A method, device and computer-readable storage medium for cloud data storage
By dividing the modified data in the cloud data storage process into multiple data blocks and building a data network topology diagram, the problem of inability to distinguish the causes of data modification in cloud data storage is solved, and accurate identification and correction of malicious tampering data blocks is achieved, and the security of cloud data storage is improved.
Patent Information
- Application Number
- CN202510323190.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-19
- Publication Date
- 2025-06-06
- Estimated Expiration
- 2045-03-19
AI Technical Summary
During the cloud data storage process, after the data is modified, it is impossible to distinguish whether it is temporarily modified by data storage personnel or malicious tampering by criminals, which reduces the security of cloud data storage.
Divide the modified data into multiple data blocks, build a data network topology diagram, determine the modified abnormal data blocks, and determine whether the data blocks have been maliciously tampered with through the traceability path and neighborhood window analysis.
It can accurately distinguish the data blocks that have been maliciously tampered with incorrect data, improving the security of cloud data storage.
Smart Images

Figure CN119854040B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of electronic digital data processing, and in particular to a cloud data storage method, device and computer-readable storage medium. Background Art
[0002] Cloud data storage refers to storing data on remote servers through cloud computing technology. This method allows users to access, manage and share data at any time through the Internet. Cloud storage service providers usually deploy multiple data centers around the world to ensure high availability and redundant backup of data. As an important user asset, data storage security is the focus of cloud computing technology. Cloud data storage technology is based on cloud computing technology. Compared with traditional data storage technology, it has a larger capacity and has greatly improved availability, security and stability.
[0003] Many large-scale and mature data storage models have been built in cloud data storage technology, but they are always based on the network. Data storage servers may be illegally attacked due to various defects and the operation of lawbreakers. Therefore, in the process of cloud data storage, it is necessary to ensure the security of data and prevent it from being tampered with by lawbreakers. However, in the process of storing cloud data, if the data is modified, it is impossible to distinguish whether it is a temporary modification by the data storage personnel or a malicious tampering by lawbreakers, which reduces the security of cloud data storage. Summary of the invention
[0004] In order to solve the technical problem that it is impossible to distinguish whether the data in cloud storage is maliciously tampered after being modified, the purpose of the present invention is to provide a method, device and computer-readable storage medium for cloud data storage. The technical solutions adopted are as follows:
[0005] In a first aspect, the present application provides a cloud data storage method, comprising:
[0006] In the process of cloud data storage, the modified data is divided into a plurality of data blocks, and a data network topology diagram is constructed with each of the data blocks as a node;
[0007] Determining a modified abnormal data block from each of the data blocks;
[0008] In the data network topology diagram, determining the affected tampering affected node in the first neighborhood window after the abnormal node on the tracing path of the abnormal node to which each abnormal data block belongs;
[0009] For each abnormal data block, determine whether the abnormal data block has been maliciously tampered with according to the number of tampering-affected nodes in the second neighborhood window around the abnormal node on the tracing path of the corresponding abnormal node and the number of tracing paths passing through the abnormal node.
[0010] In one embodiment, the data to be modified is divided into a plurality of data blocks, including:
[0011] The data to be modified is divided into multiple data blocks according to different hash values;
[0012] The step of determining the modified abnormal data block from each of the data blocks comprises:
[0013] The data blocks before and after modification are mapped to a hash ring according to the calculated hash values, and the modified abnormal data blocks are determined according to the overlap of the data blocks on the hash ring.
[0014] In one embodiment, mapping each data block before modification and each data block after modification to a hash ring according to the calculated hash value, and determining the modified abnormal data block according to the overlap of the data blocks on the hash ring, includes:
[0015] For each data block, determine the data modification evaluation value of the data block according to the difference between the hash values of the data block before and after the modification and the number of data blocks overlapped by the data block on the hash ring;
[0016] According to the data modification evaluation value, it is determined whether the data block is an abnormal data block that has been modified.
[0017] In one embodiment, the method further comprises:
[0018] If the data blocks overlap on the hash ring before and after modification, the number of the overlapping data blocks is the first number;
[0019] If the data blocks do not overlap on the hash ring before and after the modification, the number of overlapping data blocks is a second number; the first number is greater than the second number;
[0020] The step of determining the data modification evaluation value of each data block according to the difference between the hash values of the data block before and after the modification and the number of overlapping data blocks of the data block on the hash ring comprises:
[0021] For each data block, the data modification evaluation value of the data block is determined according to the difference between the hash values of the data block before and after modification and the ratio between the number of overlapping data blocks of the data block on the hash ring.
[0022] In one of the embodiments, determining the affected tampering affected node in the data network topology diagram from the first neighborhood window after the abnormal node on the tracing path of the abnormal node to which each abnormal data block belongs includes:
[0023] For each neighboring node in the first neighboring window after the abnormal node on the traceability path of each abnormal node to which the abnormal data block belongs, determine the possibility of tampering influence of the neighboring node according to the proportion of the number of times the neighboring node has been attacked in the total number of historical visits and the difference between the hash values of the neighboring node before and after modification;
[0024] According to the tampering impact possibility of the neighboring node, it is determined whether the neighboring node is a tampering impact node.
[0025] In one embodiment, for each abnormal data block, determining whether the abnormal data block has been maliciously tampered with according to the number of tampering-affected nodes in a second neighborhood window around the abnormal node on the tracing path of the corresponding abnormal node and the number of tracing paths passing through the abnormal node includes:
[0026] For each abnormal data block, determine the malicious tampering evaluation value of the abnormal data block according to the proportion of the number of abnormal nodes in the second neighborhood window around the abnormal node on the tracing path of the corresponding abnormal node, the number of tampering-affected nodes, and the number of tracing paths passing through the abnormal node;
[0027] It is determined whether the abnormal data block has been maliciously tampered with according to the malicious tampering evaluation value.
[0028] In one of the embodiments, after determining, for each of the abnormal data blocks, whether the abnormal data block has been maliciously tampered with based on the number of tampering-affected nodes in a second neighborhood window around the abnormal node on the tracing path of the corresponding abnormal node and the number of tracing paths passing through the abnormal node, the method further includes:
[0029] The data in the maliciously tampered data blocks in the modified data are corrected, and the corrected data are stored in the cloud.
[0030] In one embodiment, the step of correcting the data in the maliciously tampered data block in the modified data includes:
[0031] The data in the maliciously tampered data block is corrected according to the average value of the data of each node adjacent to the node to which the maliciously tampered data block belongs.
[0032] In a second aspect, the present application further provides a cloud data storage device, including a memory and a processor, wherein the memory stores a computer program, and when the processor executes the computer program, the following steps are implemented:
[0033] In the process of cloud data storage, the modified data is divided into a plurality of data blocks, and a data network topology diagram is constructed with each of the data blocks as a node;
[0034] Determining a modified abnormal data block from each of the data blocks;
[0035] In the data network topology diagram, determining the affected tampering affected node in the first neighborhood window after the abnormal node on the tracing path of the abnormal node to which each abnormal data block belongs;
[0036] For each abnormal data block, determine whether the abnormal data block has been maliciously tampered with according to the number of tampering-affected nodes in the second neighborhood window around the abnormal node on the tracing path of the corresponding abnormal node and the number of tracing paths passing through the abnormal node.
[0037] In a third aspect, the present application further provides a computer-readable storage medium having a computer program stored thereon, wherein when the computer program is executed by a processor, the following steps are implemented:
[0038] In the process of cloud data storage, the modified data is divided into a plurality of data blocks, and a data network topology diagram is constructed with each of the data blocks as a node;
[0039] Determining a modified abnormal data block from each of the data blocks;
[0040] In the data network topology diagram, determining the affected tampering affected node in the first neighborhood window after the abnormal node on the tracing path of the abnormal node to which each abnormal data block belongs;
[0041] For each abnormal data block, determine whether the abnormal data block has been maliciously tampered with according to the number of tampering-affected nodes in the second neighborhood window around the abnormal node on the tracing path of the corresponding abnormal node and the number of tracing paths passing through the abnormal node.
[0042] The present invention has the following beneficial effects:
[0043] In the cloud data storage process, the modified data is divided into multiple data blocks, and a data network topology diagram is constructed with each data block as a node. The modified abnormal data block is determined from each data block. In the data network topology diagram, the affected tampering-influencing nodes are determined from the first neighborhood window after the abnormal node on the tracing path of the abnormal node to which each abnormal data block belongs. For each abnormal data block, it is determined whether the abnormal data block has been maliciously tampered with according to the number of tampering-influencing nodes in the second neighborhood window around the abnormal node on the tracing path of the corresponding abnormal node and the number of tracing paths passing through the abnormal node, so that the maliciously tampered data blocks in the modified data can be accurately distinguished, thereby improving the security of cloud data storage. BRIEF DESCRIPTION OF THE DRAWINGS
[0044] In order to more clearly illustrate the technical solutions and advantages in the embodiments of the present invention or the prior art, the drawings required for use in the embodiments or the prior art descriptions are briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative work.
[0045] Figure 1 A schematic diagram of a flow chart of a cloud data storage method provided by an embodiment of the present invention;
[0046] Figure 2 A schematic diagram of mapping a data block to a hash ring provided by an embodiment of the present invention;
[0047] Figure 3 A schematic diagram of a portion of a data network topology diagram provided by an embodiment of the present invention;
[0048] Figure 4 A schematic diagram of the overall process of a cloud data storage method provided by an embodiment of the present invention;
[0049] Figure 5 A structural block diagram of a computer device provided by an embodiment of the present invention;
[0050] Figure 6 A structural block diagram of a computer-readable storage medium provided by an embodiment of the present invention. DETAILED DESCRIPTION
[0051] In order to further explain the technical means and effects adopted by the present invention to achieve the predetermined invention purpose, the following is a detailed description of a method, device and computer-readable storage medium for cloud data storage proposed by the present invention, its specific implementation, structure, features and effects in combination with the accompanying drawings and preferred embodiments. In the following description, different "one embodiment" or "another embodiment" does not necessarily refer to the same embodiment. In addition, specific features, structures or characteristics in one or more embodiments may be combined in any suitable form.
[0052] Unless defined otherwise, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this invention belongs.
[0053] The following describes in detail a specific solution of a cloud data storage method, device, and computer-readable storage medium provided by the present invention in conjunction with the accompanying drawings.
[0054] See also Figure 1 , which shows a method flow chart of a cloud data storage method provided by an embodiment of the present invention, including the following steps:
[0055] Step 102: During the cloud data storage process, the modified data is divided into a plurality of data blocks, and a data network topology diagram is constructed with each data block as a node.
[0056] The modified data refers to the data that has been modified in the data that needs to be stored in the cloud. The data network topology diagram is used to define how each data block is distributed, accessed, and transmitted in the cloud storage environment. The data network topology diagram contains nodes and connections between nodes. Each node represents the location of each data block in the storage system, and the connection represents the connection relationship and access path between storage nodes.
[0057] In one embodiment, the modified data may be divided into a plurality of data blocks according to different hash values, that is, the hash values of the data blocks are different.
[0058] In one embodiment, the modified data can be divided into a plurality of small blocks of preset sizes, and then the hash value of each small block is calculated using a hash algorithm, and the small blocks with the same hash value are merged into the same data block to determine the boundaries between the data blocks, thereby obtaining a plurality of data blocks. The preset size can be set according to actual conditions, for example, the preset size can be 512 bytes.
[0059] Step 104: determine the modified abnormal data blocks from each data block.
[0060] The abnormal data block refers to the modified data block.
[0061] In one embodiment, each data block before modification and each data block after modification may be mapped to a hash ring according to the calculated hash value, and the modified abnormal data block may be determined according to the overlap of the data blocks on the hash ring.
[0062] It can be understood that in a distributed system, a hash ring (i.e., consistent hashing) is usually used to map data to different nodes on the hash ring. The hash value of each data block is mapped to a ring structure according to the hash algorithm, and a certain position of the ring corresponds to the hash value of the data block. In the process of cloud data storage, the modification of data will cause the corresponding data block and its hash value to change. Each data block will generate a unique hash value through the hash algorithm when it is stored, and will be mapped to a specific position on the hash ring according to the hash value. When the data is modified, the hash algorithm will generate a new hash value based on the data content, so that the modified data block will be mapped to a different position on the hash ring. The hash value of the unmodified part remains unchanged, so the position on the hash ring will not change. Therefore, when only a part of the data is modified, only the hash value of the modified part changes, and the hash value of the unmodified data remains the same. At this time, the modified data block and the data block before the modification may be mapped to different positions on the hash ring, or they may be mapped to the same position on the hash ring.
[0063] like Figure 2 As shown, the overlapping part on the hash ring is that the hash value of the data block before modification is the same as that of the data block after modification, indicating that the data block has not been modified; the non-overlapping part on the hash ring is that the hash value of the data block before modification is different from that of the data block after modification, indicating that the data block is an abnormal data block that has been modified. Figure 2 In the example, the data block with serial number 6 is modified, and the hash value changes from 0.9 to 0.8 before and after the modification. Therefore, the data block with serial number 6 is mapped to different positions on the hash ring according to the hash value before and after the modification, and there is no overlap. The other data blocks are not modified, so the other data are mapped to the same position on the hash ring before and after the modification, and there is overlap.
[0064] Through the above steps, each abnormal data block is determined. The abnormal data block may be caused by various reasons such as node failure, normal human operation or malicious tampering. It is necessary to continue to perform subsequent steps 106 to 108 to determine the maliciously tampered data block.
[0065] Step 106 , in the data network topology diagram, determine the affected tampering affected node in the first neighborhood window after the abnormal node on the traceability path of the abnormal node to which each abnormal data block belongs.
[0066] Among them, the abnormal node refers to the node to which the abnormal data block belongs. The traceability path of the abnormal node is the path passing through the abnormal node in the data network topology diagram. After the abnormal node on the traceability path refers to the position of the data block after passing through the abnormal node in the process of being transmitted from the source node to the target node on the traceability path. The first neighborhood window is the neighborhood window after the abnormal node on the traceability path and adjacent to the abnormal node.
[0067] Tampering-affected nodes refer to nodes that are affected by tampering with surrounding nodes. It is understandable that in the data network topology diagram, normally modified data blocks are usually performed by authorized users, and the modified data will be synchronized to surrounding nodes according to predetermined rules, and usually will not have a negative impact on other nodes. Data blocks that are tampered with by malicious attacks by lawbreakers are tampered with by lawbreakers without authorization, which may cause data inconsistency. The tampered nodes may synchronize erroneous data to neighboring nodes, causing the replica data of these nodes to also be abnormal. If the tampered data involves dependencies, the data of neighboring nodes may be affected. For example, a tampered node provides incorrect input, causing subsequent nodes to generate incorrect data or trigger failures.
[0068] In one embodiment, the size of the first neighborhood window can be set according to actual conditions. For example, the size of the first neighborhood window can be set to 3×3. That is, the nodes within 3 layers after the abnormal node on each traceability path of the abnormal node. Figure 3 As shown, the dotted circle represents an abnormal node, and the solid circle without shade represents each node (i.e., the neighboring node) in the 3×3 first neighborhood window after the abnormal node on the traceability path of the abnormal node. The solid circle with shade represents the node outside the first neighborhood window. In other embodiments, the size of the first neighborhood window can also be set to 2×2 or 4×4, etc.
[0069] In one embodiment, the affected tampering affected node can be determined from each neighboring node based on the suspicion of each neighboring node in the first neighboring window and the change of the hash value of the neighboring node before and after the modification. The suspicion is determined based on the historical attack situation of the neighboring node.
[0070] Step 108, for each abnormal data block, determine whether the abnormal data block has been maliciously tampered with according to the number of tampering-affected nodes in the second neighborhood window around the abnormal node on the tracing path of the corresponding abnormal node and the number of tracing paths passing through the abnormal node.
[0071] The second neighborhood window is a neighborhood window that is around the abnormal node and adjacent to the abnormal node on the traceability path of the abnormal node.
[0072] In one embodiment, the size of the second neighborhood window can be set according to actual conditions. For example, the size of the second neighborhood window can be set to 3×3, 2×2, or 4×4.
[0073] It can be understood that the first neighborhood window and the second neighborhood window are different. The first neighborhood window is after the abnormal node, while the second neighborhood window can be before and after the abnormal node. That is, for example, the first neighborhood window can be a 3×3 window after the abnormal node; and the second neighborhood window can be a 3×3 window before the abnormal node and a 3×3 window after the abnormal node.
[0074] In one embodiment, for each abnormal data block, it is determined whether the abnormal data block has been maliciously tampered with based on the proportion of the number of abnormal nodes in the second neighborhood window around the abnormal node on the tracing path of the corresponding abnormal node, the number of tampering-affected nodes, and the number of tracing paths passing through the abnormal node.
[0075] In the above-mentioned cloud data storage method, during the cloud data storage process, the modified data is divided into multiple data blocks, and a data network topology diagram is constructed with each data block as a node. The modified abnormal data block is determined from each data block. In the data network topology diagram, the affected tampering-affecting nodes are determined from the first neighborhood window after the abnormal node on the tracing path of the abnormal node to which each abnormal data block belongs. For each abnormal data block, it is determined whether the abnormal data block has been maliciously tampered with according to the number of tampering-affecting nodes in the second neighborhood window around the abnormal node on the tracing path of the corresponding abnormal node and the number of tracing paths passing through the abnormal node, so that the maliciously tampered data blocks in the modified data can be accurately distinguished, thereby improving the security of cloud data storage.
[0076] In one embodiment, the modified data is divided into multiple data blocks, including: dividing the modified data into multiple data blocks according to different hash values; determining the modified abnormal data blocks from each data block, including: mapping each data block before modification and each data block after modification to a hash ring according to the calculated hash value, and determining the modified abnormal data block according to the overlap of the data blocks on the hash ring.
[0077] In one embodiment, the hash values corresponding to each data block before and after modification can be calculated respectively, and whether each data block is a modified data block can be determined based on the overlap of each data block mapped to the hash ring according to the hash value before and after modification, and the difference between the hash values of each data block before and after modification.
[0078] In the above embodiment, the modified data is divided into multiple data blocks according to different hash values, and each data block before modification and the modified data block is mapped to a hash ring according to the calculated hash value. The modified abnormal data block is determined according to the overlap of the data blocks on the hash ring, so that the modified abnormal data block can be accurately determined from the modified data.
[0079] In one embodiment, each data block before modification and each data block after modification are mapped to a hash ring according to the calculated hash value, and the modified abnormal data block is determined according to the overlap of the data blocks on the hash ring, including: for each data block, according to the difference between the hash values of the data block before and after modification and the number of overlapping data blocks on the hash ring, determining the data modification evaluation value of the data block; according to the data modification evaluation value, determining whether the data block is a modified abnormal data block.
[0080] In one embodiment, the data modification evaluation value of a data block is positively correlated with the difference between the hash values of the data block before and after the modification, and negatively correlated with the number of overlapping data blocks on the hash ring.
[0081] In one embodiment, the data modification evaluation value of the data block may be determined based on the ratio between the difference between the hash values of the data block before and after modification and the number of overlapping data blocks on the hash ring.
[0082] In one embodiment, the data modification evaluation value of the data block may be determined according to the following formula:
[0083]
[0084] in, Represents the data modification evaluation value of the i-th data block. Represents the hash value of the i-th data block in the modified data (that is, the hash value of the i-th data block after modification). Represents the hash value of the i-th data block in the original data (that is, the hash value of the i-th data block before modification). Indicates the number of data blocks that overlap with the i-th data block in the modified data on the hash ring. represents the absolute value function. Represents a linear normalization function, which is used to normalize data values to the interval [0,1].
[0085] Understandably, The larger the value of , the more likely the hash value of the i-th data block has changed, and the more likely the i-th data block has been modified. The larger the value of , the more data blocks overlap with the i-th data block, and the smaller the possibility that the i-th data block has been modified. The larger the value of , the greater the possibility that the i-th data block has been modified.
[0086] In one embodiment, the data modification evaluation value can be compared with a first preset threshold value, and whether the data block is a modified abnormal data block can be determined based on the comparison result. In one embodiment, if the data modification evaluation value of the data block is greater than or equal to the first preset threshold value, the data block is determined to be a modified abnormal data block. If the data modification evaluation value of the data block is less than the first preset threshold value, it is determined that the data block has not been modified and is not an abnormal data block. The first preset threshold value can be set according to actual conditions, for example, the first preset threshold value can be set to 0.5.
[0087] In the above embodiment, for each data block, the data modification evaluation value of the data block is determined according to the difference between the hash values of the data block before and after modification, and the number of overlapping data blocks on the hash ring. Based on the data modification evaluation value, it is determined whether the data block is a modified abnormal data block, so that the modified abnormal data block can be accurately determined from the modified data.
[0088] In one embodiment, the method also includes: if the data blocks overlap on the hash ring before and after modification, the number of overlapping data blocks is a first number; if the data blocks do not overlap on the hash ring before and after modification, the number of overlapping data blocks is a second number; the first number is greater than the second number; for each data block, according to the difference between the hash values of the data block before and after modification, and the number of overlapping data blocks of the data block on the hash ring, determining the data modification evaluation value of the data block, including: for each data block, according to the difference between the hash values of the data block before and after modification, and the ratio of the number of overlapping data blocks of the data block on the hash ring, determining the data modification evaluation value of the data block.
[0089] In one embodiment, if the data blocks overlap on the hash ring before and after modification, the number of overlapping data blocks is 2; if the data blocks do not overlap on the hash ring before and after modification, the number of overlapping data blocks is 1.
[0090] In the above embodiment, if the data blocks do not overlap on the hash ring before and after modification, the number of overlapping data blocks is the second number, and the first number is greater than the second number, so that the data modification evaluation value of the data block can be accurately determined.
[0091] In one embodiment, in a data network topology diagram, the affected tampering-affected nodes are determined from the first neighborhood window after the abnormal node on the traceability path of the abnormal node to which each abnormal data block belongs, including: for each neighboring node in the first neighborhood window after the abnormal node on the traceability path of the abnormal node to which each abnormal data block belongs, the tampering-affected possibility of the neighboring node is determined according to the proportion of the number of times the neighboring node has been historically attacked in the total number of historical visits, and the difference between the hash values of the neighboring node before and after modification; and according to the tampering-affected possibility of the neighboring node, whether the neighboring node is a tampering-affected node is determined.
[0092] In one embodiment, the likelihood of tampering of a neighboring node is positively correlated with the proportion of the number of times the neighboring node has been attacked in history to the total number of historical visits. The likelihood of tampering of a neighboring node is positively correlated with the difference between the hash values of the neighboring node before and after modification.
[0093] In one embodiment, a first ratio between the number of times the neighboring node has been attacked in history and the total number of historical visits can be determined, and a difference between the hash values of the neighboring node before and after modification can be determined. The possibility of tampering influence of the neighboring node can be determined based on the product of the first ratio and the first difference.
[0094] In one embodiment, the tampering impact possibility of a neighboring node can be determined according to the following formula:
[0095]
[0096] in, Indicates the possibility of tampering influence on the nth neighboring node of the abnormal node to which the mth abnormal data block belongs. Indicates the number of times the nth neighboring node of the abnormal node to which the mth abnormal data block belongs has been attacked in history. Indicates the total number of historical visits to the nth neighboring node of the abnormal node to which the mth abnormal data block belongs. Indicates the hash value of the data block of the nth neighboring node of the abnormal node to which the mth abnormal data block in the modified data belongs (that is, the hash value of the neighboring node after modification). Represents the hash value of the data block of the nth neighboring node of the abnormal node to which the mth abnormal data block belongs in the original data (that is, the hash value of the neighboring node before modification). represents the absolute value function. Represents a linear normalization function, which is used to normalize data values to the interval [0,1].
[0097] Understandably, represents the suspicion of the nth neighboring node of the abnormal node to which the mth abnormal data block belongs, The larger the value is, the more likely the data block corresponding to the nth neighboring node of the abnormal node to which the mth abnormal data block belongs is to be abnormal, and the greater the possibility of being affected by tampering. The change in the hash value of the nth neighboring node of the abnormal node to which the mth abnormal data block belongs is greater, and the greater the change, the more likely it is to be affected by the abnormal node to which the mth abnormal data block belongs.
[0098] In one embodiment, the tampering impact possibility of the neighboring node can be compared with the second preset threshold, and whether the neighboring node is a tampering impact node is determined according to the comparison result. In one embodiment, if the tampering impact possibility of the neighboring node is greater than or equal to the second preset threshold, the neighboring node is determined to be a tampering impact node; if the tampering impact possibility of the neighboring node is less than the second preset threshold, the neighboring node is determined not to be a tampering impact node.
[0099] In the above embodiment, for each neighboring node in the first neighborhood window after the abnormal node on the traceability path of the abnormal node to which each abnormal data block belongs, the tampering impact possibility of the neighborhood node is determined according to the proportion of the number of times the neighborhood node has been historically attacked in the total number of historical visits, and the difference between the hash values of the neighborhood node before and after modification. Based on the tampering impact possibility of the neighborhood node, it is determined whether the neighborhood node is a tampering impact node, so that the tampering impact node can be accurately determined from the neighboring nodes of the abnormal node to which the abnormal data block belongs, and the tampering impact node in the first neighborhood window of the abnormal node to which each abnormal data block belongs can be accurately obtained.
[0100] In one embodiment, for each abnormal data block, respectively, according to the number of tampering-affected nodes in the second neighborhood window around the abnormal node on the tracing path of the corresponding abnormal node, and the number of tracing paths passing through the abnormal node, determine whether the abnormal data block has been maliciously tampered with, including: for each abnormal data block, according to the proportion of the number of abnormal nodes in the second neighborhood window around the abnormal node on the tracing path of the corresponding abnormal node, the number of tampering-affected nodes, and the number of tracing paths passing through the abnormal node, determine the malicious tampering evaluation value of the abnormal data block; according to the malicious tampering evaluation value, determine whether the abnormal data block has been maliciously tampered with.
[0101] In one embodiment, the proportion of the number of abnormal nodes in the second neighborhood window may be determined according to the ratio between the number of abnormal nodes in the second neighborhood window and the total number of nodes in the second neighborhood window.
[0102] In one embodiment, the malicious tampering evaluation value of the abnormal data block is positively correlated with the proportion of the number of abnormal nodes in the second neighborhood window around the abnormal node on the tracing path of the corresponding abnormal node. The malicious tampering evaluation value of the abnormal data block is positively correlated with the number of tampering-affected nodes in the second neighborhood window around the abnormal node on the tracing path of the corresponding abnormal node. The malicious tampering evaluation value of the abnormal data block is positively correlated with the number of tracing paths passing through the corresponding abnormal node.
[0103] In one embodiment, the malicious tampering evaluation value of the abnormal data block can be determined based on the product of the proportion of the number of abnormal nodes in the second neighborhood window around the abnormal node on the tracing path of the abnormal node to which the abnormal data block belongs, the number of tampering-affected nodes in the second neighborhood window, and the number of tracing paths passing through the abnormal node.
[0104] In one embodiment, the malicious tampering evaluation value of the abnormal data block can be determined according to the following formula:
[0105]
[0106] in, Represents the malicious tampering evaluation value of the mth abnormal data block. Represents the number of tampering-affected nodes in the second neighborhood window around the abnormal node on the traceability path of the abnormal node to which the mth abnormal data block belongs. Indicates the number of traceability paths that pass through the abnormal node to which the mth abnormal data block belongs. Represents the number of abnormal nodes in the second neighborhood window around the abnormal node on the tracing path of the abnormal node to which the mth abnormal data block belongs. Represents the total number of nodes in the second neighborhood window around the abnormal node on the tracing path of the abnormal node to which the mth abnormal data block belongs. Indicates the ratio of the number of abnormal nodes in the second neighborhood window around the abnormal node on the traceability path of the abnormal node to which the mth abnormal data block belongs.
[0107] It can be understood that when the number of tampering-affected nodes in the second neighborhood window of the abnormal node to which the abnormal data block belongs is greater, it means that the abnormal node has a greater impact on the surrounding nodes, and the abnormal data block in the abnormal node is more likely to be caused by malicious tampering. Therefore, the malicious tampering evaluation value of the abnormal data block is The number of tampering-affected nodes in the second neighborhood window around the abnormal node on the traceability path of the corresponding abnormal node When more traceability paths in the data network topology diagram pass through the same abnormal node, the abnormal node is more likely to become the target of attack by criminals, and the abnormal data block is more likely to be maliciously tampered with. Therefore, the malicious tampering evaluation value of the abnormal data block is The number of traceability paths passing through the corresponding abnormal node There is a positive correlation. The larger the value of is, the greater the possibility that the mth abnormal data block is maliciously tampered with by illegal elements.
[0108] In one embodiment, the malicious tampering average value can be compared with a third preset threshold value, and whether the abnormal data block has been maliciously tampered with can be determined based on the comparison result. In one embodiment, if the malicious tampering average value is greater than or equal to the third preset threshold value, it is determined that the abnormal data block is a maliciously tampered data block; if the malicious tampering average value is less than the third preset threshold value, it is determined that the abnormal data block has not been maliciously tampered with and is not a maliciously tampered data block. In one embodiment, the third preset threshold value can be set according to actual conditions, for example: the third preset threshold value can be set to 0.4.
[0109] In the above embodiment, for each abnormal data block, the malicious tampering evaluation value of the abnormal data block is determined according to the proportion of the number of abnormal nodes in the second neighborhood window around the abnormal node on the tracing path of the corresponding abnormal node, the number of tampering-affected nodes, and the number of tracing paths passing through the abnormal node. Based on the malicious tampering evaluation value, it is determined whether the abnormal data block has been maliciously tampered with, so that the data blocks in the modified data that have been maliciously tampered with by illegal elements can be accurately determined.
[0110] In one embodiment, after determining, for each abnormal data block, whether the abnormal data block has been maliciously tampered with based on the number of tampering-affected nodes in the second neighborhood window around the abnormal node on the tracing path of the corresponding abnormal node, and the number of tracing paths passing through the abnormal node, the method further includes: correcting the data in the maliciously tampered data block in the modified data, and storing the corrected data in the cloud.
[0111] In one embodiment, the data in the maliciously tampered data block may be corrected based on the data of each node adjacent to the node to which the maliciously tampered data block belongs.
[0112] In the above embodiment, after the maliciously tampered data blocks are determined from the modified data, the data in the maliciously tampered data blocks in the modified data are corrected, and then the corrected data is stored in the cloud, which can improve the security of cloud data storage and prevent data from being maliciously tampered with.
[0113] In one embodiment, correcting data in a maliciously tampered data block in the modified data includes: correcting the data in the maliciously tampered data block according to an average of data of nodes adjacent to the node to which the maliciously tampered data block belongs.
[0114] The nodes adjacent to the node to which the maliciously tampered data block belongs refer to the previous node of the node on each traceability path of the node to which the maliciously tampered data block belongs.
[0115] In one embodiment, the average of the data of each node adjacent to the node to which the maliciously tampered data block belongs may be used as the data in the corrected maliciously tampered data block.
[0116] In one embodiment, the corrected maliciously tampered data block may be determined according to the following formula:
[0117]
[0118] in, Indicates the corrected data block that has been maliciously tampered with. Indicates a data block that has been maliciously tampered with The data of the jth node adjacent to the node. N represents the data block that has been maliciously tampered with. The number of nodes that are adjacent to the node.
[0119] In the above embodiment, after the data is maliciously tampered with, in the data network topology diagram, the node data before the node to which the maliciously tampered data block belongs has not been tampered with, which has an impact on the data of the subsequent nodes. Therefore, the maliciously tampered data block is corrected according to the node data before the node where the maliciously tampered data block is located. The maliciously tampered data block can be accurately corrected, ensuring that the data is transmitted stably and accurately in the network, improving the security of cloud data storage, and preventing data from being maliciously tampered with.
[0120] like Figure 4 FIG. 1 is a schematic diagram of the overall process of the cloud data storage method in each embodiment of the present application, including the following steps:
[0121] Step 402, divide the modified data into blocks and construct a data network topology map.
[0122] Step 404: Map the data blocks to the hash ring and determine abnormal data blocks.
[0123] Step 406, obtaining the traceability path of the node to which each abnormal data block belongs, and determining the possibility that each abnormal data block has been maliciously tampered with.
[0124] Step 408, correct the maliciously tampered data blocks to complete cloud data storage.
[0125] It should be understood that, although the various steps in the flowcharts involved in the above-mentioned embodiments are displayed in sequence according to the indication of the arrows, these steps are not necessarily executed in sequence according to the order indicated by the arrows. Unless there is a clear explanation in this article, the execution of these steps does not have a strict order restriction, and these steps can be executed in other orders. Moreover, at least a part of the steps in the flowcharts involved in the above-mentioned embodiments can include multiple steps or multiple stages, and these steps or stages are not necessarily executed at the same time, but can be executed at different times, and the execution order of these steps or stages is not necessarily to be carried out in sequence, but can be executed in turn or alternately with other steps or at least a part of the steps or stages in other steps.
[0126] In an exemplary embodiment, a computer device is provided. The computer device may be a server, and its internal structure diagram may be as shown in FIG. Figure 5 As shown. The computer device includes a processor, a memory, an input / output interface (Input / Output, referred to as I / O) and a communication interface. Among them, the processor, the memory and the input / output interface are connected through a system bus, and the communication interface is connected to the system bus through the input / output interface. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program and a database. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The database of the computer device is used to store data. The input / output interface of the computer device is used to exchange information between the processor and an external device. The communication interface of the computer device is used to communicate with an external terminal through a network connection. When the computer program is executed by the processor, a method for cloud data storage is implemented.
[0127] Those skilled in the art will understand that Figure 5 The structure shown in the figure is only a block diagram of a part of the structure related to the solution of the present application, and does not constitute a limitation on the computer device to which the solution of the present application is applied. The specific computer device may include more or fewer components than those shown in the figure, or combine certain components, or have a different arrangement of components.
[0128] In an exemplary embodiment, a computer device is provided, including a memory and a processor, wherein a computer program is stored in the memory, and when the processor executes the computer program, the steps in the cloud data storage method in each embodiment of the present application are implemented.
[0129] In one embodiment, Figure 6 As shown, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the steps in the cloud data storage method in each embodiment of the present application are implemented.
[0130] It should be noted that the data involved in this application (including but not limited to data used for analysis, stored data, displayed data, etc.) are all data authorized by the user or fully authorized by all parties, and the collection, use and processing of relevant data must comply with relevant regulations.
[0131] Those skilled in the art can understand that all or part of the processes in the above-mentioned embodiment methods can be completed by instructing the relevant hardware through a computer program, and the computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above-mentioned methods. Among them, any reference to the memory, database or other medium used in the embodiments provided in this application can include at least one of non-volatile and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetoresistive random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. As an illustration and not limitation, RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM). The database involved in each embodiment provided in this application may include at least one of a relational database and a non-relational database. Non-relational databases may include distributed databases based on blockchains, etc., but are not limited to this. The processor involved in each embodiment provided in this application may be a general-purpose processor, a central processing unit, a graphics processor, a digital signal processor, a programmable logic device, a data processing logic device based on quantum computing, etc., but are not limited to this.
[0132] The technical features of the above embodiments may be combined arbitrarily. To make the description concise, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.
[0133] The above-mentioned embodiments only express several implementation methods of the present application, and the descriptions thereof are relatively specific and detailed, but they cannot be understood as limiting the scope of the present application. It should be pointed out that, for ordinary technicians in this field, several variations and improvements can be made without departing from the concept of the present application, and these all belong to the protection scope of the present application.
[0134] It should be noted that the sequence of the above embodiments of the present invention is only for description and does not represent the advantages and disadvantages of the embodiments. The processes depicted in the accompanying drawings do not necessarily require the specific order or continuous order shown to achieve the desired results. In some embodiments, multitasking and parallel processing are also possible or may be advantageous.
[0135] The various embodiments in this specification are described in a progressive manner, and the same or similar parts between the various embodiments can be referenced to each other, and each embodiment focuses on the differences from other embodiments.
Claims
1. A method for cloud data storage, characterized in that: The method comprises: In the process of cloud data storage, the modified data is divided into multiple data blocks according to different hash values, and a data network topology diagram is constructed with each data block as a node; Determining the modified abnormal data blocks from each of the data blocks, including: mapping each data block before modification and the modified data block to a hash ring according to the calculated hash value, if the data blocks overlap on the hash ring before and after modification, the number of the overlapping data blocks is a first number; if the data blocks do not overlap on the hash ring before and after modification, the number of the overlapping data blocks is a second number; the first number is greater than the second number; for each data block, determining the ratio between the difference between the hash values of the data block before and after modification and the number of overlapping data blocks of the data block on the hash ring as the data modification evaluation value of the data block; according to the data modification evaluation value, determining whether the data block is a modified abnormal data block; In the data network topology diagram, for each neighboring node in the first neighborhood window after the abnormal node on the traceability path of each abnormal node to which the abnormal data block belongs, the product of the ratio of the number of times the neighboring node has been attacked in history to the total number of historical visits and the difference between the hash values of the neighboring node before and after modification is determined as the tampering impact possibility of the neighboring node; according to the tampering impact possibility of the neighboring node, determine whether the neighboring node is a tampering impact node; For each abnormal data block, the product of the proportion of the number of abnormal nodes in the second neighborhood window around the abnormal node on the tracing path of the corresponding abnormal node, the number of tampering-affected nodes in the second neighborhood window, and the number of tracing paths passing through the abnormal node is determined as the malicious tampering evaluation value of the abnormal data block; based on the malicious tampering evaluation value, determine whether the abnormal data block has been maliciously tampered with.
2. The cloud data storage method according to claim 1, characterized in that: After determining, for each abnormal data block, whether the abnormal data block has been maliciously tampered with according to the number of tampering-affected nodes in a second neighborhood window around the abnormal node on the tracing path of the corresponding abnormal node and the number of tracing paths passing through the abnormal node, the method further includes: The data in the maliciously tampered data blocks in the modified data are corrected, and the corrected data are stored in the cloud.
3. The cloud data storage method according to claim 2, characterized in that: The step of correcting the data in the maliciously tampered data block in the modified data includes: The data in the maliciously tampered data block is corrected according to the average value of the data of each node adjacent to the node to which the maliciously tampered data block belongs.
4. A cloud data storage device, comprising a memory and a processor, wherein the memory stores a computer program, characterized in that: When the processor executes the computer program, the steps of the cloud data storage method according to any one of claims 1 to 3 are implemented.
5. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the cloud data storage method according to any one of claims 1 to 3 are implemented.
Citation Information
Patent Citations
Attack tracing method and system
CN117155665A