A computing method and system for information security

By fragmenting data in a distributed environment and comprehensively applying distributed storage, encryption, fault tolerance and permission control technologies, the problem of difficult data security in complex environments is solved, and efficient, secure storage and access of data is achieved.

CN119691780BActive Publication Date: 2025-06-27NANCHANG CAMPUS OF EAST CHINA UNIV OF TECH
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202510192975.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-02-21
Publication Date
2025-06-27
Estimated Expiration
2045-02-21

AI Technical Summary

Technical Problem

The prior art is difficult to ensure the security of data in a complex distributed environment, especially in the fields involving sensitive information and personal privacy, and there are still large research gaps in data security issues.

Method used

By segmenting and fragmenting the input data, randomized storage and pseudo-random offsets are used to disrupt the fragmentation sequence, and combined with distributed storage, encryption, fault tolerance, permission control and intelligent security monitoring technologies, secure storage and access of data are achieved.

Benefits of technology

It effectively improves the security, reliability and management efficiency of data, enhances the protection of data leakage, tampering and loss, and ensures data integrity and privacy protection.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119691780B_ABST
    Figure CN119691780B_ABST
Patent Text Reader

Abstract

The present invention relates to the field of information security technology, and specifically provides a computing method and system for information security. The method steps are as follows: The input data is divided into blocks and fragmented, and the data is distributed to multiple storage nodes through randomization, distributed storage, and hash mapping to ensure the security and distribution flexibility of data storage; An index table is established for all fragments; The data obfuscation mechanism is triggered regularly, and the storage locations of data fragments are adjusted through a pseudo-random function; The integrity of the data is detected by generating check codes and erasure codes to ensure that the data is not tampered with or damaged during transmission or storage, and redundant copies are used to recover in case of data loss; Identity authentication and data integrity are ensured when users access data through permission authentication; The storage nodes and data access behaviors are monitored in real time to detect potential threats and take dynamic adjustment measures. Through multi-level security policies, the present invention effectively improves the security and fault tolerance of data processing.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of information security technology, and particularly relates to a calculation method and system for information security. Background Art

[0002] With the increasing severity of information security issues, traditional protection mechanisms can no longer meet the security requirements of modern data storage and transmission. Especially in the context of distributed storage and cloud computing, the storage, transmission, processing, and access of data all face many security risks, such as risks of data leakage, tampering, and loss. Therefore, how to ensure the integrity, confidentiality, and availability of data in a distributed system has become an important research direction in the field of information security.

[0003] A Chinese patent application for invention with the publication number CN116318628A discloses an information security method that ensures information security and has a small amount of calculation. The client connects to the server to establish communication; the communication between the client and the server first enters the handshake stage. In the handshake stage, the client and the server verify the legitimacy of their identities and generate a symmetric key through three message headers; after the handshake stage passes, the communication between the client and the server enters the normal communication stage and starts to exchange information. In the normal communication stage, the check bits of the message headers are used to perform CRC and DES calculations to determine the legitimacy of identities and the reliability of data. This invention application can achieve the information security attributes of reliable identities, non-tamperable information, and non-forgeable information for both parties in network communication under the limitation of low computing power.

[0004] However, with the continuous upgrading of network attack technologies, the importance of data protection has become even more prominent. Especially in the fields involving sensitive information and personal privacy, data security issues have become difficult problems that need to be solved urgently. Most of the existing technologies focus on single aspects of data protection such as encryption and authentication, and there are still relatively large research gaps in how to comprehensively ensure data security in a complex distributed environment. Summary of the Invention

[0005] The object of the present invention is to address the problems in the background art and propose a calculation method and system for information security.

[0006] The technical solution of the present invention: A calculation method for information security includes the following specific implementation steps:

[0007] S1. Split the input data according to a preset rule, divide it into multiple logically independent small data fragments, and output the fragmented data set;

[0008] S2. Combine the fragmented data set and establish a distribution index table for all fragments, including: fragment number, storage node, data check value;

[0009] S3. Regularly trigger the obfuscation mechanism to dynamically adjust the storage locations of existing data fragments. By migrating the data fragments to other storage nodes, randomly redistribute the storage order of the fragments again;

[0010] S4. Dynamically reorganize the index according to logical rules through the obfuscated fragment set to generate new fragments, and dynamically adjust the storage policy based on the load status of distributed nodes. Prioritize selecting the node with the lowest load to store the new fragments, and at the same time update the index table records, the original fragment set, reorganization rules, storage node information, and checksum values of the reorganized fragments;

[0011] S5. Based on distributed storage, segment the data fragments to generate check codes, construct a distributed check table, and use linear coding to generate data blocks and check blocks. Dynamically adjust the number of redundant blocks in combination with node failure prediction, and pre-generate additional redundant blocks at high-risk nodes. Then, through periodic check tasks and dynamic trigger mechanisms, use machine learning to predict node risks and optimize check scheduling;

[0012] S6. When a user initiates a data access request, verify the permissions. After the permission verification passes, locate the data shards and query the distributed node addresses. After reading the data shards, verify the data integrity through hash value comparison. If it fails, call the error correction mechanism. After the verification is successful, encrypt the data shards using the AES algorithm to generate ciphertext, and return it to the user through a secure transmission protocol;

[0013] S7. Real-time monitor the behaviors of storage nodes and data access. If abnormal behaviors are found, immediately mark them as potential threats. When potential threats are detected, automatically trigger the dynamic adjustment mechanism and automatically trigger the alarm function to notify the administrator to check for security vulnerabilities.

[0014] Preferably, the generation process of the fragmented data set is as follows:

[0015] S21. Set the original data D with a size of |D|. According to the preset storage policy, divide the data into n logical data blocks:

[0016] ;

[0017] where S i represents the size of the i-th logical data block; n represents the number of logical blocks;

[0018] S22. After completing the data block division, enter the fragmentation stage. The logical data block S i will be further divided into smaller random fragments. Each logical data block S i is further decomposed into k fragments F i,j , and the fragment order is shuffled through random offsets as follows:

[0019] S2201, Fragmentation Rule:

[0020] ;

[0021] In the formula, F i,j represents the j-th fragment of the i-th logical data block; k represents the number of fragments of each logical data block;

[0022] S2202, Random Offset: Introduce a pseudo-random function PRNG(seed) to generate the offset δ of each fragment j :

[0023] δ j =PENG(seed) mod |S i |;

[0024] In the formula, seed represents the dynamically generated random seed;

[0025] Among them, δ j determines the starting position of the fragment and breaks the regularity of linear segmentation. The ending position of the offset is determined by δ j+1 or |S i |;

[0026] After fragmentation, distribute these randomized fragments to different storage nodes;

[0027] S23, The fragmented data F i,j is mapped to different storage nodes N according to the distribution strategy p :

[0028] Node Distribution Mapping Rule: Use the hash function H(F i,j ) to calculate the fragment distribution:

[0029] N p =H(F i,j ) mod m;

[0030] In the formula, H(F i,j ) represents the hash value calculated based on the fragment content; m represents the total number of storage nodes; N p represents the target storage node number; H represents the hash function;

[0031] Consistent Hashing: Adopt consistent hashing, and the number of virtual nodes v of each node N p is dynamically adjusted according to its performance weight: p ;

[0032] ;

[0033] In the formula, W pIndicates the node weight; VR represents the total number of virtual nodes; W q Indicates the weight of the q-th storage node;

[0034] S24. Output the fragmented dataset F = {F i,j}.

[0035] Preferably, the migration process of migrating data fragments to other storage nodes is as follows:

[0036] S31. Generate a confusion sequence M for each group of fragments based on the pseudo-random function PRNG(seed') i,j :

[0037] M i,j = shuffle(F i,j , PRNG(seed'));

[0038] In the formula, shuffle() represents a function for randomly arranging the fragment set, used to disrupt the order; PRNG(seed') is a pseudo-random function, and the seed seed' is dynamically updated and adjusted according to the storage node status;

[0039] S32. Cross-confuse the fragments of different logical data blocks to construct a random mapping relationship:

[0040] ;

[0041] In the formula, represents the confused fragment; represents a logical combination based on specific rules, i.e., the exclusive OR operation; k and l represent another randomly selected data block and its fragment number; F i,j represents the j-th fragment in the i-th data block; F k,l represents the l-th fragment in the k-th data block.

[0042] Preferably, the verification process through the periodic verification task and the dynamic trigger mechanism is as follows:

[0043] S41. For each confused and recombined data segment G l,s , generate the corresponding verification code C l,s :

[0044] C l,s = H(G l,s );

[0045] S42. Construct a distributed verification table to record the information of each data segment G l,s , including: data segment identifier R, corresponding verification code C l,s , storage node location N p, the current timestamp T;

[0046] Among them, the data segment identifier R = H(G l,s ||T); || represents the concatenation operation;

[0047] S43. The distributed check table is stored in multiple nodes in a distributed manner: Replicate(C l,s , R');

[0048] Among them, R' represents the number of redundant copies, which is dynamically adjusted according to the importance of the data to ensure the high availability of the check table; Replicate() is a function used to generate data redundant copies;

[0049] S44. For the recombined data segment G l,s , k data blocks and r check blocks are generated through the generating matrix G to form a (k + r) error - correcting code: Encode(G l,s ) = {D1, D2, …, D k , P1, P2, …, P r};

[0050] The encoding process is as follows:

[0051] ;

[0052] Among them, D i represents the data block, i = 1, 2, …, k; P j represents the check block, which is generated through linear encoding, j = 1, 2, …, r; k represents the number of data blocks; r represents the number of check blocks, r ≥ m', and m' represents the number of fault - tolerant nodes;

[0053] S45. Data integrity check: Read the data block D i and the check block P j from the storage node, and verify whether the following linear constraints are satisfied:

[0054] ;

[0055] Data recovery: When some data blocks are lost, the original data is reconstructed using the remaining k + r - m' blocks:

[0056] G l,s = Decode(D i , P j );

[0057] Among them, Decode() represents the decoding formula, and the formula is as follows:

[0058] ;

[0059] Wherein, represents the segment participating in decoding, that is, the currently available data segment;

[0060] Accordingly, according to the importance of the data and the node status, the number of check blocks r is adjusted in real time to optimize the balance between storage and fault tolerance capabilities, and combined with node fault prediction, additional redundant blocks P are pre-generated r+1 , P r+2 and stored on high-risk nodes;

[0061] S46. Schedule check tasks regularly, and read the check table C l,s to compare the integrity of the data segment G l,s :

[0062] ;

[0063] When detecting abnormal node load, increased access latency or other risk signals, dynamically trigger data check tasks; if data corruption or loss is found, immediately start the fault tolerance recovery process to reconstruct the complete data segment G l,s .

[0064] Preferably, the generating matrix G is an r×k matrix, which is used to map k original data blocks into k data blocks and r check blocks. Each element of the matrix is an element on the finite field GF(2 n' ), and n' represents the bit width of the data block;

[0065] ;

[0066] Wherein, a 11 , a 12 , … and a rk represent the coefficients of the generating matrix; k represents the number of data blocks and r represents the number of check blocks.

[0067] Preferably, the access process for the user to initiate a data access request is as follows:

[0068] S61. When the user initiates a data access request, generate an access credential K and verify the user's permissions:

[0069] ;

[0070] Wherein, P u represents the user permission verification result, 1 for passing and 0 for rejecting; U represents the user identity identifier; K represents the access credential; R represents the target resource identifier, corresponding to the data shard index;

[0071] S62. After the permission verification is passed, locate the data shard requested by the user, query the distributed check table according to the resource identifier R, and obtain the distributed node address N of the shard p ;

[0072] S63. After the fragmented reading is completed, perform integrity verification on the fragmented data to ensure that the data has not been tampered with or lost;

[0073] S64. For the target data D i encrypt it using the AES encryption algorithm to obtain the ciphertext CT i , and then return the ciphertext CT i to the user through the network transmission protocol.

[0074] Preferably, the verification process for performing integrity verification on the fragmented data is as follows:

[0075] S71. Calculate the hash value H(D i ) of the read data fragment D i ;

[0076] S72. Extract the check code C l,s of the distributed check table;

[0077] S73. If H(D i ) = C l,s , the verification passes; otherwise, call the error correction mechanism to regenerate the number of fragments.

[0078] Preferably, the generation process of the access credential K is as follows:

[0079] S81. When the user logs in, automatically verify the user's identity. If the authentication passes, a temporary session key K session will be assigned to the user to ensure the legality of this access;

[0080] S82. Generate the final access credential K according to the user's session key K session and the characteristics of the currently accessed resource. The formula is:

[0081] K = f key (K session , C text );

[0082] where C text represents the access context information.

[0083] Preferably, the update process of the index table record is as follows:

[0084] S91. Reconstruct the index from the obfuscated fragment set according to the new logical rules:

[0085] ;

[0086] In the formula, G l,sDenote the data fragments after dynamic recombination; merge() represents the fragment combination operation for generating new fragments; R(i,j) represents the set of mapping relationships of the dynamic recombination rules;

[0087] S92. Use the state of the distributed node, i.e., the node load L, as the dynamic adjustment factor:

[0088] Re(i,j)=argmin p (L p ), p ∈ Nodes;

[0089] Accordingly, select the node with the lowest load to preferentially store the new fragment;

[0090] S93. Update the index table. Each recombined fragment G l,s corresponds to an index record, including: the set of original fragments , the recombination rule Re(i,j), the storage node information N p , and the check value H(G l,s ).

[0091] The technical solution of the present invention: A computing system for information security, which is used to execute the above-mentioned computing method for information security, includes:

[0092] A data distribution module, responsible for data chunking, fragmentation, and dynamic distribution;

[0093] An index management module, used to maintain the distribution index of fragments and storage nodes;

[0094] A fault tolerance and verification module, used to provide data verification and redundancy recovery functions;

[0095] A permission control module, used to control the permissions and content of users to access data;

[0096] A security monitoring module, used to monitor and respond to potential security threats in real time.

[0097] Compared with the prior art, the above technical solution of the present invention has the following beneficial technical effects:

[0098] The present invention designs a computing method and system for information security. Through the comprehensive application of distributed storage, fragmentation, encryption, fault tolerance, and permission control technologies, it comprehensively improves the security, reliability, and management efficiency of data, providing an innovative solution for the field of information security:

[0099] (1)Enhanced data security: By splitting and fragmenting the input data, and using randomized storage and pseudo-random offsets to shuffle the fragment order, the risk of data leakage and tampering is effectively avoided. Data fragmentation can increase the difficulty for attackers to obtain complete data and enhance data security;

[0100] (2)Efficient data distribution and storage management: Using distributed storage nodes and the consistent hashing algorithm to map and distribute fragments, effectively avoiding large-scale data migration problems caused by node changes. Through dynamic adjustment of virtual node weights, the performance and resource utilization rate of storage nodes are optimized;

[0101] (3)Flexible data management and verification mechanism: Combining index management with fragmented data enables efficient data index management and verification, ensuring data integrity and traceability. The dynamically updated index table and data fragment migration mechanism ensure effective data management and storage when the status of storage nodes changes;

[0102] (4)Enhanced fault tolerance and data recovery ability: Through the strategies of erasure coding and redundant copies, the system has strong fault tolerance. Even if some nodes fail, the data can still be recovered through redundant copies, improving data reliability and availability. Regularly triggered verification tasks can detect data corruption in a timely manner and initiate the recovery process to ensure data integrity;

[0103] (5)Intelligent security monitoring and anomaly detection: By real-time monitoring of storage nodes and data access behaviors, potential security threats can be identified in a timely manner and corresponding measures can be taken. This mechanism not only enhances the protection against security vulnerabilities but also improves the ability to quickly respond to abnormal access behaviors;

[0104] (6)Efficient data access control: Through dynamic permission verification and encryption mechanisms, it is ensured that users' access to data is legal and secure. Through multi-factor authentication and dynamically generated access credentials, the authenticity of access is guaranteed, and combined with encryption algorithms, privacy protection during data transmission is ensured;

[0105] (7)Flexible and scalable storage architecture: Using the distributed storage and virtual node mapping mechanism, the system can dynamically expand or reduce storage nodes according to the load situation, enhancing the scalability and adaptability of the system. BRIEF DESCRIPTION OF THE DRAWINGS

[0106] Figure 1 FIG. is a system architecture diagram of a computing system for information security proposed by the present invention. DETAILED DESCRIPTION OF THE INVENTION

[0107] Example 1, as Figure 1As shown in the figure, a computing system for information security proposed by the present invention includes: a data distribution module, an index management module, a fault tolerance and verification module, a permission control module, and a security monitoring module.

[0108] The data distribution module is responsible for data chunking, fragmentation, and dynamic distribution;

[0109] The index management module is used to maintain the distribution index of fragments and storage nodes;

[0110] The fault tolerance and verification module is used to provide data verification and redundant recovery functions;

[0111] The permission control module is used to control the permissions and content for users to access data;

[0112] The security monitoring module is used to monitor and respond to potential security threats in real time.

[0113] Embodiment 2, a computing method for information security proposed by the present invention, which is applied to a computing system for information security proposed in Embodiment 1, and its specific implementation steps are as follows:

[0114] S1. The data distribution module divides the input data according to preset rules and divides it into multiple logically independent small data fragments. The specific implementation process is as follows:

[0115] S11. Set the original data D, whose size is |D|, and divide the data into n logical data blocks according to the preset storage strategy:

[0116] ;

[0117] where S i represents the size of the i-th logical data block; n represents the number of logical chunks;

[0118] It should be noted that the preset storage strategy is: on the basis of conventional logical chunking, combined with a data content analysis algorithm, further optimized for data types (including but not limited to text, image, or time series):

[0119] Text data: Chunked according to semantic structure (including but not limited to paragraphs);

[0120] Image data: Based on feature region segmentation, including but not limited to edges, color blocks;

[0121] Time series data: Divided according to time windows or event frequencies;

[0122] S12. After completing data chunking, enter the fragmentation stage, and the logical data block S i will be further broken down into smaller random fragments to improve security and distribution flexibility. Each logical data block Si Further decomposed into k fragments F i,j , and the order of the fragments is scrambled by random offsets. The specific implementation process is as follows:

[0123] S1201. Fragmentation rule:

[0124] ;

[0125] In the formula, F i,j represents the j-th fragment of the i-th logical data block; k represents the number of fragments of each logical data block;

[0126] S1202. Random offset: Introduce the pseudo-random function PRNG(seed) to generate the offset δ j of each fragment:

[0127] δ j = PENG(seed) mod |S i |;

[0128] In the formula, seed represents the dynamically generated random seed;

[0129] Among them, δ j determines the starting position of the fragment and breaks the regularity of the linear segmentation. The offset end position is determined by δ j+1 or |S i |;

[0130] After fragmentation is completed, these randomized fragments are allocated to different storage nodes;

[0131] S13. The fragmented data F i,j is mapped to different storage nodes N p according to the distribution strategy. The specific implementation process is as follows:

[0132] S1301. Node distribution mapping rule: Use the hash function H(F i,j ) to calculate the fragment distribution:

[0133] N p = H(F i,j ) mod m;

[0134] In the formula, H(F i,j ) represents the hash value calculated based on the fragment content; m represents the total number of storage nodes; N p represents the target storage node number; H represents the hash function;

[0135] S1302. Consistent hashing: Adopt consistent hashing to avoid large-scale data migration caused by node changes. The number of virtual nodes v p of each node Np Dynamically adjust according to its performance weight:

[0136] ;

[0137] Wherein, W p represents the node weight; VR represents the total number of virtual nodes; W q represents the weight of the q-th storage node;

[0138] S14. Output the fragmented data set F = {F i,j}.

[0139] S2. The index management module combines the fragmented data set F = {F i,j} to establish an index table I j,j for all fragments, implementing an efficient data management and verification mechanism:

[0140] S21. Design the index content:

[0141] Each index record includes: fragment number (i, j), storage node N p , data check value H(F i,j );

[0142] Index table formula: I i,j = {(i, j), N p , H(F i,j )};

[0143] S22. Dynamic index update: When the storage node status changes (including but not limited to failure or expansion), dynamically update the index table and synchronously migrate the affected fragments.

[0144] S3. The data distribution module periodically triggers the obfuscation mechanism to dynamically adjust the storage locations of the existing data fragments. By migrating the data fragments to other storage nodes, the storage order of the fragments is randomly redistributed again. The specific implementation process is as follows:

[0145] S31. The data distribution module generates an obfuscation sequence M i,j for each group of fragments based on the pseudo-random function PRNG(seed'):

[0146] M i,j = shuffle(F i,j , PRNG(seed'));

[0147] Wherein, shuffle() represents a function for randomly arranging the fragment set to disrupt the order; PRNG(seed') is a pseudo-random function, and the seed seed' is dynamically updated and adjusted according to the storage node status (including but not limited to load or network latency).

[0148] S32. Cross - mix the fragments of different logical data blocks to construct a random mapping relationship:

[0149] ;

[0150] In the formula, represents the mixed fragment; represents the logical combination based on specific rules. In this embodiment, the exclusive - OR operation is adopted; k and l represent another randomly selected data block and its fragment number; F i,j represents the j - th fragment in the i - th data block; F k,l represents the l - th fragment in the k - th data block.

[0151] S4. During the confusion, the index management module automatically updates the fragment distribution index table and discards the old distribution information at the same time. The specific implementation steps are as follows:

[0152] S41. The set of confused fragments is re - indexed according to the new logical rules:

[0153] ;

[0154] In the formula, G l,s represents the dynamically re - combined data fragment; merge() represents the fragment combination operation for generating a new fragment; R(i, j) represents the set of mapping relationships of the dynamic re - combination rules;

[0155] S42. Use the state of the distributed node (node load L) as the dynamic adjustment factor:

[0156] Re(i, j)=argmin p (L p ), p ∈ Nodes;

[0157] Accordingly, select the node with the lowest load to preferentially store the new fragment;

[0158] S43. Update the index table. Each re - combined fragment G l,s corresponds to an index record, including: the original fragment set , the re - combination rule Re(i, j), the storage node information N p , and the check value H(G l,s ).

[0159] S5. The fault - tolerance and verification module takes the check code, check table, erasure code, and dynamic trigger mechanism as the core, dynamically adjusts the parameters and strategies, detects whether the data is tampered or damaged through the verification mechanism, and uses the fault - tolerance strategy to ensure the data recoverability. The specific implementation process is as follows:

[0160] S51. For each data segment G after confusion and recombination l,s , generate the corresponding check code C l,s :

[0161] C l,s =H(G l,s );

[0162] Accordingly, the check code provides a unique integrity identifier for each data segment, and any form of tampering or damage can be quickly detected during data transmission or storage;

[0163] S52. Construct a distributed check table to record the information of each data segment G l,s , including: data segment identifier R, corresponding check code C l,s , storage node location N p , current timestamp T;

[0164] Among them, the data segment identifier R = H(G l,s ||T); || represents the concatenation operation;

[0165] S53. The distributed check table is stored on multiple nodes in a distributed manner: Replicate(C l,s , R');

[0166] Among them, R' represents the number of redundant copies, which is dynamically adjusted according to the importance of the data to ensure the high availability of the check table; Replicate() is a function used to generate data redundant copies (i.e., replicate data segments);

[0167] It should be noted that the function of Replicate() is: according to the system's fault tolerance strategy, generate and distribute the redundant copies of the data segment G l,s to different storage nodes, and ensure that even if some nodes fail, the data can still be restored through the redundant copies, improving the reliability and fault tolerance of the system;

[0168] It should be noted that redundant copies (Redundant Copies) refer to multiple identical copies of the original data that are replicated and stored on multiple nodes in a distributed storage system or data management system to improve the reliability, availability, and fault tolerance of the data;

[0169] S54. For the recombined data segment G l,s , generate k data blocks {D1, D2,..., D k} and r check blocks {P1, P2,..., P r} through the generating matrix G, and form a (k + r) error correction code: Encode(G l,s ) = {D1, D2,..., Dk , P1, P2, …, P r};

[0170] The encoding process is as follows:

[0171] ;

[0172] Among them, D i represents a data block, i = 1, 2, …, k; P j represents a parity block, generated by linear encoding, j = 1, 2, …, r; k represents the number of data blocks; r represents the number of parity blocks, r ≥ m', where m' represents the number of fault-tolerant nodes;

[0173] Among them, the generator matrix G is an r×k matrix used to map k original data blocks into k data blocks and r parity blocks. Each element (coefficient) of the matrix is an element in the finite field GF(2 n' ), and n' represents the bit width of the data block;

[0174] ;

[0175] In the formula, a 11 , a 12 , …, and a rk represent the coefficients of the generator matrix;

[0176] S55. Data integrity check: Read the data block D i and the parity block P j from the storage nodes and verify whether the following linear constraints are satisfied:

[0177] ;

[0178] Data recovery: When some data blocks are lost, reconstruct the original data using the remaining k + r - m' blocks:

[0179] G l,s = Decode(D i , P j );

[0180] Among them, Decode() represents the decoding formula, and the formula is as follows:

[0181] ;

[0182] In the formula, represents the segments participating in decoding, that is, the currently available data segments;

[0183] Accordingly, based on the importance of the data and the node status, adjust the number of parity blocks r in real time, optimize the balance between storage and fault tolerance, and combine node fault prediction to pre-generate additional redundant blocks Pr+1 ,P r+2 Storing on high-risk nodes improves the system's fault recovery efficiency;

[0184] S56, regularly schedule the verification task, by reading the verification table C l,s Compare data segment G l,s For completeness:

[0185] ;

[0186] When abnormal node load, increased access latency or other risk signals are detected, the data verification task is dynamically triggered; if data damage or loss is found, the fault-tolerant recovery process is immediately started to rebuild the complete data fragment G l,s ;

[0187] Based on this, machine learning is used to predict the risk of node failure, verify the data of high-risk nodes in advance, improve response speed, and use multiple nodes for parallel verification to improve the execution efficiency of verification tasks.

[0188] S6. The permission control module realizes efficient user access to data based on the output results of distributed verification and fault tolerance, while ensuring the integrity and authenticity of the data. The specific implementation process is as follows:

[0189] S61. When a user initiates a data access request, the user's authority is first verified:

[0190] ;

[0191] Where P u Indicates the result of user permission verification, 1 means passed and 0 means rejected; U indicates the user identity identifier; K indicates the access credential; R indicates the target resource identifier, which corresponds to the data shard index;

[0192] It should be noted that the access credential K: when a user logs in, the user's identity is automatically verified (including but not limited to username and password or multi-factor authentication). If the authentication is successful, a temporary session key K will be assigned to the user. session , to ensure the legitimacy of this access, and then use the user's session key K session The final access credential K is generated by the resource characteristics currently being accessed. The formula is: K=f key (K session ,C text ), C text Indicates access context information (including but not limited to user role, permission scope, access time);

[0193] S62. After the permission verification passes, locate the data shards requested by the user, query the distributed verification table according to the resource identifier R, and obtain the distributed node address N of the shards p ;

[0194] S63. After the shard reading is completed, perform integrity verification on the shard data to ensure that the data has not been tampered with or lost. The verification process is as follows:

[0195] S6301. Calculate the hash value H(D i of the read data shard i );

[0196] S6302. Extract the verification code C of the distributed verification table l,s ;

[0197] S6303. If H(D i ) = C l,s , the verification passes, and S64 is executed; otherwise, the error correction mechanism is called to regenerate the shard numbers;

[0198] S64. Encrypt the target data D i using the AES (Advanced Encryption Standard) encryption algorithm to obtain the ciphertext CT i , and then return the ciphertext CT i to the user through the network transmission protocol (including but not limited to HTTPS).

[0199] S7. The security monitoring module monitors the behaviors of storage nodes and data accesses in real time, including access frequency, request sources, and data migration situations. If abnormal behaviors (including but not limited to high-frequency accesses of a single node or multiple failed authentication attempts) are found, they are immediately marked as potential threats. When potential threats are detected, a dynamic adjustment mechanism is automatically triggered, including but not limited to reallocating data fragments, changing the fragment storage order, or locking sensitive data access permissions. In addition, an alarm function is automatically triggered to notify the administrator to check for possible security vulnerabilities.

[0200] The embodiments of the present invention have been described in detail above with reference to the accompanying drawings. However, the present invention is not limited to this. Various changes can be made without departing from the spirit of the present invention within the knowledge of those skilled in the art of the relevant technical field.

Claims

1. A computing method for information security, characterized in that: The specific implementation steps include the following: S1. Split the input data into multiple logically independent small data fragments according to preset rules, and output the fragmented data sets; The generation process of the fragmented dataset is as follows: A1. Assume the original data D has a size of |D|. According to the preset storage strategy, the data is divided into n logical data blocks: ; In the formula, S i Indicates the size of the i-th logical data block; n indicates the number of logical blocks; A2. After data segmentation is completed, the fragmentation phase begins. The logical data block S i will be further subdivided into smaller random fragments, with each logical data block S i Further decomposed into k fragments F i,j , and disrupt the fragment order by random offset, as follows: Fragmentation rules: ; In the formula, F i,j represents the jth fragment of the i-th logical data block; k represents the number of fragments of each logical data block; Random offset: Introduce a pseudo-random function PRNG (seed) to generate the offset δ of each fragment j : δ j =MONEY(seed) mod |S i |; In the formula, seed represents a dynamically generated random seed; Among them, δ j Determine the starting position of the fragment and break the regularity of linear segmentation. The end position of the offset is determined by δ j+1 or |S i | OK; After fragmentation is completed, these randomized fragments are distributed to different storage nodes; A3. Fragmented data F i,j Map to different storage nodes N according to the distribution strategy p : Node distribution mapping rule: Using the hash function H(F i,j ) Calculate the fragmentation distribution: N p =H(F i,j ) mod m; In the formula, H(F i,j ) represents the hash value calculated based on the fragment content; m represents the total number of storage nodes; N p represents the target storage node number; H represents the hash function; Consistent hashing: Using consistent hashing, each node N p The number of virtual nodes v p Dynamically adjust according to its performance weight: ; Where W p represents the node weight; VR represents the total number of virtual nodes; W q represents the weight of the qth storage node; A4. Output the fragmented data set F = {F i,j }; S2. Combine the fragmented data set and create a distribution index table for all fragments, including fragment number, storage node, and data checksum value; S3. Trigger the obfuscation mechanism regularly to dynamically adjust the storage location of existing data fragments, migrate data fragments to other storage nodes, and redistribute the storage order of fragments randomly; S4, dynamically reorganize the index according to the logical rules through the obfuscated fragment set to generate new fragments, and dynamically adjust the storage strategy according to the distributed node load status, give priority to the node with the lowest load to store the new fragment, and update the index table record at the same time, reorganize the original fragment set, reorganization rules, storage node information and check value of the fragment; S5. Based on distributed storage, data fragments are segmented, checksums are generated, distributed checksum tables are constructed, and linear coding is used to generate data blocks and checksums. The number of redundant blocks is dynamically adjusted in combination with node failure prediction, and additional redundant blocks are pre-generated at high-risk nodes. Then, through periodic check tasks and dynamic trigger mechanisms, machine learning is used to predict node risks and optimize check scheduling. S6. The user initiates a data access request and verifies the authority. After the authority verification is passed, the data shard is located and the distributed node address is queried. After reading the data shard, the data integrity is verified by hash value comparison. If it fails, the error correction mechanism is called. After the verification is successful, the data shard is encrypted using the AES algorithm to generate ciphertext, and then returned to the user through a secure transmission protocol; S7. Monitor the behavior of storage nodes and data access in real time. If abnormal behavior is found, it will be immediately marked as a potential threat. When a potential threat is detected, the dynamic adjustment mechanism will be automatically triggered, and the alarm function will be automatically triggered to notify the administrator to check for security vulnerabilities.

2. A calculation method for information security according to claim 1, characterized in that: The migration process of migrating data fragments to other storage nodes is as follows: S31, generating a confusion sequence M for each group of fragments based on a pseudo-random function PRNG (seed') i,j : M i,j =shuffle(F i,j ,PRNG(seed')); In the formula, shuffle() represents a function that randomly arranges a set of fragments to disrupt the order; PRNG(seed') is a pseudo-random function, and the seed seed' is dynamically updated and adjusted according to the storage node status; S32, cross-confusion of fragments of different logical data blocks to build a random mapping relationship: ; In the formula, Indicates the fragments after confusion; represents a logical combination based on a specific rule, i.e., an XOR operation; k and l represent another randomly selected data block and its fragment number; F i,j represents the jth fragment in the i-th data block; F k,l Represents the lth fragment in the kth data block.

3. A calculation method for information security according to claim 1, characterized in that: The verification process through periodic verification tasks and dynamic triggering mechanism is as follows: S41, for each obfuscated and reorganized data segment G l,s , generate the corresponding check code C l,s : C l,s =H(G l,s ); S42, build a distributed check table to record each data segment G l,s Information including: data segment identifier R, corresponding check code C l,s , storage node location N p , current timestamp T; Wherein, the data segment identifier R=H(G l,s ||T);|| represents the splicing operation; S43, the distributed check table is stored in multiple nodes in a distributed manner: Replicate (C l,s ,R'); Among them, R' represents the number of redundant copies, which is dynamically adjusted according to the importance of the data to ensure the high availability of the checksum table; Replicate() is a function used to generate redundant copies of data; S44, for the reorganized data segment G l,s , k data blocks and r check blocks are generated by generating matrix G to form (k+r) error correction code: Encode(G l,s )={D1,D2,…,D k ,P1,P2,…,P r }; The encoding process is as follows: ; Among them, D i represents a data block, i=1,2,…,k; P j represents the check block, which is generated by linear coding, j=1,2,…,r; k represents the number of data blocks; r represents the number of check blocks, r≥m', m' represents the number of fault-tolerant nodes; S45, data integrity check: read data block D from the storage node i Sum check block P j , verify that the following linear constraints are satisfied: ; Data recovery: When some data blocks are lost, the original data is reconstructed using the remaining k+r-m' blocks: G l,s =Decode(D i ,P j ); Among them, Decode() represents the decoding formula, which is as follows: ; In the formula, Indicates the fragment involved in decoding, that is, the currently available data fragment; Based on this, the number of check blocks r is adjusted in real time according to the importance of the data and the node status, the balance between storage and fault tolerance is optimized, and additional redundant blocks P are pre-generated in combination with node failure prediction. r+1 ,P r+2 Storage on high-risk nodes; S46, regularly schedule the verification task, by reading the verification table C l,s Compare data segment G l,s For completeness: ; When abnormal node load, increased access latency or other risk signals are detected, the data verification task is dynamically triggered; if data is found to be damaged or lost, the fault-tolerant recovery process is immediately started to rebuild the complete data fragment G l,s .

4. A calculation method for information security according to claim 3, characterized in that: The generator matrix G is an r×k matrix used to map k original data blocks into k data blocks and r check blocks. Each element of the matrix is ​​a finite field GF(2 n' ), n' represents the bit width of the data block; ; In the formula, a 11 、a 12 , … and a rk represents the coefficients of the generator matrix; k represents the number of data blocks and r represents the number of check blocks.

5. A calculation method for information security according to claim 1, characterized in that: The access process for a user to initiate a data access request is as follows: S61. When a user initiates a data access request, an access credential K is generated and the user's authority is verified: ; Where P u Indicates the result of user permission verification, 1 means passed and 0 means rejected; U indicates the user identity identifier; K indicates the access credential; R indicates the target resource identifier, which corresponds to the data shard index; S62: After the permission check is passed, locate the data shard requested by the user, query the distributed check table according to the resource identifier R, and obtain the distributed node address N of the shard. p ; S63. After the shard reading is completed, the integrity of the shard data is verified to ensure that the data has not been tampered with or lost; S64. Target data D i Use the AES encryption algorithm to encrypt and obtain the ciphertext CT i , and then the ciphertext CT i The data is returned to the user via the network transmission protocol.

6. A calculation method for information security according to claim 5, characterized in that: The verification process for integrity verification of shard data is as follows: S71. Calculate the read data fragment D i The hash value H(D i ); S72, extract the check code C of the distributed check table l,s ; S73, if H(D i )=C l,s , the verification passes, otherwise the error correction mechanism is called to regenerate the number of shards.

7. A computing method for information security according to claim 1, characterized in that: The generation process of access credential K is as follows: S81. When a user logs in, the user's identity is automatically verified. If the authentication is successful, a temporary session key K is assigned to the user. session , to ensure the legitimacy of this visit; S82: Based on the user's session key K session The final access credential K is generated by the resource characteristics currently being accessed. The formula is: K=f key (K session ,C text ); Among them, C text Represents access context information.

8. A computing method for information security according to claim 1, characterized in that: The update process for updating index table records is as follows: S91. The obfuscated fragment set is reindexed according to the new logical rules: ; In the formula, G l,s Represents the dynamically reorganized data fragment; merge() represents the fragment combination operation, which is used to generate a new fragment; R(i,j) represents the mapping relationship set of dynamic reorganization rules; S92. Use the state of the distributed nodes, that is, the node load L, as a dynamic adjustment factor: Re(i,j)=argmin p (L p ),p∈Nodes; Based on this, the node with the lowest load is selected to store the new fragment first; S93, update the index table, each recombinant fragment G l,s Corresponding to an index record, including: the original fragment set , reorganization rule Re(i,j), storage node information N p , check value H(G l,s ).

9. A computing system for information security, used to execute a computing method for information security as claimed in any one of claims 1 to 8, characterized in that: include: Data distribution module, responsible for data segmentation, fragmentation and dynamic distribution; Index management module, used to maintain the distribution index of fragments and storage nodes; Fault tolerance and verification module, used to provide data verification and redundancy recovery functions; Permission control module, used to control the permissions and content of user access to data; Security monitoring module, used to monitor and respond to potential security threats in real time.

Citation Information

Patent Citations

  • Information security method capable of ensuring information security and small in calculation amount

    CN116318628A

  • Method and device for ensuring data security of distributed storage system

    CN118862170A

  • Auditing data distributed storage method based on multi-layer encryption strategy and related product

    CN119441229A