Distributed file encryption system based on domestic OS
By introducing dynamic encryption management and homomorphic encryption technology into distributed file encryption systems, combined with distributed GPU acceleration technology, the problem that existing systems cannot dynamically adjust encryption policies and support complex queries is solved, and efficient and secure data processing and storage are achieved.
Patent Information
- Application Number
- CN202411764360.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-04
- Publication Date
- 2025-05-23
- Estimated Expiration
- 2044-12-04
AI Technical Summary
Existing distributed file encryption systems cannot dynamically adjust encryption policies to adapt to different access modes and frequencies, resulting in inefficiency, unable to flexibly cope with the security needs of high-frequency and low-frequency data access, and lack the ability to support complex queries in an encrypted state.
The distributed file encryption system based on domestic OS is adopted, and file access requests are captured in real time through the file monitoring module. The dynamic encryption management module adjusts encryption parameters according to the access mode. The homomorphic encryption module performs full or semi-homomorphic encryption processing, and optimizes the computing speed through the performance optimization module using distributed GPU acceleration technology.
It realizes dynamic adjustment of encryption policies to adapt to different access modes and frequencies, improves data security and processing efficiency, supports complex queries in the encrypted state, reduces security risks in the decryption process, and improves the system's response speed and data processing capabilities.
Smart Images

Figure CN119272310B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of file encryption, and in particular to a distributed file encryption system based on a domestic OS. Background Art
[0002] File encryption technology involves the use of encryption algorithms to protect electronic files from unauthorized access and reading. In this field, data is converted into an encrypted format when stored or transmitted that can only be read by people with decryption keys. It is widely used to protect sensitive information such as personal data, trade secrets and government secrets. File encryption can be static, acting directly on files stored on the hard disk, or dynamic, encrypting data transmitted over the network.
[0003] Among them, the distributed file encryption system is designed to implement encryption measures in a distributed computing environment. The system stores files on multiple network-connected nodes and encrypts them before they are stored or transmitted to these nodes. Its main purpose is to provide a secure method to manage and store large amounts of data distributed in different physical locations. Its implementation can significantly improve data security and prevent data leakage, while supporting flexible data access and backup options.
[0004] Existing technologies fail to optimize for different file access requirements, resulting in rigid encryption strategies that cannot be dynamically adjusted to adapt to changing access patterns and frequencies. This static encryption processing method is inefficient and consumes a lot of computing resources when processing large-scale distributed data, especially in data storage and access in multiple physical locations. In particular, when the system adopts a single encryption standard, it cannot flexibly respond to the different security requirements of high-frequency and low-frequency data access. In addition, it lacks the ability to support complex queries while the data is encrypted. Traditional encryption technology requires decryption before data processing, increasing the risk of data being intercepted or leaked during processing. Summary of the invention
[0005] The purpose of the present invention is to solve the shortcomings in the prior art and to propose a distributed file encryption system based on a domestic OS.
[0006] In order to achieve the above purpose, the present invention adopts the following technical solution: a distributed file encryption system based on a domestic OS, the system comprising:
[0007] The file monitoring module is based on the OS system, captures file access requests in real time, records the timestamp of each access, determines the average time interval and frequency of access, and judges the access frequency of files based on the access mode to obtain access mode classification data;
[0008] The dynamic encryption management module adopts AES-128 for high-frequency access files and AES-256 for low-frequency and sensitive files based on the access mode classification data, updates encryption parameters in real time to match differentiated security requirements, and records the adjustment process of each encryption parameter to generate a parameter adjustment log;
[0009] The homomorphic encryption module encrypts the file based on the parameter adjustment log through a fully homomorphic or semi-homomorphic encryption algorithm, verifies the feasibility of querying and analyzing the file in an encrypted state, and obtains a homomorphic operation log;
[0010] The performance optimization module identifies the performance bottleneck in the homomorphic encryption operation according to the homomorphic operation log, optimizes the computing speed by using distributed GPU acceleration technology, and reallocates the operating system resources to optimize the operating efficiency, thereby obtaining a performance efficiency optimization result.
[0011] The present invention is improved in that the steps of determining the average time interval and frequency are specifically as follows:
[0012] Based on the OS system, by monitoring file access events, the timestamp of each access is captured and recorded in real time to form a timestamp list;
[0013] Based on the timestamp list, calculating the difference between two adjacent timestamps to obtain a time interval list;
[0014] Based on the list of time intervals, the formula is used:
[0015]
[0016] and
[0017]
[0018] Calculate the average time interval and access frequency ,in, and Respectively represent and Timestamp, is the total number of events.
[0019] The present invention is improved in that the step of obtaining the access mode classification data is specifically as follows:
[0020] Analyze the file access pattern based on the average time interval and frequency, determine the file access frequency level, and obtain file frequency level information;
[0021] Based on the file frequency information, the formula is used:
[0022]
[0023] Calculating Categorical Values , the files are divided into high-frequency and low-frequency access files according to the classification value, and the classified access patterns are obtained, where is the file access frequency, For the duration of the visit, is the access time interval, To adjust the parameters;
[0024] Based on the classified access patterns, access characteristic indicators of each type of file are calculated, and access characteristics of files of different categories are analyzed to obtain access pattern classification data.
[0025] The present invention is improved in that the step of updating the encryption parameters in real time is specifically as follows:
[0026] Based on the access pattern classification data, determine the access frequency and sensitivity level of each file, use AES-128 encryption for high-frequency access files, use AES-256 encryption for low-frequency and sensitive files, and generate a pre-encryption strategy list;
[0027] Based on the pre-encryption strategy list, according to the current network environment and security, the formula is adopted:
[0028]
[0029] Update encryption parameters , matching differentiated security requirements, where Represents the file access frequency, Represents the sensitivity of the file. and is an adjustment factor based on the current security level.
[0030] The present invention is improved in that the step of obtaining the parameter adjustment log is specifically as follows:
[0031] Monitor each file encryption parameter adjustment event, record the file identifier, current encryption algorithm, parameters before change, parameters after change, and change time, using the formula:
[0032]
[0033] Calculate the parameter change information and obtain a preliminary change record with a mark, where: is the change in encryption parameters, and Indicates the encryption parameter values before and after the change. is the weight parameter for the target security requirement;
[0034] According to the marked preliminary change record, each record information, including the file identifier, the current encryption algorithm, the parameters before the change, the parameters after the change and the change time, is integrated and filed into the parameter adjustment log.
[0035] The present invention is improved in that the step of encrypting the file is specifically as follows:
[0036] Based on the parameter adjustment log, security requirements and encryption parameters of the file are extracted from the log, including file access frequency, user identity and access type, a fully homomorphic or semi-homomorphic encryption algorithm is adopted, a key length and an encryption mode are set, and encryption algorithm decision information for each file is generated;
[0037] Based on the encryption algorithm decision information, the formula is adopted:
[0038]
[0039] Encrypt the file to obtain the encrypted file data ,in, Represents the data content of the file. is the selected encryption key, and They are weight coefficients adjusted based on file sensitivity;
[0040] The encrypted file data is stored, and key information in the encryption process is recorded, including the key, encryption algorithm and encryption execution time, to obtain an encryption activity record.
[0041] The present invention is improved in that the steps of obtaining the homomorphic operation log are specifically as follows:
[0042] Continuously track the query and analysis activities of encrypted files, record the operation type, time and participant information, and obtain file operation information;
[0043] Based on the file operation information, the collected data is processed using the formula:
[0044]
[0045] Get the homomorphic operation log, where is the score of the operation log, Indicates the operation time. Indicates the operation type. Indicates the result of an operation.
[0046] The present invention is improved in that the steps of obtaining the performance efficiency optimization result are specifically as follows:
[0047] According to the homomorphic operation log, collect data related to the performance bottleneck, including operation duration and resource usage, and generate preliminary performance analysis results based on the collected data;
[0048] Based on the preliminary performance analysis results, distributed GPU acceleration technology is applied to adjust the operating system resource configuration, using the formula:
[0049]
[0050] Optimize the calculation process and obtain performance improvement indicators, among which, is performance efficiency, Represents a computing task, Represents the processing time corresponding to the task, Represents the total number of computing tasks;
[0051] According to the performance improvement index, resource reallocation and configuration optimization are performed to obtain performance efficiency optimization results.
[0052] The present invention is improved in that the steps of processing the low-frequency and sensitive files are specifically as follows:
[0053] After encrypting low-frequency and sensitive files based on AES-256, the files are sliced, and the slices are divided according to size and stored independently in the distributed storage system. The storage location and encryption level information of the slices are recorded to obtain the slice storage index;
[0054] Based on the slice storage index, if there is a need for use, the data fragments are reassembled using the formula:
[0055]
[0056] Get the complete file content ,in, Indicates The encrypted data of each slice, Indicates The weight parameter of each slice during the reassembly process, Indicates the total number of slices.
[0057] Compared with the prior art, the advantages and positive effects of the present invention are:
[0058] In the present invention, by dynamically applying AES-128 and AES-256 encryption algorithms, high-frequency access files are ensured to be quickly processed while sensitive files are highly secure, thereby improving the effective use of resources and reducing the performance burden caused by excessive encryption. The introduction of homomorphic encryption technology allows complex data processing while keeping the data fully encrypted, thereby enhancing data security and avoiding security vulnerabilities that occur during the decryption process. The performance optimization of distributed GPU technology enables the system to efficiently process encryption tasks, alleviates the traditional single-node processing bottleneck, and improves the response speed and data processing capabilities of the entire system. BRIEF DESCRIPTION OF THE DRAWINGS
[0059] Figure 1 is a system flow chart of the present invention;
[0060] Figure 2 is a flow chart for determining the average time interval and frequency in the present invention;
[0061] Figure 3 A flowchart for obtaining access mode classification data in the present invention;
[0062] Figure 4 A flowchart of updating encryption parameters in real time in the present invention;
[0063] Figure 5 This is a flow chart for obtaining a parameter adjustment log in the present invention;
[0064] Figure 6 This is a flow chart of encrypting a file in the present invention;
[0065] Figure 7 This is a flowchart for obtaining homomorphic operation logs in the present invention;
[0066] Figure 8 A flowchart for obtaining the performance efficiency optimization results in the present invention;
[0067] Fig. 9 The flowchart of the present invention is to process low-frequency and sensitive files. DETAILED DESCRIPTION
[0068] In order to make the purpose, technical solution and advantages of the present invention more clearly understood, the present invention is further described in detail below in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present invention and are not intended to limit the present invention.
[0069] In the description of the present invention, it should be understood that the terms "length", "width", "up", "down", "front", "back", "left", "right", "vertical", "horizontal", "top", "bottom", "inside", "outside", etc., indicating positions or positional relationships, are based on the positions or positional relationships shown in the accompanying drawings, and are only for the convenience of describing the present invention and simplifying the description, rather than indicating or implying that the device or element referred to must have a specific orientation, be constructed and operated in a specific orientation, and therefore cannot be understood as limiting the present invention. In addition, in the description of the present invention, the meaning of "multiple" is two or more, unless otherwise clearly and specifically defined.
[0070] Example
[0071] See also Figure 1 The present invention provides a technical solution: a distributed file encryption system based on a domestic OS includes:
[0072] The file monitoring module is based on the OS system, captures file access requests in real time, records the timestamp of each access, determines the average time interval and frequency of access, and judges the access frequency of files based on the access mode to obtain access mode classification data;
[0073] The dynamic encryption management module classifies data based on access patterns, using AES-128 for high-frequency access files and AES-256 for low-frequency and sensitive files. It updates encryption parameters in real time to match differentiated security requirements, records each encryption parameter adjustment process, and generates parameter adjustment logs.
[0074] The homomorphic encryption module encrypts files based on parameter adjustment logs using a fully homomorphic or semi-homomorphic encryption algorithm, verifies the feasibility of querying and analyzing files in an encrypted state, and obtains homomorphic operation logs;
[0075] The performance optimization module identifies the performance bottlenecks in homomorphic encryption operations based on homomorphic operation logs, uses distributed GPU acceleration technology to optimize the computing speed, and reallocates operating system resources to optimize operating efficiency, thereby obtaining performance efficiency optimization results.
[0076] Access pattern classification data includes access type identification, frequency level, and time characteristics. Parameter adjustment logs include encryption algorithm usage records, parameter update details, and security level adjustment items. Homomorphic operation logs include encryption algorithm application instances, query operation compatibility, and analysis function execution records.
[0077] See also Figure 2 , the steps for determining the average time interval and frequency are as follows:
[0078] Based on the OS system, by monitoring file access events, the timestamp of each access is captured and recorded in real time to form a timestamp list;
[0079] The operating system is configured with sufficient resources to ensure the continuity of data capture. The recording operation needs to be optimized to reduce the impact on system performance. The recorded timestamp data must be accurate to the millisecond level to meet the needs of subsequent processing. The data is stored in a NoSQL database to quickly write and query data. The creation of a timestamp list is not just to record a point in time, but to capture the specific time of the event and the environmental status of the event. The time recording function needs to be embedded in the event listener to ensure that each file access event can be recorded instantly and accurately.
[0080] Based on the timestamp list, calculate the difference between two adjacent timestamps to obtain a time interval list;
[0081] Calculate the difference between two adjacent timestamps in the timestamp list. By calculating the difference for each pair of consecutive timestamps, the specific interval of access can be obtained. The key is the accurate acquisition of timestamps and the accurate calculation of time differences. The calculation of each time difference needs to take into account the synchronization of system time to ensure that the actual situation of file access is reflected without error. After the calculation is completed, the time interval data will be stored in another data table for subsequent analysis and processing. The data will serve as the basis for judging the file access mode. The accurate time interval is the key data for analyzing file usage patterns and user behavior patterns, and is directly related to the next step of frequency calculation and mode judgment.
[0082] Based on the list of time intervals, use the formula:
[0083]
[0084] and
[0085]
[0086] Calculate the average time interval and access frequency ,in, and Respectively represent and Timestamp, is the total number of events;
[0087] If there are 10 timestamps: [100, 110, 120, 150, 160, 170, 200, 210, 220, 230] (seconds), calculate the time interval: [10, 10, 30, 10, 10, 30, 10, 10, 10], and then use the formula to calculate the average time interval and access frequency , the calculation process is as follows:
[0088]
[0089] and
[0090]
[0091] The result shows that a file is accessed once every 14.44 seconds on average, with an access frequency of 0.07 times per second, which can be used to analyze system load and user access habits.
[0092] See also Figure 3 ,The specific steps for obtaining access mode classification data are:
[0093] Based on the average time interval and frequency, analyze the file access pattern, determine the file access frequency level, and obtain the file frequency level information;
[0094] Based on the access frequency and average time interval data, the access pattern of each file is analyzed, and the frequency distribution analysis method is used to determine the access frequency level of the file. The process involves statistical processing of a large amount of data and frequency calculation. First, the system extracts the access records of each file from the data set, and then calculates the number of accesses of each file, and then determines the frequency based on the total access time and the number of accesses. The analysis not only helps to understand the overall trend of file access, but also can identify files with abnormally high or low access frequencies. In order to make classification judgments, a classification threshold is set. For example, files with more than 50 access times and an average access interval of less than 5 minutes are classified as "high-frequency access", while files with less than 20 access times and an average access interval of more than 10 minutes are classified as "low-frequency access". The frequency level data will then be used for further access pattern classification.
[0095] Based on the file frequency information, the formula is used:
[0096]
[0097] Calculating Categorical Values , the files are divided into high-frequency and low-frequency access files according to the classification value, and the classified access patterns are obtained, where is the file access frequency, For the duration of the visit, is the access time interval, To adjust the parameters;
[0098] A file is accessed 100 times in the observation window, with a total access time of 400 minutes and an average time interval of 4 minutes. The adjustment parameter is set to 1, and the value is inserted for calculation:
[0099]
[0100] The result shows that the access mode classification value of this file is 8000, which helps to further analyze the importance of the file and adjust the system's resource allocation strategy.
[0101] Based on the classified access patterns, the access characteristic index of each type of file is calculated, and the access characteristics of files of different categories are analyzed to obtain the access pattern classification data;
[0102] Combined with the classified access pattern data, statistical analysis is performed. By calculating the access characteristic indicators of each type of file, for example, analyzing the average access interval and total access time of frequently accessed files, a detailed description of each classification can be obtained. This information is crucial for optimizing system performance. For example, for frequently accessed files (accessed more than 50 times and with an average access interval of less than 5 minutes), the system needs to increase cache resources or back them up more frequently to ensure data integrity and access efficiency. Infrequently accessed files can be considered for archiving or cleaning, which not only helps to analyze data access patterns, but also guides the rational allocation of resources.
[0103] See also Figure 4 ,The steps for updating encryption parameters in real time are as follows:
[0104] Based on the access pattern classification data, determine the access frequency and sensitivity level of each file, use AES-128 encryption for frequently accessed files, use AES-256 encryption for infrequently accessed and sensitive files, and generate a pre-encryption policy list;
[0105] The access pattern and sensitivity data of each file are collected, and the files are classified as high-risk or low-risk according to predetermined standards. High-risk files are scheduled to use the AES-128 encryption strategy based on their high access frequency and sensitive data characteristics. For files with high sensitivity but low access frequency, the more secure AES-256 encryption strategy is scheduled to be used. During this classification and predetermined strategy process, the classification basis and predetermined strategy of each file will be recorded in detail to ensure the traceability and transparency of each operation, so that the implementation of security policies can be monitored in real time, and security policies can be adjusted according to real-time data to ensure that data protection measures always meet current security needs.
[0106] Based on the pre-encryption policy list, according to the current network environment and security, the formula is used:
[0107]
[0108] Update encryption parameters , matching differentiated security requirements, where Represents the file access frequency, Represents the sensitivity of the file. and It is to ensure that the encryption strategy for each file is the latest and most suitable according to the adjustment coefficient of the current security level;
[0109] If the access frequency of a file ( ) is 0.8 (indicating very frequent access), and its sensitivity ( ) is rated 0.5 (medium sensitivity), safe parameters Set to 1.5, Set it to 1.0 and calculate:
[0110]
[0111] The calculation result 1.7 will be used to determine the actual encryption strength and instruct the system to select appropriate encryption technology and parameter settings to address security risks.
[0112] See also Figure 5 , the specific steps for obtaining the parameter adjustment log are:
[0113] Monitor each file encryption parameter adjustment event, record the file identifier, current encryption algorithm, parameters before change, parameters after change, and change time, using the formula:
[0114]
[0115] Calculate the parameter change information and obtain a preliminary change record with a mark, where: is the change in encryption parameters, and Indicates the encryption parameter values before and after the change. is the weight parameter for the target security requirement;
[0116] When monitoring encryption parameter adjustments, each encryption parameter change event of a file is captured, and records include the file identifier, the currently used encryption algorithm, the parameter values before and after the change, and the change time. The data is collected in real time and stored in a temporary database. The system preliminarily classifies the change data and marks those major changes that exceed the preset threshold, and generates marked change records. The process ensures the capture and recording of all key information, laying the foundation for further log processing.
[0117] According to the marked preliminary change records, integrate each record information, including file identifier, current encryption algorithm, parameters before change, parameters after change and change time, and archive it into the parameter adjustment log;
[0118] The original encryption parameters of a file It was 128 bits, and now it is changed to 256 bits. is 0.5, and the change significance is calculated according to the formula:
[0119]
[0120] The calculation result 64 indicates that the significance of the parameter change is medium. If the system threshold is set to 50, this change will be marked as significant and specially recorded. This result shows that this change in the encryption parameters is significant enough to be recorded in the system's security log for further analysis.
[0121] See also Figure 6 , the specific steps for encrypting files are:
[0122] Based on the parameter adjustment log, security requirements and encryption parameters of the file are extracted from the log, including file access frequency, user identity and access type, a fully homomorphic or semi-homomorphic encryption algorithm is adopted, a key length and an encryption mode are set, and encryption algorithm decision information for each file is generated;
[0123] The key length refers to the number of bits of the key used to encrypt and decrypt data. The key length determines the encryption strength, because the longer the key, the more attempts are required to crack the encryption, and the higher the security. The key length can be 128, 192 and 256 bits. The encryption mode can be selected from ECB (Electronic Codebook Mode), CBC (Cipher Block Chaining Mode), CFB (Cipher Feedback Mode), OFB (Output Feedback Mode) and GCM (Galois / Counter Mode), etc.
[0124] Access parameter adjustment logs to extract the security requirements and previous encryption parameters of each file. The analysis process involves deep mining of log data to ensure that the unique security requirements and historical encryption measures of each file can be understood. Through comprehensive evaluation of these data, it is possible to accurately determine whether a fully homomorphic or semi-homomorphic encryption algorithm should be used for each file. The generated decision information not only includes the choice of encryption type, but also indicates personalized security measures for each file, preparing for the next encryption operation.
[0125] Based on the encryption algorithm decision information, the formula is adopted:
[0126]
[0127] Encrypt the file to obtain the encrypted file data ,in, Represents the data content of the file. is the selected encryption key, and They are weight coefficients adjusted based on file sensitivity;
[0128] If the file data The text content is "exampledata", and its value is represented by the numeric code 1001. The selected key The value is 2001, the weight caused by security requirements and are 1.5 and 0.5 respectively, and the calculation process is:
[0129]
[0130] The results show that by adjusting the weight parameters, it is possible to ensure that the encryption operation meets the security standards of the file while maintaining the flexibility of the operation, making the encrypted data It is 2502, indicating the encrypted state.
[0131] The encrypted file data is stored, and the key information in the encryption process is recorded, including the key, encryption algorithm, and encryption execution time, to obtain encryption activity records;
[0132] Once the file is encrypted, the system will enter the storage and recording stage. At this time, the encrypted file data will be securely stored and key operation information will be recorded simultaneously, including but not limited to the details of the key used, the type of encryption algorithm selected, and the specific time of encryption implementation. The recording process is crucial because it provides a method to ensure the transparency and traceability of each step of the operation. The generated encryption activity records provide data support for future security audits and performance evaluations, ensuring the organization's security compliance and the effectiveness of data protection measures.
[0133] See also Figure 7 , the specific steps for obtaining homomorphic operation logs are:
[0134] Continuously track the query and analysis activities of encrypted files, record the operation type, time and participant information, and obtain file operation information;
[0135] After the real-time monitoring system is started, all query and analysis operations on the file are continuously tracked according to the fully homomorphic or semi-homomorphic encryption method. The monitoring content involves the type of each operation, the execution time and the identity information of the executor. The information is recorded in the system to ensure the comprehensiveness and accuracy of the data. Each data call is encoded and identified, and matched with the specific access rights in its encrypted state. The query information in the encrypted state of the file is matched with the query authorization of the database, unauthorized operation requests are excluded, and each query result is recorded in the log according to the operation time and the importance of the file to generate a homomorphic operation log.
[0136] Based on the file operation information, the collected data is processed using the formula:
[0137]
[0138] Get the homomorphic operation log, where is the score of the operation log, Indicates the operation time to reflect the increasing importance of time factors to logs, Indicates the type of operation, highlighting that common operations have a smaller impact, while uncommon operations have a larger impact. Represents the result of the operation, through logarithmic transformation To handle and optimize the impact of abnormal results;
[0139] The square of the time, the square root of the operation type, and the logarithmic transformation of the operation result enhance the segmentation of the importance of different operations, so that the log can reflect the actual weight of each operation. 4, operation type is 16, the result of the operation is 64, calculated as:
[0140]
[0141]
[0142]
[0143] The result shows that the operation log value is 21.806, which reflects the relative importance of this operation and is saved as part of the log in the homomorphic operation log for subsequent auditing and analysis.
[0144] See also Figure 8 , the specific steps for obtaining performance efficiency optimization results are:
[0145] According to the homomorphic operation log, collect the relevant data of performance bottlenecks, including operation duration and resource usage, and generate preliminary performance analysis results based on the collected data;
[0146] In the process of analyzing homomorphic operation logs, we first collect data from each distributed node to obtain detailed records of operation duration and resource usage, including CPU usage, memory consumption, and frequency of input and output operations. Then, we use data mining technology to analyze data points and identify the location of performance bottlenecks, such as insufficient processor speed or memory resource overload. Based on the analysis results, we automatically generate a preliminary performance analysis report that points out the peaks and troughs of resource usage in each operation, providing decision support for subsequent optimization measures.
[0147] Based on the preliminary performance analysis results, distributed GPU acceleration technology is applied to adjust the operating system resource configuration, using the formula:
[0148]
[0149] Optimize the calculation process and obtain performance improvement indicators, among which, is performance efficiency, Represents a computing task, Represents the processing time corresponding to the task, Represents the total number of computing tasks;
[0150] There are three computing tasks, and the processing time of each task is , , The task complexity is , , , the performance efficiency is calculated according to the formula :
[0151]
[0152]
[0153] This result shows that after considering the complexity and processing time of the task, the performance efficiency of the system is about 0.161, indicating the amount of work completed per unit time, which helps to further accurately adjust the resource allocation and task optimization strategy, thereby improving the system performance.
[0154] According to the performance improvement indicators, perform resource reallocation and configuration optimization to obtain performance efficiency optimization results to ensure maximum operating efficiency;
[0155] According to the performance improvement indicators, the distributed computing resources and GPU configuration are automatically adjusted, including increasing memory allocation and optimizing processor time slicing, so as to effectively utilize the processing power of each node. Through the adjustment, the operation efficiency is successfully optimized and the performance efficiency optimization results are generated, ensuring that each operation can be executed under the optimal resource configuration to achieve the expected efficiency improvement.
[0156] See also Fig. 9 , the specific steps for processing low-frequency and sensitive files are:
[0157] Based on AES-256, after encrypting low-frequency and sensitive files, the files are sliced. The slices are divided according to size and stored independently in the distributed storage system. The storage location and encryption level information of the slices are recorded to generate a slice storage index. After the low-frequency and sensitive files are encrypted using AES-256, the files are sliced and stored according to the encryption strategy. Each file slice is segmented according to the set standard size. The segmentation process involves the specific length of the file and the preset slice size. The file length is obtained through the file attributes. The slice size is set according to the configuration of the storage system. The slice size can be 1MB, 64MB, and 256MB. Each slice is independently stored in different nodes in the distributed storage system. The storage location information is determined and recorded by the system allocation algorithm to ensure that the location of each slice can be accurately tracked. The encryption level information is recorded together with the slice, and an index is established to optimize data retrieval efficiency to obtain an index record of encryption and slice storage.
[0158] Based on the slice storage index, if there is a need to use it, the data fragments are reassembled using the formula:
[0159]
[0160] Get the complete file content ,in, Indicates The encrypted data of each slice, Indicates The weight parameter of each slice during the reassembly process, Indicates the total number of slices;
[0161] There are 5 slices, and the encrypted data of each slice is They are [10, 20, 30, 40, 50] respectively, with weights Set to [1, 2, 3, 4, 5] respectively, the total number of slices The calculation process is as follows:
[0162]
[0163]
[0164] The result shows that the sum of the encrypted data of the entire file after reassembly is 110, which means that through weight adjustment, more important file slices contribute more data content during the reassembly process, ensuring the integrity and security of the file.
[0165] The above are only preferred embodiments of the present invention and are not intended to limit the present invention in other forms. Any technician familiar with the profession may use the technical contents disclosed above to change or modify them into equivalent embodiments with equivalent changes and apply them to other fields. However, any simple modification, equivalent change and modification made to the above embodiments based on the technical essence of the present invention without departing from the technical solution of the present invention still falls within the protection scope of the technical solution of the present invention.
Claims
1. A distributed file encryption system based on domestic OS, characterized by: The system comprises: The file monitoring module is based on the OS system, captures file access requests in real time, records the timestamp of each access, determines the average time interval and frequency of access, and judges the access frequency of files based on the access mode to obtain access mode classification data; The dynamic encryption management module adopts AES-128 for high-frequency access files and AES-256 for low-frequency and sensitive files based on the access mode classification data, updates encryption parameters in real time to match differentiated security requirements, and records the adjustment process of each encryption parameter to generate a parameter adjustment log; The steps for obtaining the parameter adjustment log are specifically as follows: Monitor each file encryption parameter adjustment event, record the file identifier, current encryption algorithm, parameters before change, parameters after change, and change time, using the formula: Calculate the parameter change information and obtain a preliminary change record with a mark, where: is the change in encryption parameters, and Indicates the encryption parameter values before and after the change. is the weight parameter for the target security requirement; According to the marked preliminary change record, each record information is integrated, including a file identifier, a current encryption algorithm, a parameter before the change, a parameter after the change, and a change time, and filed into a parameter adjustment log; The homomorphic encryption module encrypts the file based on the parameter adjustment log through a fully homomorphic or semi-homomorphic encryption algorithm, verifies the feasibility of querying and analyzing the file in an encrypted state, and obtains a homomorphic operation log; The steps of encrypting the file are specifically as follows: Based on the parameter adjustment log, security requirements and encryption parameters of the file are extracted from the log, including file access frequency, user identity and access type, a fully homomorphic or semi-homomorphic encryption algorithm is adopted, a key length and an encryption mode are set, and encryption algorithm decision information for each file is generated; Based on the encryption algorithm decision information, the formula is adopted: Encrypt the file to obtain the encrypted file data ,in, Represents the data content of the file. is the selected encryption key, and They are weight coefficients adjusted based on file sensitivity; The encrypted file data is stored, and key information in the encryption process is recorded, including the key, encryption algorithm, and encryption execution time, to obtain an encryption activity record; The performance optimization module identifies the performance bottleneck in the homomorphic encryption operation according to the homomorphic operation log, optimizes the computing speed by using distributed GPU acceleration technology, and reallocates the operating system resources to optimize the operating efficiency, thereby obtaining a performance efficiency optimization result.
2. The distributed file encryption system based on domestic OS according to claim 1 is characterized in that: The steps for determining the average time interval and frequency are specifically as follows: Based on the OS system, by monitoring file access events, the timestamp of each access is captured and recorded in real time to form a timestamp list; Based on the timestamp list, calculating the difference between two adjacent timestamps to obtain a time interval list; Based on the list of time intervals, the formula is used: and Calculate the average time interval and access frequency ,in, and Respectively represent and Timestamp, is the total number of events.
3. The distributed file encryption system based on domestic OS according to claim 1 is characterized in that: The steps for obtaining the access mode classification data are specifically as follows: Analyze the file access pattern based on the average time interval and frequency, determine the file access frequency level, and obtain file frequency level information; Based on the file frequency information, the formula is used: Calculating Categorical Values , the files are divided into high-frequency and low-frequency access files according to the classification value, and the classified access patterns are obtained, where is the file access frequency, For the duration of the visit, is the access time interval, To adjust the parameters; Based on the classified access patterns, access characteristic indicators of each type of file are calculated, and access characteristics of files of different categories are analyzed to obtain access pattern classification data.
4. The distributed file encryption system based on domestic OS according to claim 1 is characterized in that: The steps of updating the encryption parameters in real time are specifically as follows: Based on the access pattern classification data, determine the access frequency and sensitivity level of each file, use AES-128 encryption for high-frequency access files, use AES-256 encryption for low-frequency and sensitive files, and generate a pre-encryption strategy list; Based on the pre-encryption strategy list, according to the current network environment and security, the formula is adopted: Update encryption parameters , matching differentiated security requirements, where Represents the file access frequency, Represents the sensitivity of the file. and is an adjustment factor based on the current security level.
5. The distributed file encryption system based on domestic OS according to claim 1 is characterized in that: The steps for obtaining the homomorphic operation log are specifically as follows: Continuously track the query and analysis activities of encrypted files, record the operation type, time and participant information, and obtain file operation information; Based on the file operation information, the collected data is processed using the formula: Get the homomorphic operation log, where is the score of the operation log, Indicates the operation time. Indicates the operation type. Indicates the result of an operation.
6. The distributed file encryption system based on domestic OS according to claim 1 is characterized in that: The steps for obtaining the performance efficiency optimization result are specifically as follows: According to the homomorphic operation log, collect data related to the performance bottleneck, including operation duration and resource usage, and generate preliminary performance analysis results based on the collected data; Based on the preliminary performance analysis results, distributed GPU acceleration technology is applied to adjust the operating system resource configuration, using the formula: Optimize the calculation process and obtain performance improvement indicators, among which, is performance efficiency, Represents a computing task, Represents the processing time corresponding to the task, Represents the total number of computing tasks; According to the performance improvement index, resource reallocation and configuration optimization are performed to obtain performance efficiency optimization results.
7. The distributed file encryption system based on domestic OS according to claim 4 is characterized in that: The specific steps for processing the low-frequency and sensitive files are: After encrypting low-frequency and sensitive files based on AES-256, the files are sliced, and the slices are divided according to size and stored independently in the distributed storage system. The storage location and encryption level information of the slices are recorded to obtain the slice storage index; Based on the slice storage index, if there is a need to use it, the data fragments are reassembled using the formula: Get the complete file content ,in, Indicates The encrypted data of each slice, Indicates The weight parameter of each slice during the reassembly process, Indicates the total number of slices.
Citation Information
Patent Citations
Block chain privacy protection method and system based on homomorphic encryption algorithm and zero-knowledge proof protocol
CN116915379A
Dynamic encryption method and system, computer equipment and storage medium
CN117131484A
Information encryption system and method based on cloud computing
CN118400166A