormal accesses to the audited logs is the number of unauthorized accesses.

[0078] In practice, the method of the present invention creates virtual data for a shared file and performs a first encryption on the actual data. The virtual data layer isolates the actual data from the operating environment. Even if the virtual environment is attacked or fails, it will not directly affect the security of the actual data. Through the virtual data layer, it is easier to implement fine-grained access control policies to ensure that only authorized users can access and modify data, and directly manage data copies of shared files to avoid repeated storage of the same data between different users or systems, thereby saving storage space; by dividing the data into risk levels and determining the decryption area, the data that needs to be protected can be clearly identified so that more stringent security measures can be taken, thereby reducing the risk of data leakage or abuse. Risks: Screening of abnormal data may lead to misjudgment or misleading conclusions, which will affect data quality. Screening of abnormal data can reduce the risk of affecting the accuracy and reliability of data analysis results. By determining whether the security risk meets the requirements, since the stay during the data transmission process may lead to the risk of attack, by increasing the number of data packets, thereby reducing the size of the transmitted data packets, and transparently encrypting them a second time during the transmission process, the stay time is reduced, thereby reducing the risk of attack and reducing security risks. Although the underlying data of the shared file is encrypted for the first time, the security risk increases during the log audit update process. By adjusting the log update and training ratio, the log audit risk is reduced.

[0079] Specifically, the risk level of the virtual data is classified as follows:

[0080] Obtaining the number of accesses to the virtual data;

[0081] The risk levels of the virtual data are sorted in ascending order of the number of accesses to the virtual data.

[0082] Specifically, determining the decryption area of ​​the encrypted data according to the risk level of the virtual data includes:

[0083] Dividing the storage space of the decryption area into a plurality of unit storage spaces;

[0084] Determining a risk level of the unit storage space according to the number of accesses per unit time to the unit storage space;

[0085] Decrypting the encrypted data into corresponding unit storage spaces in order of risk level from high to low;

[0086] The risk level of the virtual data is negatively correlated with the risk level of the corresponding storage space.

[0087] In implementation, the method of the present invention sets a preset risk level. Since data with fewer access times is trained less times, it has a higher risk when attacked. By establishing risk levels, it helps to quickly locate the scope and extent of affected data when data leakage or other security incidents occur. Since data with higher risk levels is more likely to be compromised, transferring it to a specific decryption area helps to enhance the security of the data's peripheral storage area and further improves data security.

[0088] Specifically, the transmission tags of the transmission process determined based on the distance between the user's operation and the risk point include:

[0089] Collect the user's target operation location of the data to be transmitted and the risk point location in the data to be transmitted;

[0090] Calculating the operation distance between the user's operation and the risk point according to the number of clicks from the target operation position to the risk point position;

[0091] A transmission tag for the data to be transmitted is generated according to the operation distance and the number of risk points of the data to be transmitted.

[0092] Specifically, the operation distance is the number of file clicks required to click from the target operation position to the risk point position.

[0093] In implementation, the method of the present invention generates a specific transmission tag. Since external risks may decrypt the data during the transmission process, resulting in data loss or cracking, or multiple access requests on the user side may cause confusion between data packets, by setting a unique tag, confusion between data packets can be effectively avoided, thereby improving the accuracy of data transmission.

[0094] Specifically, judging whether the security risk meets the requirements according to the packet loss rate of the encrypted data includes:

[0095] Obtaining the packet loss data amount of the encrypted data and the total data amount of the data to be encrypted to calculate the packet loss rate of the encrypted data;

[0096] Comparing the packet loss rate of the encrypted data with a preset first packet loss rate and a preset second packet loss rate respectively;

[0097] If the packet loss rate of the encrypted data is greater than a preset second packet loss rate, it is determined whether the security risk meets the requirements.

[0098] In implementation, the general value range of the preset first packet loss rate is [2%, 4%], and the general value range of the preset second packet loss rate is [5%, 8%].

[0099] Preferably, the preferred embodiment of the preset first packet loss rate is 3%, and the preferred embodiment of the preset second packet loss rate is 6%.

[0100] Specifically, adjusting the number of packets in transmission includes:

[0101] Comparing the packet loss rate of the encrypted data with the preset second packet loss rate;

[0102] If the packet loss rate of the encrypted data is greater than the preset second packet loss rate, the number of the data packets in the transmission is adjusted.

[0103] Specifically, the number of data packets in transmission is positively correlated with the packet loss rate.

[0104] Specifically, when the difference between the packet loss rate of the data to be encrypted and the preset second packet loss rate is within 1%, the number of data packets in transmission increases by 10; when the difference between the packet loss rate of the data to be encrypted and the preset second packet loss rate exceeds 1%, the number of data packets in transmission increases by 8 for every 0.5% increase. For example, when the packet loss rate of the data to be encrypted is 8%, the number of data packets currently in transmission is 60, and the number of data packets in transmission increases to 60+10+8×2=86.

[0105] In implementation, the method of the present invention sets a preset second packet loss rate. Since data loss will lead to a decline in data quality, which will affect the integrity of the data and thus increase the data security risk, the method increases the number of data packets in transmission, thereby reducing the risk of data packets being tampered with, lost or reorganized incorrectly during transmission, thereby further increasing the data security risk.

[0106] Specifically, adjusting the update and training ratio of the basic data log according to the number of abnormal accesses to the audited log includes:

[0107] Comparing the packet loss rate with the preset first packet loss rate and the preset second packet loss rate respectively;

[0108] If the packet loss rate is greater than the preset first packet loss rate and less than or equal to the preset second packet loss rate, it is preliminarily determined that the log audit risk does not meet the requirements, and the number of abnormal accesses to the audited logs is obtained;

[0109] Comparing the number of abnormal accesses of the log with a preset number of abnormal accesses;

[0110] If the number of abnormal accesses to the log is greater than or equal to the preset number of abnormal accesses, it is determined that the log audit risk does not meet the requirements for a second time, and the update and training ratio of the log of the basic data is adjusted.

[0111] Specifically, the update and training ratio of the basic data log is negatively correlated with the number of abnormal accesses to the log;

[0112] The calculation formula for the update and training ratio of the log is:

[0113]

[0114] Wherein, n is the update and training ratio of the log, N is the data volume of the log update, and T is the data volume of the log training.

[0115] Specifically, log updating is to modify, add or delete log files, and log training is to clean log data, format log entries, and extract key log fields.

[0116] In implementation, the general value range of the preset abnormal access times is [80 times / minute, 100 times / minute].

[0117] Preferably, the preferred embodiment of the preset abnormal access number is 85 times / minute.

[0118] Specifically, when the difference between the number of abnormal accesses to the log and the preset number of abnormal accesses is within 10 times / minute, the update and training ratio of the log is reduced to 0.9 times of the original; when the difference between the number of abnormal accesses to the log and the preset number of abnormal accesses exceeds 10 times / minute, the update and training ratio of the log is reduced by 2% for every 10 times / minute. For example, the number of abnormal accesses to the log is 115 times / minute, the current update and training ratio of the log is 25%, and the update and training ratio of the log is reduced to 25%×0.9+2%×2=18.5%.

[0119] In implementation, the method of the present invention sets a preset number of abnormal accesses. Since the audit and log contents need to be updated according to new situations during the log audit update process, there is an update risk. By reducing the update and training ratio of the log, the log audit risk is reduced.

[0120] So far, the technical solutions of the present invention have been described in conjunction with the preferred embodiments shown in the accompanying drawings. However, it is easy for those skilled in the art to understand that the protection scope of the present invention is obviously not limited to these specific embodiments. Without departing from the principle of the present invention, those skilled in the art can make equivalent changes or substitutions to the relevant technical features, and the technical solutions after these changes or substitutions will fall within the protection scope of the present invention.

Claims

1. A shared file transparent encryption method, characterized in that: include: Performing basic encryption and storage on basic data in a shared file, and duplicating the basic data to form virtual data; Classifying the risk level of the virtual data according to the number of times the virtual data is accessed; determining a decryption area for encrypted data according to the risk level of the virtual data; Screening abnormal data based on feature points in the virtual data; Encrypting the filtered virtual data to generate a key, and using the key to convert the filtered virtual data into the encrypted data; transmitting the encrypted data to a target user; Determine the transmission label of the transmission process based on the distance between the user's operation and the risk point; Determining whether the security risk meets the requirements according to the packet loss rate of the encrypted data; If the security risk does not meet the requirements, the number of data packets in transmission is adjusted, or the update and training ratio of the basic data log is adjusted according to the number of abnormal accesses to the audited log; decrypting the encrypted data received by the target user into the decryption area; The operation distance between the user's operation and the risk point is the number of file clicks required from the target operation position to the risk point position.

2. The shared file transparent encryption method according to claim 1, characterized in that: Classifying the risk levels of the virtual data includes: Obtaining the number of accesses to the virtual data; The risk levels of the virtual data are sorted in ascending order of the number of accesses to the virtual data.

3. The shared file transparent encryption method according to claim 2, characterized in that: Determining the decryption area of ​​the encrypted data according to the risk level of the virtual data includes: Dividing the storage space of the decryption area into a plurality of unit storage spaces; Determining a risk level of the unit storage space according to the number of accesses per unit time to the unit storage space; Decrypting the encrypted data into corresponding unit storage spaces in order of risk level from high to low; The risk level of the virtual data is negatively correlated with the risk level of the corresponding storage space.

4. The shared file transparent encryption method according to claim 3, characterized in that: The transmission tags of the transmission process determined based on the distance between the user's operation and the risk point include: Collect the user's target operation location of the data to be transmitted and the risk point location in the data to be transmitted; Calculating the operation distance between the user's operation and the risk point according to the number of clicks from the target operation position to the risk point position; A transmission tag for the data to be transmitted is generated according to the operation distance and the number of risk points of the data to be transmitted.

5. The shared file transparent encryption method according to claim 4, characterized in that: Determining whether the security risk meets the requirements based on the packet loss rate of the encrypted data includes: Obtaining the packet loss data amount of the encrypted data and the total data amount of the data to be encrypted to calculate the packet loss rate of the encrypted data; Comparing the packet loss rate of the encrypted data with a preset first packet loss rate and a preset second packet loss rate respectively; If the packet loss rate of the encrypted data is greater than a preset second packet loss rate, it is determined whether the security risk meets the requirements.

6. The shared file transparent encryption method according to claim 5, characterized in that: Adjusting the number of packets in flight involves: Comparing the packet loss rate of the encrypted data with the preset second packet loss rate; If the packet loss rate of the encrypted data is greater than the preset second packet loss rate, the number of the data packets in the transmission is adjusted.

7. The shared file transparent encryption method according to claim 6, characterized in that: The number of data packets in transmission is positively correlated with the packet loss rate.

8. The shared file transparent encryption method according to claim 7, characterized in that: Adjusting the update and training ratio of the basic data log according to the number of abnormal accesses to the audited log includes: Comparing the packet loss rate with the preset first packet loss rate and the preset second packet loss rate respectively; If the packet loss rate is greater than the preset first packet loss rate and less than or equal to the preset second packet loss rate, it is preliminarily determined that the log audit risk does not meet the requirements, and the number of abnormal accesses to the audited logs is obtained; Comparing the number of abnormal accesses of the log with a preset number of abnormal accesses; If the number of abnormal accesses to the log is greater than or equal to the preset number of abnormal accesses, it is determined that the log audit risk does not meet the requirements for a second time, and the update and training ratio of the log of the basic data is adjusted.

9. The shared file transparent encryption method according to claim 8, characterized in that: The update and training ratio of the basic data log is negatively correlated with the number of abnormal accesses to the log; The calculation formula for the update and training ratio of the log is: Wherein, n is the update and training ratio of the log, N is the data volume of the log update, and T is the data volume of the log training.

Citation Information

Patent Citations

  • Shared file transparent encryption method and system

    CN115550058A

  • Data management method and device, electronic equipment and storage medium

    CN110704691A

  • Virtual machine-based trusted execution environment

    US11288377B1