A data security processing system and method based on port information

By performing personnel identity verification, data labeling, grouping, replacement and hash value sorting processing in the data security processing system, displacement encryption packages are generated, and matching storage with distributed storage nodes according to the data type, the problems of data encryption security and storage efficiency in the prior art are solved, and efficient and secure data storage management is achieved.

CN119740253BActive Publication Date: 2025-05-06ZHEJIANG ELECTRONIC PORT CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202510237166.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-03-01
Publication Date
2025-05-06
Estimated Expiration
2045-03-01

AI Technical Summary

Technical Problem

Existing data security processing systems cannot fully guarantee the security and effectiveness of data during the encryption process. At the same time, it is difficult to efficiently store encrypted data in a distributed storage environment and make rational use of storage resources.

Method used

The user's identity verification and analysis unit is used to verify the identity of the user. After generating the correct verification results, the data are labeled, grouped, and replaced, and the hash sort is used to generate a displacement encryption package. Then, the encrypted data is classified according to the data type, and is stored in a matching manner with the distributed storage node, and the storage is filtered in combination with the storage distribution characteristics.

Benefits of technology

Ensure the security and effectiveness of the encryption process. The strength and complexity of encryption are increased through hash calculation and nine-grid sorting, the utilization rate of storage resources is improved, the load balancing of storage nodes is realized, and the storage management of encrypted data is optimized.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119740253B_ABST
    Figure CN119740253B_ABST
Patent Text Reader

Abstract

The present invention discloses a data security processing system and method based on port information. The present invention relates to the field of data processing technology, and solves the technical problems of being unable to fully guarantee the security and effectiveness of data in the encryption process, efficiently storing encrypted data, and reasonably utilizing storage resources. The present invention ensures the security and effectiveness of the encryption process by adopting a carefully constructed S box to perform byte replacement operations based on strict mathematical design and security considerations. The strength and complexity of encryption are increased by grouping data, and subsequent hash value calculation and sorting processing, effectively preventing data from being cracked and tampered with. According to the data type of the displacement encryption package, it is matched and stored with the corresponding type of distributed storage nodes. When unevenly distributed, it is matched and stored according to the capacity interval, thereby improving the utilization rate of storage resources, realizing the load balancing of storage nodes, and optimizing the storage management of encrypted data.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of data processing, and in particular to a data security processing system and method based on port information. Background Art

[0002] With the rapid development of information technology, data security and the accuracy of user identity authentication have become crucial. In various information systems, a large amount of data information and personnel information needs to be processed.

[0003] The patent application with application number CN202410119897.3 discloses a data security processing method and system. The above patent application constructs a first data security protection rule and a second data security protection rule, and identifies unsafe data processing processes through the first data security protection rule and the second data security protection rule, thereby effectively ensuring or improving the security of the data processing process, and is provided with an abnormal database and a security database, which can partition and store different types of data to avoid affecting normal data.

[0004] However, when some existing data security processing systems process data, on the one hand, the data may contain sensitive content, such as commercial secrets, personal privacy, etc., and effective encryption protection must be performed to prevent data leakage and illegal access. The security and effectiveness of the data during the encryption process cannot be fully guaranteed. On the other hand, different users have different permissions and operation requirements, and the identity of personnel needs to be accurately verified to ensure that only authorized users can access and operate the corresponding data. At the same time, in a distributed storage environment, how to efficiently store encrypted data and reasonably use storage resources. Summary of the invention

[0005] In view of the deficiencies of the prior art, the present invention provides a data security processing system and method based on port information, which solves the problem of being unable to fully guarantee the security and effectiveness of data during the encryption process, as well as the problem of efficiently storing encrypted data and reasonably utilizing storage resources.

[0006] To achieve the above objectives, the present invention is implemented through the following technical solutions: A data security processing system based on port information, comprising:

[0007] The personnel identity verification and analysis unit is used to transmit the data information to the data encryption processing unit, verify the obtained personnel information, generate the identity verification result, and transmit the correct verification result to the data encryption unit;

[0008] The data encryption processing unit is used to process the data information according to the correct verification result, obtain the replacement group data by labeling the acquired data and performing grouping and replacement processing according to the data capacity, calculate the hash value of the replacement group data, and sort it into a nine-square grid based on the size of the hash value to generate a displacement encryption package, and transmit it to the encrypted data storage and analysis unit at the same time;

[0009] The encrypted data storage and analysis unit is used to perform storage analysis on the acquired displacement encryption packages, classify them according to the data type in the displacement encryption packages, generate single-type encryption packages and multi-type encryption packages, and classify the distributed storage nodes according to the stored data type to obtain single-type storage nodes and multi-type storage nodes, store the classified displacement encryption packages and the classified distributed storage nodes accordingly, and screen them according to the data capacity in combination with the corresponding storage distribution characteristics to generate encrypted storage information and transmit it to the management information display unit.

[0010] As a further solution of the present invention, it also includes an information comprehensive acquisition unit and a management information display unit;

[0011] The information comprehensive acquisition unit is used to acquire data information and personnel information and transmit the two to the personnel identity verification and analysis unit;

[0012] The management information display unit is used to display the verification error results, displacement encryption packages and encrypted storage information.

[0013] As a further solution of the present invention, the specific manner in which the personnel identity verification analysis unit generates the identity verification result is:

[0014] Obtain personnel information and identify the personnel information at the same time, then determine whether the personnel information is the same as the information recorded in the system. If they are the same, it means that the personnel information verification is correct, and a correct verification result is generated and transmitted to the data encryption processing unit. If they are not the same, it means that the personnel information verification is wrong, and a verification error result is generated and transmitted to the management information display unit.

[0015] As a further solution of the present invention, the specific manner in which the data encryption processing unit generates the replacement packet data is:

[0016] Obtain all data in the data information and label them as i, where i=1, 2, ..., j, where j represents the number of data, and then group the data i to obtain grouped data;

[0017] Establish a lookup table, pre-build an S-box of 256 bytes, and the S-box can be regarded as a special mapping table. At the same time, each index position uniquely corresponds to a specific replacement value. The value of each byte is used as an index to accurately search in the pre-defined S-box. If the corresponding index position is found, the byte is replaced with the value stored in the index position in the S-box, and the replacement packet data is generated;

[0018] Similarly, all data i are processed in the same way, and corresponding replacement group data are obtained.

[0019] As a further solution of the present invention, the specific method of the data encryption processing unit generating the displacement encryption packet is:

[0020] Get all the replacement grouped data, then select nine groups of replacement grouped data in sequence according to the labels as the data to be analyzed, and arrange them into the pre-established nine-square grid in the order of the labels, and calculate the hash value of the data to be analyzed at the same time, and determine whether there is data to be analyzed with the same hash value. If so, get the corresponding data to be analyzed, and reverse the original sorting labels of the two groups of data to be analyzed. If not, sort the data to be analyzed into the nine-square grid in order from small to large according to the hash value to generate a displacement encryption package.

[0021] As a further solution of the present invention, the specific manner in which the encrypted data storage analysis unit performs storage analysis on the displacement encrypted package is:

[0022] First, the displacement encryption package is labeled as n, and n=1, 2, ..., m, where m represents the number of displacement encryption packages. Then, the data type corresponding to the displacement encryption package n is obtained, and the displacement encryption package n is classified according to the data type to generate a single-type encryption package and a multi-type encryption package, which are respectively denoted as n a and n b ;

[0023] Then, the distributed storage nodes are obtained and labeled as o, where o=1, 2, ..., p, where p represents the number of distributed storage nodes. At the same time, the distributed storage nodes o are classified according to the data types corresponding to the stored data to generate single-type storage nodes and multi-type storage nodes, which are respectively denoted as o a and b And the distributed storage nodes are stored correspondingly to the displacement data packets.

[0024] As a further solution of the present invention, the specific manner in which the encrypted data storage analysis unit stores the distributed storage nodes and the displacement data packets in correspondence is:

[0025] Get all single-type storage nodes o aThe corresponding stored data is obtained, and the data capacity corresponding to the stored data is obtained. At the same time, the single type storage node o is a The storage distribution characteristics are obtained, and uniform distribution results and uneven distribution results are generated;

[0026] Perform storage analysis on the generated uniform distribution results and obtain the single-type storage nodes o for all uniform distribution results a , while calculating the single type storage node o a The capacity average of the data stored in the , and then the single type of encrypted packages are screened based on the capacity average as a standard to generate encrypted storage information;

[0027] Perform storage analysis on the generated uneven separation results and obtain single-type storage nodes o for all uneven separation results b , while for a single type of storage node o b The data capacity of the stored data is obtained and the corresponding capacity interval is generated. Then, the data capacity of the single-type encrypted package is obtained and matched with the capacity interval. The matching single-type encrypted packages are matched with the corresponding single-type storage nodes o b Perform matching storage and generate encrypted storage information.

[0028] As a further solution of the present invention, the specific method of the encrypted data storage analysis unit to screen a single type of encrypted package based on the capacity average value to generate encrypted storage information is:

[0029] Get the data capacity of a single-type encrypted packet, calculate the difference between its data capacity and the mean capacity, and compare the difference with the threshold. If the difference is less than the threshold, store the single-type encrypted packet in the corresponding single-type storage node o a , and generate encrypted storage information at the same time. If the difference is greater than the threshold, select the single-type storage node o corresponding to the difference less than the threshold. a , and store a single type of encrypted package to generate encrypted storage information.

[0030] A data security processing method based on port information, the method specifically comprises the following steps:

[0031] Step S001: Verify the user's personal information and generate a correct verification result or an incorrect verification result;

[0032] Step S002: according to the verification result, the data is grouped according to the data capacity to obtain grouped data, and at the same time, the grouped data is replaced according to the established lookup table to generate replaced grouped data;

[0033] Step S003, calculating the hash value of the replacement group data, and sorting them into a nine-square grid based on the size of the hash value to generate a displacement encryption package;

[0034] Step S004: Classify the data types in the displacement encryption package to generate a single-type encryption package and a multi-type encryption package, and classify the distributed storage nodes according to the stored data types to obtain single-type storage nodes and multi-type storage nodes;

[0035] Step S005: The classified displacement encryption packages and the classified distributed storage nodes are stored correspondingly, and at the same time, the corresponding storage distribution characteristics are combined and screened according to data capacity to generate encrypted storage information.

[0036] The present invention provides a data security processing system and method based on port information. Compared with the prior art, it has the following beneficial effects:

[0037] The present invention uses a carefully constructed S-box to perform byte replacement operations, based on rigorous mathematical design and security considerations, to ensure the security and effectiveness of the encryption process. By grouping the data into groups of 8 bytes, and randomly supplementing the last data less than 8 bytes, as well as subsequent hash value calculation and sorting, the strength and complexity of the encryption are further increased, effectively preventing the data from being cracked and tampered with;

[0038] According to the data type of the displacement encryption package, it is matched and stored with the corresponding type of distributed storage nodes. For a single type of encryption package, different storage strategies are adopted according to the storage distribution characteristics of the single type of storage node, such as screening storage according to the capacity mean and threshold when evenly distributed, and matching storage according to the capacity interval when unevenly distributed, which improves the utilization of storage resources, realizes the load balancing of storage nodes, and optimizes the storage management of encrypted data. BRIEF DESCRIPTION OF THE DRAWINGS

[0039] Figure 1 This is a block diagram of the system principle of the present invention;

[0040] Figure 2 It is a step method diagram of the present invention;

[0041] Figure 3 This is a schematic diagram of the nine-square grid of the present invention;

[0042] Figure 4 Schematic diagram of the displacement data packet sorting transformation of the present invention. DETAILED DESCRIPTION

[0043] The following will be combined with the drawings in the embodiments of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.

[0044] For example, see Figure 1 The present application provides a data security processing system based on port information, specifically including: an information comprehensive acquisition unit, a personnel identity verification unit, a data encryption processing unit, a data storage and analysis unit, and a management information display unit, and combined with Figure 1 It can be known that the above functional units are electrically connected in a unidirectional manner.

[0045] The information comprehensive acquisition unit is used to acquire data information and personnel information, and transmit the two to the personnel identity verification and analysis unit.

[0046] Personnel identity verification and analysis unit, which is used to transmit data information to the data encryption processing unit, verify the acquired personnel information, and generate identity verification results. The specific verification method is as follows:

[0047] Obtain personnel information and identify the personnel information at the same time. The personnel information here includes user name / password, digital certificate, etc. Then determine whether the personnel information is the same as the information recorded in the system. If they are the same, it means that the personnel information is verified correctly, and a verification result is generated, and it is transmitted to the data encryption processing unit at the same time. If they are not the same, it means that the personnel information is verified incorrectly, and a verification error result is generated, and it is transmitted to the management information display unit at the same time. Specifically, for the verification error result, it means that the user does not have the authority to perform a series of operations such as data access. Secondly, collect various attribute information of users at the same time, such as user role, department, position, work content, business needs, security level, etc., and classify and grade the collected user attributes. For example, user roles are divided into different levels such as administrators, ordinary users, and visitors; according to department functions, they are divided into sales departments, technical departments, and financial departments; according to security levels, they can be divided into three levels: high, medium, and low. According to the characteristics of the system or resources, determine the type of permissions that need to be set, such as read, write, modify, delete, execute, and approve.

[0048] The data encryption processing unit is used to process the data information according to the correct verification result, and obtains the grouped data by labeling the acquired data and grouping them according to the data capacity. The specific processing method is as follows:

[0049] All data in the data information are obtained and labeled as i, where i=1, 2, ..., j, where j represents the number of data, and then the data i is grouped to obtain grouped data, and the grouping process is to group the data i into groups of 8 bytes, and at the same time, the data with less than 8 bytes remaining at the end is supplemented, and the supplementation method is random supplementation;

[0050] Then, a lookup table is established, and an S-box of 256 bytes is carefully constructed in advance. This S-box can be regarded as a special mapping table. In this mapping table, each index position (from 0x00 to 0xFF) uniquely corresponds to a specific replacement value, and the mapping relationship is not set arbitrarily, but is based on rigorous mathematical design and security considerations. Then, the value of each byte is used as an index to accurately search in the pre-defined S-box. Once the corresponding index position is found, the byte is replaced with the value stored in the index position in the S-box, and the replacement group data is generated. Similarly, all data i are processed in the same way, and the corresponding replacement group data is obtained.

[0051] In a specific example, for the first byte 0x35: its value 0x35 is used as the index to search in the S box. Assuming that in this S box, the value stored at the position with index 0x35 is 0x9d, then the byte 0x35 will be replaced by 0x9d.

[0052] For the second byte 0x7e: Also use 0x7e as the index to search the S box. If the value at index 0x7e in the S box is 0xf5, 0x7e is replaced with 0xf5.

[0053] For the third byte 0x89: locate it in the S box with 0x89 as the index. If the corresponding value is 0xb3, 0x89 is replaced by 0xb3. After such byte replacement operation, the original data to be encrypted [0x35, 0x7e, 0x89] is transformed into [0x9d, 0xf5, 0xb3].

[0054] Get all the replacement grouped data, and the replacement grouped data here is the grouped data corresponding to the same data i, then select nine groups of replacement grouped data in sequence according to the labels as the data to be analyzed, and arrange them in the pre-established nine-square grid in the order of the labels, and as shown in the attached figure Figure 3As shown, from the upper left to the lower right are 1, 2, 3, 4, 5, 6, 7, 8 and 9 respectively, and the hash value of the data to be analyzed is calculated at the same time, and the MD5 algorithm is used as an example for calculation here, and it is determined whether there is data to be analyzed with the same hash value. If so, the corresponding data to be analyzed is obtained, and the original sorting labels of the two groups of data to be analyzed are reversed. For data to be analyzed with different hash values, they are sorted from small to large according to the hash value. If a conflict occurs during the sorting process with the data to be analyzed with the same hash value, the data to be analyzed with the same hash value is retained, and the remaining data to be analyzed is sorted in sequence. If it does not exist, the data to be analyzed is sorted in sequence from small to large according to the hash value into the nine-square grid, and a displacement encryption package is generated, and it is transmitted to the encrypted data storage and analysis unit at the same time;

[0055] In a specific example, after the calculation of hash values, data 1 to be analyzed, data 2 to be analyzed, data 3 to be analyzed, data 4 to be analyzed, data 5 to be analyzed, data 6 to be analyzed, data 7 to be analyzed, data 8 to be analyzed, and data 9 to be analyzed have the same hash values, and the hash values ​​of the other data to be analyzed are all different. For the data to be analyzed with the same hash values, their original sorting labels are reversed. For example, for data 1 and 6 to be analyzed, the original label order is 1 and 6, which becomes 6 and 1 after reversal, and the remaining data are sorted in ascending order according to the hash values, as shown in the attached figure. Figure 4 As shown, the smallest one is data 8 to be analyzed, the largest one is data 7 to be analyzed, and so on.

[0056] The encrypted data storage and analysis unit is used to store and analyze the acquired displacement encryption packages. First, the displacement encryption packages are labeled as n, and n=1, 2, ..., m, where m represents the number of displacement encryption packages. Then, the data type corresponding to the displacement encryption package n is acquired, and the displacement encryption package n is classified according to the data type to generate a single-type encryption package and a multi-type encryption package, which are respectively labeled as n a and n b , a specific single type encryption package n a Indicates that there is only one type of data in the encryption package, while multiple types of encryption packages b This means that there are two or more types of data in the encrypted package;

[0057] Then, the distributed storage nodes are obtained and labeled as o, where o=1, 2, ..., p, where p represents the number of distributed storage nodes. At the same time, the distributed storage nodes o are classified according to the data types corresponding to the stored data to generate single-type storage nodes and multi-type storage nodes, which are respectively denoted as o a and b, and the distributed storage nodes and the displacement data packets are stored correspondingly, and the corresponding storage is specifically represented as storing a single type of encrypted package with a single type of storage node, and storing multiple types of encrypted packages with multiple types of storage nodes;

[0058] Take a single type of encrypted package as an example to analyze and obtain all single type storage nodes o a The corresponding stored data is obtained, and the data capacity corresponding to the stored data is obtained. At the same time, the single type storage node o is a The storage distribution characteristics of the data are obtained, and uniform distribution results and uneven distribution results are generated. The specific uniform distribution result is represented by the data capacity difference of the stored data being within the fluctuation range, and vice versa, it is an uneven distribution result if it is not within the fluctuation range, and the specific value of the fluctuation range is set by the operator;

[0059] Perform storage analysis on the generated uniform distribution results and obtain the single-type storage nodes o for all uniform distribution results a , while calculating the single type storage node o a The average capacity of the data stored in the , and the average capacity calculated here is the average capacity of a single type of storage node, and then the single type of encrypted packages are screened based on the average capacity as the standard. The specific screening method is:

[0060] Get the data capacity of a single-type encrypted packet, calculate the difference between its data capacity and the mean capacity, and compare the difference with the threshold. If the difference is less than the threshold, store the single-type encrypted packet in the corresponding single-type storage node o a , and generate encrypted storage information at the same time. If the difference is greater than the threshold, select the single-type storage node o corresponding to the difference less than the threshold. a , and store the single-type encrypted package to generate encrypted storage information; and here are some encrypted packages in the single-type encrypted package, and do not represent the total number of single-type encrypted packages.

[0061] The data capacity stored in the single-type storage node oa is: Node 1 stores 20GB, Node 2 stores 22GB, and Node 3 stores 21GB. The fluctuation range set by the operator is ±3GB. Since the data capacity difference of each node is within this fluctuation range, these nodes are evenly distributed, and the average capacity is calculated. = 21GB, the threshold T set by the operator = 2GB, assuming that there is a single type of encrypted packet with a data capacity of C packet =22GB, calculate the difference △C=|22-21|=1GB. Because 1GB<2GB, the encrypted package is stored in node 2, and the encrypted storage information is generated (such as recording the encrypted package ID, storage node number, storage time, etc.).

[0062] Perform storage analysis on the generated uneven separation results and obtain single-type storage nodes o for all uneven separation results b , while for a single type of storage node o b The data capacity of the stored data is obtained and the corresponding capacity interval is generated. Then, the data capacity of the single-type encrypted package is obtained and matched with the capacity interval. The matching single-type encrypted packages are matched with the corresponding single-type storage nodes o b Perform matching storage and generate encrypted storage information.

[0063] In a specific example, suppose that node 1 stores 10GB, node 2 stores 30GB, and node 3 stores 5GB. The operator sets the fluctuation range to ±3GB. At this time, these nodes are unevenly distributed. The generated capacity intervals are: Node 1 capacity interval I 1 =[5GB, 10GB], capacity interval I of node 2 2 =[25GB, 30GB], capacity interval I of node 3 3 =[0GB, 5GB]. Assume that there is a single type of encrypted packet with a data capacity of C packet =8GB, which falls within the capacity interval I of node 1, so the encrypted package is stored in node 1 and encrypted storage information is generated.

[0064] The analysis of multiple types of encrypted packages is similar to the analysis of single type encrypted packages, and the generated encrypted storage information is transmitted to the management information display unit.

[0065] A management information display unit is used to encrypt and store data according to the generated encrypted storage information.

[0066] Embodiment 2: This application provides a data security processing method based on port information, which specifically includes the following steps:

[0067] Step S001: Verify the user's personal information and generate a correct verification result or an incorrect verification result;

[0068] Step S002: according to the verification result, the data is grouped according to the data capacity to obtain grouped data, and at the same time, the grouped data is replaced according to the established lookup table to generate replaced grouped data;

[0069] Step S003, calculating the hash value of the replacement group data, and sorting them into a nine-square grid based on the size of the hash value to generate a displacement encryption package;

[0070] Step S004: Classify the data types in the displacement encryption package to generate a single-type encryption package and a multi-type encryption package, and classify the distributed storage nodes according to the stored data types to obtain single-type storage nodes and multi-type storage nodes;

[0071] Step S005: The classified displacement encryption packages and the classified distributed storage nodes are stored correspondingly, and at the same time, the corresponding storage distribution characteristics are combined and screened according to data capacity to generate encrypted storage information.

[0072] Some of the data in the above formulas are calculated by taking their numerical values, and are not substituted into parameter units for calculation. At the same time, the contents not described in detail in this specification belong to the existing technologies known to those skilled in the art.

[0073] The above embodiments are only used to illustrate the technical method of the present invention rather than to limit it. Although the present invention has been described in detail with reference to the preferred embodiments, those skilled in the art should understand that the technical method of the present invention may be modified or replaced by equivalents without departing from the spirit and scope of the technical method of the present invention.

Claims

1. A data security processing system based on port information, characterized in that: include: The personnel identity verification and analysis unit is used to transmit the data information to the data encryption processing unit, verify the obtained personnel information, generate the identity verification result, and transmit the correct verification result to the data encryption unit; The data encryption processing unit processes the data information according to the verification result, labels the acquired data, groups them according to the data capacity, then constructs an S box, searches the S box with the data byte value as the index, replaces the byte to obtain the replaced grouped data, calculates the hash value of the replaced grouped data, and if there is data to be analyzed with the same hash value, reverses its original sorting number; if not, arranges the data to be analyzed into a nine-square grid according to the hash value from small to large, generates a displacement encryption package and transmits it to the encrypted data storage and analysis unit; The encrypted data storage and analysis unit is responsible for storage and analysis of the acquired displacement encrypted packages, and divides them into single-type encrypted packages and multi-type encrypted packages according to the data types in the displacement encrypted packages. At the same time, the distributed storage nodes are divided into single-type storage nodes and multi-type storage nodes according to the stored data types, and the two types of encrypted packages and nodes are stored accordingly; Next, we analyze the storage distribution of single-type storage nodes and obtain two results: uniform and non-uniform. a , calculate the average value of the stored data capacity, and based on this, filter out a single type of encrypted package and generate encrypted storage information. The specific processing method is: Get the data capacity of a single-type encrypted packet, calculate the difference between its data capacity and the mean capacity, and compare the difference with the threshold. If the difference is less than the threshold, store the single-type encrypted packet in the corresponding single-type storage node o a , and generate encrypted storage information at the same time. Otherwise, select the single-type storage node o corresponding to the difference value less than the threshold a , and store a single type of encrypted package to generate encrypted storage information; For unevenly distributed single-type storage nodes o b , determine the capacity range of its stored data, match and store a single type of encrypted package according to the capacity, and generate encrypted storage information at the same time; At the same time, combined with the corresponding storage distribution characteristics, screening is performed according to data capacity, encrypted storage information is generated, and transmitted to the management information display unit.

2. A data security processing system based on port information according to claim 1, characterized in that: It also includes an information comprehensive acquisition unit and a management information display unit; The information comprehensive acquisition unit is used to acquire data information and personnel information and transmit the two to the personnel identity verification and analysis unit; The management information display unit is used to display the verification error results, displacement encryption packages and encrypted storage information.

3. A data security processing system based on port information according to claim 1, characterized in that: The specific method of generating the identity verification result by the personnel identity verification analysis unit is as follows: Obtain personnel information and identify it, and compare it with the system record information. If they are consistent, the personnel information is verified to be correct, and the verification result is generated and transmitted to the data encryption processing unit; If there is any inconsistency, the personnel information verification is incorrect, and a verification error result is generated and transmitted to the management information display unit.

4. A data security processing system based on port information according to claim 1, characterized in that: The specific method of the data encryption processing unit generating the replacement packet data is: All data labels in the data information are denoted as i, where i=1, 2, ..., j, and then the data i is grouped to obtain grouped data; Construct a 256-byte S-box as a special mapping table. Each index position corresponds to a unique replacement value. Use the value of each byte in the packet data as an index to search in the S-box. If the corresponding position is found, replace the byte with the corresponding value in the S-box to generate replacement packet data. All data labeled i are processed in this way to obtain the corresponding replacement group data.

5. A data security processing system based on port information according to claim 1, characterized in that: The specific method of generating the displacement encryption packet by the data encryption processing unit is as follows: After obtaining all the replaced grouped data, nine groups are selected as the data to be analyzed according to the labels, and they are arranged in order into the pre-built nine-square grid. The hash values ​​of these data to be analyzed are calculated. If there are identical hash values, the corresponding data is obtained and its original sorting labels are reversed; If it does not exist, the data to be analyzed will be arranged into a nine-square grid from small to large according to the hash value to generate a displacement encryption package.

6. A data security processing system based on port information according to claim 1, characterized in that: The specific method in which the encrypted data storage analysis unit performs storage analysis on the displacement encrypted package is: The displacement encryption packets are labeled as n, where n=1, 2, ..., m, where m represents the number of displacement encryption packets, and the data type of each displacement encryption packet n is obtained, and the data type is divided into single-type encryption packets n accordingly. a and multiple encryption packages b ; The distributed storage nodes are labeled as o, and o=1, 2, ..., p, where p represents the number of distributed storage nodes. According to the type of data stored in the node, it is divided into single-type storage nodes o a and multiple types of storage nodes b And the distributed storage nodes are stored correspondingly to the displacement data packets.

7. A data security processing system based on port information according to claim 1, characterized in that: The specific manner in which the encrypted data storage analysis unit stores the distributed storage nodes and the displacement data packets in correspondence is: Get a single type of storage node o a The stored data and corresponding capacity are used to determine the storage distribution characteristics based on these capacities, and to obtain uniform distribution and uneven distribution results; For the uniform distribution result, obtain the corresponding single-type storage node o a , calculate the average value of the stored data capacity, use the average value as the standard to filter a single type of encrypted package, and generate encrypted storage information; For uneven distribution results, obtain the corresponding single-type storage node o b , determine the stored data capacity interval, match the single type of encrypted package with the corresponding interval according to the capacity, and store it in node o b , and generate encrypted storage information.

8. A data security processing method based on port information, executed by a data security processing system based on port information according to any one of claims 1 to 7, characterized in that: The method specifically comprises the following steps: Step S001: Verify the user's personal information and generate a correct verification result or an incorrect verification result; Step S002: according to the verification result, the data is grouped according to the data capacity to obtain grouped data, and at the same time, the grouped data is replaced according to the established lookup table to generate replaced grouped data; Step S003, calculating the hash value of the replacement group data, and sorting them into a nine-square grid based on the size of the hash value to generate a displacement encryption package; Step S004: Classify the data types in the displacement encryption package to generate a single-type encryption package and a multi-type encryption package, and classify the distributed storage nodes according to the stored data types to obtain single-type storage nodes and multi-type storage nodes; Step S005: The classified displacement encryption packages and the classified distributed storage nodes are stored correspondingly, and at the same time, the corresponding storage distribution characteristics are combined and screened according to data capacity to generate encrypted storage information.

Citation Information

Patent Citations

  • Data security processing method and system

    CN117828688B

  • Security storage system of electronic information system

    CN118827232A

  • Abstraction layer for default encryption with orthogonal encryption logic session object; and automated authentication, with a method for online litigation

    US20140304505A1