User-space and kernel-space data interaction method and system

By introducing data interaction methods and systems based on user-state and kernel-state in the encrypted file system, the problem of lack of automation and flexibility in the encrypted file system in the prior art is solved, and efficient key management and enhanced security and manageability are achieved.

CN119537060BActive Publication Date: 2025-06-10JIANGSU IDEABANK MICROELECTRONICS TECH
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510007730.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-01-03
Publication Date
2025-06-10
Estimated Expiration
2045-01-03

AI Technical Summary

Technical Problem

Existing encrypted file systems lack automation and flexibility to achieve efficient key management. Since encryption and decryption operations usually occur in the kernel state, users cannot directly control and monitor these operations, resulting in the system's security and manageability.

Method used

Provides a data interaction method and system based on user state and kernel state, which realizes user request processing and key management through communication connection between user layer and kernel layer. The user layer obtains user requests and sends them to the kernel layer. The kernel layer generates action instructions and communicates with the data processing system, processes key actions and feedbacks the results to the user layer.

Benefits of technology

Through functional division and efficient communication, the database security and stability in key application and management scenarios are improved, the system manageability and flexibility are enhanced, and performance and transparency are optimized.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119537060B_ABST
    Figure CN119537060B_ABST
Patent Text Reader

Abstract

This application relates to a data interaction method and system based on user mode and kernel mode, and relates to the technical field of data processing. The system includes a user terminal and a data processing system. The user terminal includes a user layer and a kernel layer; the user layer of the user terminal and the kernel layer of the user terminal are communicatively connected; the data processing system is communicatively connected to the kernel layer. In the process of managing key usage and key data collection, the functions of the user layer and the kernel layer of the client are divided. After the kernel layer receives data, the data is processed in the kernel layer, and the result is fed back to the user layer, thereby ensuring the secure and stable operation of the database in the key application and management scenario.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the technical field of data processing, and particularly to a data interaction method and system based on user space and kernel space. Background Art

[0002] With the rapid development of information technology, data security has become a key issue in computer system design. Traditionally, the encryption, decryption, and permission management of files are usually independently processed by user space and kernel space, which have certain limitations in terms of security and management efficiency. In addition, there are also some challenges in key management, including issues such as key generation, storage, and distribution.

[0003] Existing encrypted file systems often require users to manually manage keys.

[0004] The encrypted file systems in related technologies lack automation and flexibility and cannot achieve efficient key management. In addition, since the encryption and decryption operations usually occur in kernel space, users cannot directly control and monitor these operations, which affects the security and manageability of the system. Summary of the Invention

[0005] This application provides a data interaction method and system based on user space and kernel space, which improves the security and manageability of system use. The technical solution is as follows:

[0006] On the one hand, a data interaction method based on user space and kernel space is provided. This method is applied to a data interaction system based on user space and kernel space. The data interaction system based on user space and kernel space includes a user terminal and a data processing system. The user terminal includes a user layer and a kernel layer;

[0007] The user layer of the user terminal and the kernel layer of the user terminal are communicatively connected;

[0008] The data processing system is communicatively connected to the kernel layer;

[0009] The method includes:

[0010] The user layer obtains a user request; sends the user request to the kernel layer;

[0011] The kernel layer receives the user request; generates an action instruction based on the user request; and sends the action instruction to the data processing system in response to the action instruction being associated with a key application action;

[0012] The data processing system receives the action instruction; generates a key action processing result based on the action instruction; and feeds back the key action processing result to the kernel layer;

[0013] The kernel layer receives the key action processing result; generates a key action feedback result based on the key action processing result; and sends the user action feedback result to the user layer.

[0014] In an optional embodiment, before the user layer obtains a user request, when the terminal device is connected to an external device, it includes:

[0015] The user layer executes an authentication process with the external device;

[0016] In response to the authentication process passing, the user request is obtained.

[0017] In an optional embodiment, when the user layer sends the user request to the kernel layer, it includes:

[0018] The user layer sends the user request to the kernel layer based on the Remote Procedure Call Protocol.

[0019] In an optional embodiment, when the kernel layer generates an action instruction based on the user request, it includes:

[0020] The kernel layer, in response to receiving the user request, performs an authorization process matching on the user request; based on the matching result of the authorization process, determines a user instruction corresponding to the user request.

[0021] In an optional embodiment, after the kernel layer determines a user instruction corresponding to the user request based on the matching result of the authorization process, it includes:

[0022] The kernel layer mounts an encrypted directory corresponding to the user instruction based on the user instruction; configures an audit log corresponding to the user instruction.

[0023] In an optional embodiment, the method further includes: The data processing system includes a key generation module, a key storage module, and a key life cycle management module.

[0024] In an optional embodiment, the action instruction is associated with a key acquisition action;

[0025] The key action processing result includes key data, and the key data is used to uniquely indicate a key.

[0026] In an optional embodiment, the method further includes:

[0027] The kernel layer receives the key action processing result; stores the key data corresponding to the key action processing result; generates the key feedback action result based on the key data.

[0028] In an alternative embodiment, the action instruction key audit is associated with the hole action;

[0029] The key action processing result includes key audit data, and the key audit data is used to indicate the key management process of the data processing system.

[0030] In an alternative embodiment, the method further includes:

[0031] The kernel layer receives the key action processing result; stores the key audit result corresponding to the key audit data; generates visual log data corresponding to the key audit result based on the key audit result; and sends the visual log data to the user layer.

[0032] On the other hand, a data interaction system based on user mode and kernel mode is provided. The system includes a user terminal and a data processing system. The user terminal includes a user layer and a kernel layer;

[0033] The user layer of the user terminal and the kernel layer of the user terminal are communicatively connected;

[0034] The data processing system is communicatively connected to the kernel layer;

[0035] This system is used for the data interaction method based on user mode and kernel mode as described in any of the above.

[0036] The technical effects included in each embodiment of the present application at least include:

[0037] In the process of managing key usage and key data collection, the functions of the user layer and the kernel layer of the client are divided. After the kernel layer receives the data, the data is processed in the kernel layer, and the result is fed back to the user layer, thereby ensuring the safe and stable operation of the database in the key application and management scenario. BRIEF DESCRIPTION OF THE DRAWINGS

[0038] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the drawings in the following description are only some embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.

[0039] Figure 1 The block diagram of a data interaction system based on user mode and kernel mode provided by an exemplary embodiment of the present application is shown.

[0040] Figure 2 The schematic flowchart of a data interaction method based on user mode and kernel mode provided by an exemplary embodiment of the present application is shown.

[0041] Figure 3 The modular block diagram of a data interaction system based on user mode and kernel mode provided by an exemplary embodiment of the present application is shown.

[0042] Figure 4 The process schematic diagram of a data interaction method based on user mode and kernel mode provided by an exemplary embodiment of the present application is shown. Detailed implementation manners

[0043] To make the objectives, technical solutions, and advantages of the present application clearer, the following will further describe the embodiments of the present application in detail with reference to the accompanying drawings.

[0044] Figure 1 The structural block diagram of a data interaction system based on user mode and kernel mode provided by an exemplary embodiment of the present application is shown. Please refer to Figure 1 , the system includes a user terminal 110 and a data processing system 120. Among them, the user terminal 110 includes a user layer 111 and a kernel layer 112, and the user layer and the kernel layer of the user terminal are communicatively connected.

[0045] In the embodiments of the present application, the data storage system is implemented in the form of a database, and the data storage system is used for storing and managing data. In the embodiments of the present application, the data processing system may be implemented as a key management system. Optionally, the key management system can perform different processes in the key life cycle, such as key generation, storage, distribution, update, and destruction. In different embodiments of the present application, the data storage system configures an entity server, or the data storage system correspondingly configures a cloud server, or the data management system is implemented as a server cluster. The present application does not limit the entity form of data storage.

[0046] In the embodiments of the present application, the user terminal may be implemented as a terminal device such as a mobile phone, a personal computer, and a wearable device. During the application of the above devices, the file encryption and decryption permissions are usually interactively processed by the user layer and the kernel layer.

[0047] It should be noted that in the embodiments of the present application, the user layer and the kernel layer are two operating environments in the operating system architecture. The user layer corresponds to the operating environment of the user mode, and the kernel layer corresponds to the operating environment of the kernel mode.

[0048] Among them, the user layer is the interface layer provided by the operating system to users and application programs. It includes the user interface, application programming interface (API), and runtime library, etc. The main purpose is to provide users with an easy-to-use and understandable environment while hiding the complexity of the operating system. Programs running in the user layer are called user programs or user processes, and they usually execute in user mode. Programs cannot directly access hardware resources and must request services from the kernel layer through system calls.

[0049] It should be noted that in the embodiments of this application, the user layer is configured with a user-mode file system, which can support the configuration of different types of algorithm strategies. In one example, the user-mode file system configured in the user layer supports SM1, SM4, and AES encryption algorithms for backing up and decrypting databases.

[0050] Correspondingly, the kernel layer is the core part of the operating system, responsible for managing system resources such as CPU time, memory, file system, and I / O devices, etc. It provides a set of system call interfaces that allow user-layer programs to request services from the operating system, such as file operations, process management, network communication, etc. The kernel layer runs in kernel mode, has direct access rights to hardware and system resources, is responsible for scheduling user processes, handling interrupts and exceptions, and implementing security and protection mechanisms.

[0051] In this case, in the embodiments of this application, there is a communication connection relationship between the user layer of the user terminal and the kernel layer of the user terminal. In this case, the user-layer program requests services from the kernel layer through system calls, and the kernel layer processes these requests and returns the results to the user-layer program. The communication between the kernel layer and the user layer in the embodiments of this application can be carried out based on this form.

[0052] In Figure 1 the case of showing the system, Figure 2 shows a schematic flow diagram of a data interaction method based on user mode and kernel mode provided by an exemplary embodiment of this application. Taking this method applied to a system as shown in Figure 1 as an example for illustration, this method includes:

[0053] Step 201, the user layer obtains a user request.

[0054] Optionally, the user layer is configured with an application program, and the user request obtained by the user layer is associated with the user's operations on the application program.

[0055] Step 202, the user layer sends the user request to the kernel layer.

[0056] This process is the process of sending the user request. Optionally, this sending process is sent through the interface connection between the user layer and the kernel layer.

[0057] Step 203, the kernel layer receives the user request.

[0058] Step 204, the kernel layer generates an action instruction based on the user request.

[0059] In the embodiment of the present application, the action instruction is associated with the function of the data processing system. Optionally, when the data processing system is a database for storing data, the action instruction can be an instruction for retrieving and previewing; when the data processing system is a key management system, the action instruction can be an instruction for processing keys.

[0060] Step 205, in response to the action instruction being associated with the key application action, the kernel layer sends the action instruction to the data processing system.

[0061] In the embodiment of the present application, taking the action instruction being associated with the key application action as an example, at this time, the action instruction is used to be sent to the data processing system as a key management device.

[0062] Step 206, the data processing system receives the action instruction.

[0063] Step 207, the data processing system executes the database action based on the action instruction and generates a key action processing result.

[0064] Optionally, the database action can be actions such as retrieving, storing, and deleting data. The present application does not limit the specific form of the database action. After executing the database action, a data processing result is correspondingly generated.

[0065] Step 208, the data processing system feeds back the key action processing result to the kernel layer.

[0066] In the embodiment of the present application, the key processing action will be sent to the terminal device and received by the kernel layer of the terminal device.

[0067] Step 209, the kernel layer receives the key action processing result.

[0068] This process is the process for the kernel layer to receive the key action processing result.

[0069] Step 210, the kernel layer generates a key action feedback result based on the key action processing result.

[0070] In the embodiment of the present application, the key action feedback result is generated based on the key action processing result, and the feedback result is used to display the result at the interface end of the application program.

[0071] Step 211, the kernel layer sends the user action feedback result to the user layer.

[0072] In summary, in the method provided by the embodiments of the present application, during the management of key usage and key data collection, the functions of the user layer and the kernel layer of the client are divided. After the kernel layer receives data, the data is processed in the kernel layer, and the results are fed back to the user layer, thereby ensuring the secure and stable operation of the database in the key application and management scenario.

[0073] In some embodiments of the present application, please refer to Figure 3 , when the user terminal and the data processing system are connected, in the embodiments of the present application, the data interaction system based on the user mode and the kernel mode includes a database module 310, a communication interface module 320, an auditing and monitoring module 330, a configuration management module 340, a backup and recovery module 350, a key management module 360, and a key policy management module 370. In the embodiments of the present application, the above modules are configured in the user terminal and the data processing system based on application requirements.

[0074] Next, the functions of the above modules will be described:

[0075] Database module: Responsible for recording authorized process information, encrypted directory information, and audit logs. It provides a persistent storage mechanism to ensure that this information can be retained and accessed even after the system restarts.

[0076] Communication interface module: Serves as the communication bridge between the user layer and the kernel layer. The IBEfsService and the kernel IBEfs module exchange information through this interface, transmitting the user's operation requests and processing results.

[0077] Auditing and monitoring module: Responsible for collecting, sorting, and analyzing audit logs, providing monitoring and traceability functions for database access and operation behaviors. Administrators can understand the usage of the database through this module and discover potential security risks.

[0078] Configuration management module: Used to manage the configuration information of the system, such as the selection of encryption algorithms, the storage location of keys, etc. This module allows administrators to configure and adjust flexibly according to actual needs.

[0079] Backup and recovery module: Used to back up the key information (keys, encryption policies, etc.) of the encrypted database, and restore this information when needed. This helps to quickly restore the normal operation of the database in case of system failures or data loss.

[0080] Key management module: Responsible for the full life cycle management of key generation, storage, distribution, usage, update, and destruction in the entire encryption system. Ensure the security, confidentiality, and integrity of keys, thereby guaranteeing the security and reliability of database encryption and decryption operations.

[0081] Key Policy Management Module: Define the usage restrictions of keys, including the validity period of keys, usage times limit, usage scope, etc. Define key rotation and update policies, and regularly update and rotate keys to enhance the security of the system. Such policies can help prevent security issues caused by the long-term use of the same key. It can be used in conjunction with access control to ensure that only authorized users or systems can use specific keys. These restrictions can ensure that keys are only used when necessary and are not misused.

[0082] In this case, in an optional embodiment, the terminal device is connected to an external device. Before the user layer obtains the user request, the user layer executes the authentication process with the external device; in response to the successful authentication process, the user request is obtained.

[0083] Corresponding to this embodiment, the external device is generally implemented as an external storage device with complete interactive functions. In one example, the external device is implemented as a USB-Key. When the USB-Key is connected to the terminal device, the application program in the user layer first verifies whether the USB-Key is connected. After determining the connection, it performs PIN code authentication with the USB-Key. In the case of successful verification, the user layer executes the functions of the application program.

[0084] It should be noted that the verification process based on the USB-Key can be executed in various processes of the interaction between the user layer and the kernel layer. For example, it can be executed in the processes such as the user layer sending key modification instructions and key receiving instructions to the kernel layer.

[0085] Optionally, in some optional embodiments, the user layer is communicatively connected to the key module. During the process of the user layer performing authentication with the USB-Key, the key module performs further identity verification to prevent the occurrence of identity forgery and further reduce the security risk of key leakage.

[0086] In an optional embodiment, based on the existence of the communication interface module, the user layer sends the user request to the kernel layer based on the Remote Procedure Call Protocol.

[0087] In an optional embodiment, in response to receiving the user request, the kernel layer performs an authorization process matching for the user request, and based on the matching result of the authorization process, determines the user instruction corresponding to the user request.

[0088] Corresponding to this situation, the kernel layer can mount the encrypted directory corresponding to the user instruction based on user intelligence and configure the audit log corresponding to the user instruction.

[0089] In an optional embodiment, the action instruction is associated with the key acquisition action; the key action processing result includes key data, and the key data is used to uniquely indicate the key.

[0090] In response to this situation, the kernel layer receives the processing result of the key action; stores the key data corresponding to the processing result of the key action; and generates a key feedback action result based on the key data. That is, the kernel layer can independently process the key data and generate a key feedback action result.

[0091] In another optional embodiment, the action instruction is associated with the key audit action; the key audit data is included in the key action processing result, and the key audit data is used to indicate the key management process of the data processing system.

[0092] In response to this situation, the data processing system parses the instruction content of the action instruction to obtain an instruction content parsing result; in response to the instruction content parsing result indicating that the action instruction is an encryption / decryption instruction, determines the original data file based on the original data path; backs up the original data file in the new data path to obtain a backup data file; creates a mount command folder corresponding to the original data file; and encrypts and decrypts the data of the mounted file through the mount command folder to obtain an encrypted / decrypted file.

[0093] Combined with the above description, Figure 4 FIG. shows a schematic diagram of a process of implementing a data interaction method based on the user space and the kernel space provided by an exemplary embodiment of the present application. Taking the data processing system in this method process as a key management system as an example for description, please refer to Figure 4 , the process includes:

[0094] Step 401, initialize the key management system.

[0095] In the embodiment of the present application, when the system starts, the key management system is initialized. Operations such as generating a root key, setting a key storage location, and a permission policy are included.

[0096] Step 402, the user layer receives a user operation.

[0097] In the user operation layer, there is a user interface for interacting with the user. The user interface is the main interface for the user to interact with the system, providing a visual operation platform for the user. Through a graphical interface or a command line method, the user can perform a series of operations, such as requesting to add / delete an authorized process, mount / unmount an encrypted directory, and open / close an audit log, etc. In one example, the user interface is named IBEfsConsole. Corresponding to this user interface, there is a data processing end in the user layer, and this processing end is a localized application server. In one example, this localized application server is named IBEfsService.

[0098] Step 403, the application server in the user layer receives a processing request.

[0099] Optionally, the IBEfsService receives an RPC call from the IBEfsConsole. In this case, according to the user request, the IBEfsService performs operations accordingly, such as adding / deleting an authorization process, mounting / unmounting an encrypted directory, and opening / closing an audit log, etc. It should be noted that if file encryption / decryption operations are involved, the IBEfsService passes the corresponding request to the corresponding module in the kernel layer and calls the key management system to request the generation of keys required for encryption / decryption. Optionally, the corresponding module in the kernel layer is the kernel IBEfs module.

[0100] Step 404, the kernel layer processes the request.

[0101] The kernel IBEfs module receives the request passed by the IBEfsService and processes it. When file encryption / decryption operations are involved, the kernel IBEfs module sends the request to the key management system to request the generation of keys required for encryption / decryption. The key management system generates the corresponding keys and returns them to the kernel IBEfs module. The kernel IBEfs module uses the obtained keys to perform encryption / decryption operations on the files. If permission verification of the process is required, the kernel IBEfs module performs the corresponding permission verification operation. The kernel IBEfs module records the log of the process opening the file and sends the relevant information to the user layer for auditing and monitoring.

[0102] Step 405, the user layer processes the feedback.

[0103] During this process, the IBEfsService receives the processing result of the kernel IBEfs module and passes the feedback information to the IBEfsConsole. The IBEfsConsole updates the user interface status according to the feedback information so that the user can understand the operation result.

[0104] In summary, the method provided by the embodiment of this application has the following technical effects:

[0105] (1) Enhanced security: The present invention adopts the integration of the key management system and a flexible permission control strategy, which improves the security of the encrypted file system. The key management system ensures the secure generation, storage, distribution, update, and destruction of keys and other full-life cycle management tasks, effectively preventing the risks of key leakage and unauthorized access. At the same time, the flexible permission control strategy enables users to perform fine-grained control over file access permissions, further enhancing the security of the system.

[0106] (2) Improved Manageability: The present invention realizes efficient communication and collaboration between the user space and the kernel space, and at the same time provides an automated key management mechanism, greatly improving the manageability of the encrypted file system. Users can perform key management and permission control through a unified interface, simplifying the operation process, reducing the complexity and workload of management, and improving the management efficiency of the system.

[0107] (3) Enhanced Flexibility: The present invention provides flexible permission control policies, allowing users to dynamically adjust the access permissions of processes or users according to actual needs. This flexibility enables the system to adapt to the needs of different users and application scenarios, providing a more personalized data security solution. At the same time, the automated mechanism of the key management system also enhances the flexibility of the system. Users do not need to manually manage keys, improving the management efficiency and security of the system for keys.

[0108] (4) Performance Optimization: The present invention designs an efficient interaction method between the user space and the kernel space, realizing communication and collaboration between the user layer and the kernel layer through RPC calls and system calls. This design optimizes the performance and response speed of the system, reduces communication latency, improves the throughput and concurrency of the system, and provides users with a smoother and more stable usage experience.

[0109] (5) Improved Transparency: By realizing efficient communication and collaboration between the user space and the kernel space, the present invention enables users to directly monitor and control the running state of the encrypted file system, improving the transparency of the system. Users can understand the encryption and decryption process of files and the permission control situation in real time, reducing the uncertainty of system operation and enhancing users' trust in the system.

[0110] (6) Strong Scalability: Since the present invention adopts a modular design concept, separating functional modules such as key management and permission control, the system has strong scalability. Users can customize and expand the system according to actual needs, add new functional modules or replace existing modules to adapt to different application scenarios and business requirements. This scalability gives the present invention good application prospects and development potential.

[0111] The above are only optional embodiments of the present application and are not intended to limit the present application. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of the present application shall be included in the protection scope of the present application.

Claims

1. A data interaction method based on user state and kernel state, characterized in that: The method is applied to a data interaction system based on user state and kernel state, wherein the data interaction system based on user state and kernel state comprises a user terminal and a data processing system, wherein the user terminal comprises a user layer and a kernel layer; A communication connection between a user layer of the user terminal and a kernel layer of the user terminal; The data processing system is communicatively connected with the kernel layer; The user terminal is connected to an external device, which is implemented as an external storage device with complete interactive functions; The method comprises: The user layer obtains a user request in response to executing and passing the PIN code identity authentication; and sends the user request to the kernel layer; The kernel layer receives a user request; generates an action instruction based on the user request; and sends the action instruction to the data processing system in response to associating the action instruction with a key application action; The data processing system receives the action instruction; executes the database action based on the action instruction and generates a key action processing result; and feeds back the key action processing result to the kernel layer; The kernel layer receives the key action processing result; generates a key action feedback result based on the key action processing result; and sends the key action feedback result to the user layer.

2. The data interaction method based on user state and kernel state according to claim 1 is characterized in that: The user terminal is connected to an external device, and before the user layer obtains the user request, it includes: The user layer performs an identity authentication process with the external device; In response to the authentication process passing, get the user request.

3. The data interaction method based on user state and kernel state according to claim 2 is characterized in that: The user layer sends the user request to the kernel layer, including: The user layer sends the user request to the kernel layer based on the remote procedure call protocol.

4. The data interaction method based on user state and kernel state according to claim 3 is characterized in that: The kernel layer generates an action instruction based on the user request, including: In response to receiving the user request, the kernel layer matches the user request with an authorization process; and determines a user instruction corresponding to the user request based on a matching result of the authorization process.

5. The data interaction method based on user state and kernel state according to claim 4 is characterized in that: After the kernel layer determines the user instruction corresponding to the user request based on the matching result of the authorization process, it includes: Based on the user instruction, the kernel layer mounts the encrypted directory corresponding to the user instruction; and configures the audit log corresponding to the user instruction.

6. The data interaction method based on user state and kernel state according to claim 1 is characterized in that: The method also includes: the data processing system includes a key generation module, a key storage module and a key life cycle management module.

7. The data interaction method based on user state and kernel state according to claim 6 is characterized in that: The action instruction is associated with a key acquisition action; The key action processing result includes key data, and the key data is used to uniquely indicate the key.

8. The data interaction method based on user state and kernel state according to claim 7 is characterized in that: The method further comprises: The kernel layer receives the key action processing result; stores the key data corresponding to the key action processing result; and generates the key action feedback result based on the key data.

9. The data interaction method based on user state and kernel state according to claim 6 is characterized in that: The action instruction is associated with a key audit action; The key action processing result includes key audit data, and the key audit data is used to indicate the key management process of the data processing system; The data processing system executes a database action based on the action instruction and generates a key action processing result, including: The data processing system performs instruction content analysis on the action instruction to obtain an instruction content analysis result; in response to the instruction content analysis result indicating that the action instruction is an encryption and decryption instruction, the original data file is determined based on the original data path; Backing up the original data file in the new data path to obtain a backup data file; Create a mount command folder corresponding to the original data file; The mount file is encrypted and decrypted through the mount command folder to obtain an encrypted and decrypted file.

10. A data interaction system based on user state and kernel state, characterized in that: The system includes a user terminal and a data processing system, wherein the user terminal includes a user layer and a kernel layer; A communication connection between a user layer of the user terminal and a kernel layer of the user terminal; The data processing system is communicatively connected with the kernel layer; The system is used to execute the data interaction method based on user state and kernel state as described in any one of claims 1 to 9.

Citation Information

Patent Citations

  • Method for encrypting extended file system based on Linux

    CN105373744A

  • Enterprise-level data encryption and access control method and system

    CN118410505A