Intelligent encryption control system of distributed storage system

By identifying the dependencies and high-frequency calling characteristics of cross-node requests in a distributed storage system, prioritizing resource occupation and call levels, and adjusting encryption algorithms and streamlining redundant operations in the encryption optimization module, the contradiction between performance bottlenecks and security requirements of distributed storage systems under high concurrency conditions is solved, and a dynamic balance between system performance and security is achieved.

CN119918076APending Publication Date: 2025-05-02HUANYU DIGITAL TECHNOLOGY CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202411993315.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-12-31
Publication Date
2025-05-02

AI Technical Summary

Technical Problem

There is a contradiction between performance bottlenecks and security requirements under high concurrency conditions. The traditional encryption mode fails to differentiate processing of data of different sensitivity, resulting in both key nodes and ordinary nodes bearing the same intensity of encryption and decryption load, and cannot balance high-intensity protection and access efficiency.

Method used

Through the call chain division module, the dependency relationship and high-frequency call characteristics of cross-node requests are identified, and the priority is combined with resource occupation and call hierarchy division, the key paths are accurately filtered, and the encryption algorithm and streamlined redundant operations are adjusted in the encryption optimization module, which significantly reduces the encryption and decryption overhead, while improving the efficiency and consistency of key management.

Benefits of technology

The dynamic balance between system performance and security is achieved. By optimizing encryption policies and dynamic routing adjustments, the request processing efficiency is significantly improved, the risk of resource conflicts is reduced, and the security of data transmission is ensured.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119918076A_ABST
    Figure CN119918076A_ABST
Patent Text Reader

Abstract

The invention discloses an intelligent encryption control system of a distributed storage system, particularly relates to the field of encryption optimization of the distributed storage system, is used for solving the problem of balance between performance bottleneck and security requirements in a high-concurrency environment, and aims to identify a dependency relationship of a cross-node request and a high-frequency call characteristic from call chain division, so as to improve the security of the distributed storage system. Calculating and quantifying the performance burden and the encryption and decryption density of the call chain through the coupling degree, and accurately screening a key path; the priority is divided in combination with resource occupation and calling levels, so that the encryption strategy adapts to the performance and security requirements of different scenes; when a high-priority path is optimized, by adjusting an encryption algorithm and simplifying redundant operation, the encryption and decryption overhead is remarkably reduced, and meanwhile, the high efficiency and consistency of key management are improved; finally, an optimization strategy is embedded into a dynamic routing module, similar requests are combined, the access depth is shortened, the request processing efficiency is further improved, resource conflicts are reduced, and dynamic balance between system performance and safety is comprehensively achieved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of encryption optimization of distributed storage systems, and more specifically, to an intelligent encryption control system of distributed storage systems. Background Art

[0002] Multi-node collaboration in a distributed storage system relies on frequent data interaction and resource sharing. Large-scale cross-node calls form multiple complex call chains under high concurrency conditions. If encryption and decryption operations are not managed in a refined manner or lack reasonable routing scheduling, the data flow process will produce significant delays and resource consumption. Traditional methods tend to adopt a unified encryption mode and fail to perform differentiated processing for data of different sensitivities, causing key nodes and ordinary nodes to bear the same encryption and decryption load. Without a mechanism for dynamic scheduling based on the coupling degree of the call chain, it is difficult to strike a balance between high-intensity protection and access efficiency. Once a node with a high degree of coupling is in high-frequency requests, even if the encryption algorithm has the best performance, it will become a system bottleneck due to repeated encryption and decryption, hindering the throughput and expansion of distributed storage. In order to solve the above problems, a technical solution is now provided. Summary of the invention

[0003] In order to overcome the above-mentioned defects of the prior art, an embodiment of the present invention provides an intelligent encryption control system for a distributed storage system, which starts with the division of the call chain, identifies the dependencies and high-frequency call characteristics of cross-node requests, quantifies the performance burden and encryption and decryption density of the call chain through coupling calculation, and accurately screens the key path; combines resource occupancy and call level to divide priorities, so that the encryption strategy adapts to the performance and security requirements of different scenarios; when optimizing high-priority paths, by adjusting the encryption algorithm and streamlining redundant operations, the encryption and decryption overhead is significantly reduced, and the efficiency and consistency of key management are improved; finally, the optimization strategy is embedded in the dynamic routing module, similar requests are merged and the access depth is shortened, so as to further improve the request processing efficiency and reduce resource conflicts, and comprehensively realize the dynamic balance between system performance and security, so as to solve the problems raised in the above-mentioned background technology.

[0004] To achieve the above object, the present invention provides the following technical solutions:

[0005] An intelligent encryption control system for a distributed storage system, comprising: a call chain division module, a coupling degree calculation module, a priority division module, an encryption optimization module and a routing strategy module;

[0006] Call chain division module: divides the cross-node requests recorded in the distributed storage system into multiple independent call chains, and transmits the generated independent call chain data to the coupling degree calculation module;

[0007] Coupling degree calculation module: Mark the function call frequency item by item in each call chain and record the number of encryption and decryption times, calculate the coupling degree table, identify the high-frequency call nodes, and send the high-frequency call nodes to the priority division module;

[0008] Priority classification module: categorizes high-frequency call nodes into encryption priorities according to resource occupancy and call levels, and transmits the determined priority information to the encryption optimization module;

[0009] Encryption optimization module: optimizes the encryption algorithm for high-priority paths and simplifies repeated encryption and decryption operations. The output optimization strategy is passed to the routing strategy module;

[0010] Routing strategy module: applies optimization strategies to the dynamic routing module to merge similar requests and shorten the cross-node access depth.

[0011] In a preferred embodiment, the call chain partitioning module includes the following contents:

[0012] First, read the original records of all cross-node requests in the log, form a request vector through timestamp, node sequence number and session identifier, and then perform quantitative calculation on the similarity between request vectors; construct the judgment function F(r i , r j ) to measure the request r i With r j Whether they belong to the same call chain, let r i With r j Contains the following key parameters: D i represents the number of node-level hops that a request goes through in a distributed environment, T i , T j Represents the time when the request occurred, U i , U j Represents the identifier of the request in the upper layer business; select positive real constants α and β to adjust the relative influence weights of different factors, and define the following judgment formula: By traversing all request pairs in the log (r i , r j ) and calculate the decision function. If the result exceeds the decision threshold, the request r i With request r j Belong to the same call chain.

[0013] In a preferred embodiment, the coupling degree calculation module includes the following contents:

[0014] For each call chain, parse the system operation log and monitoring data to extract all the function call records involved; for each function, record its call frequency F in the corresponding call chain m And the number of encryption and decryption operations triggered F e; The coupling degree is calculated by the following formula: Where: L represents the current call chain; N L Represents the total number of functions in the call chain L; Indicates the calling frequency of the nth function in the call chain L; Indicates the number of encryption and decryption operations of the nth function in the call chain L; S n Indicates the total number of operations of the nth function in the call chain L; M max Indicates the maximum function call frequency of all call chains in the system.

[0015] In a preferred embodiment, the coupling degree calculation module further includes the following contents:

[0016] For each call chain, calculate its coupling degree separately; sort the coupling values ​​of all call chains from high to low to generate a coupling degree table; based on the coupling degree table, use the coupling degree threshold to filter out call chains with coupling degrees higher than the coupling degree threshold; for these high-coupling call chains, analyze the calling frequency and encryption and decryption operation times of each function within them, filter out function nodes that meet both high calling frequency standards and high encryption and decryption operation times standards, and mark them as high-frequency call nodes; these high-frequency call nodes are potential performance blocking points and need to be optimized first.

[0017] In a preferred embodiment, the prioritization module includes the following contents:

[0018] First, for the identified high-frequency call nodes, extract the resource usage data of the call link where they are located, including the CPU usage R cpu 、Memory consumption R mem And I / O load R io , and record its position H in the call hierarchy; calculate the encryption priority score P(L) to quantify the impact of resource usage and call hierarchy on encryption priority, which is calculated by the following formula: Where: L represents the current call link; M L is the total number of high-frequency call nodes in the call link L; represent the CPU usage, memory consumption, and I / O load of the mth high-frequency call node in the call link L; H m Indicates the hierarchical position of the mth node in the call link, ranging from 1 to K, where K is the maximum number of levels; T m and U m Dynamically adjust the memory and I / O load parameters of the mth node.

[0019] In a preferred embodiment, the priority division module further includes the following contents:

[0020] An encryption priority score is calculated for each high-frequency call link; then, the corresponding standard is compared according to the encryption priority score, and the call link is classified into high priority and low priority accordingly.

[0021] In a preferred embodiment, the encryption optimization module includes the following contents:

[0022] First, we retrieve the encryption and decryption module configurations in the high-priority path and their reuse at the node level. By comparing the node logs and call information, we determine the repeated or redundant encryption and decryption trigger points. Then, we optimize the decision for each high-priority path to select the best solution from multiple encryption algorithms and determine whether to merge some repeated operations. Let the path encryption optimization function Ξ(ε, q, s, u) be: Where ε represents the category of candidate encryption algorithms; Ω core and Ω aux They refer to the high-intensity core encryption scheme set and the auxiliary encryption scheme set respectively; q represents the repeated encryption trigger frequency counted in the corresponding path; s represents the impact level of the current algorithm on system performance; u records the cumulative number of key synchronization actions related to the corresponding algorithm in this path.

[0023] In a preferred embodiment, the encryption optimization module further includes the following contents:

[0024] After the calculation is completed, a set of algorithm configuration schemes that minimize the value of the path encryption optimization function is selected, and the repeated encryption and decryption call points that appear in them are streamlined through merging operations or segmented caching.

[0025] In a preferred embodiment, the routing strategy module includes the following contents:

[0026] First, we obtain the optimized encryption scheme and deduplication information from the high-priority path configuration, and then filter out the cross-node requests that are compatible with each other or have small differences by retrieving the request parameters and node distribution, and then merge and evaluate them. To quantify the merging decision, we define the following formula as the merging coordination function γ(δ, ψ): Where δ is the average difference of the parameters or data structures of the requests to be merged, ψ is the concurrency coefficient of the corresponding batch requests, Γ(·) is the Gamma function, and Ei(·) is the exponential integral function.

[0027] In a preferred embodiment, the routing strategy module further includes the following contents:

[0028] If the value of the merge coordination function is lower than the preset threshold, it is determined that this batch of cross-node requests has a strong merging value in terms of execution order and resource scheduling. The dynamic routing module then merges them and compresses the repeated encryption and parsing links into a single execution to reduce the access link depth. After completion, the new routing mapping and merging strategy are written into the routing configuration, and these updates are immediately deployed in the distributed storage system. At the same time, the updated routing configuration will be synchronized to all relevant nodes through the distributed configuration management tool.

[0029] The technical effects and advantages of the intelligent encryption control system of a distributed storage system of the present invention are as follows:

[0030] The present invention aims at the contradiction between the performance bottleneck and security requirements of the distributed storage system under high concurrency conditions, and realizes the dynamic balance between system performance and security through the optimization design of the whole process. Starting from the division of the call chain, the dependency relationship and high-frequency call characteristics of cross-node requests are accurately identified, and the performance burden and encryption and decryption density of different call chains are quantified by coupling calculation to ensure that the key path is effectively screened; the key path is prioritized in combination with the resource occupancy and the call level, so that the encryption strategy can adapt to the performance and security requirements of different scenarios; in the optimization process, based on the refined analysis of the high-priority path, the system overhead caused by encryption and decryption is greatly reduced by adjusting the encryption algorithm and streamlining redundant operations, while ensuring the efficiency and consistency of key management; on this basis, the optimization strategy is embedded in the dynamic routing module, and the method of merging similar requests and shortening the access depth is used to further improve the request processing efficiency and reduce the risk of resource conflicts; the whole scheme realizes the systematic improvement from request identification, strategy optimization to path simplification through the step-by-step transmission and progressive processing of data between modules, and provides an efficient and flexible solution for the distributed storage system, so that it can maintain stable operation with high performance and high security in a complex environment. BRIEF DESCRIPTION OF THE DRAWINGS

[0031] Figure 1 The present invention is a schematic diagram of the structure of an intelligent encryption control system of a distributed storage system. DETAILED DESCRIPTION

[0032] The following will be combined with the drawings in the embodiments of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.

[0033] Embodiment 1: Figure 1The invention provides an intelligent encryption control system for a distributed storage system, comprising: a call chain division module, a coupling degree calculation module, a priority division module, an encryption optimization module and a routing strategy module;

[0034] Call chain division module: divides the cross-node requests recorded in the distributed storage system into multiple independent call chains, and transmits the generated independent call chain data to the coupling degree calculation module;

[0035] Coupling degree calculation module: Mark the function call frequency item by item in each call chain and record the number of encryption and decryption times, calculate the coupling degree table, identify the high-frequency call nodes, and send the high-frequency call nodes to the priority division module;

[0036] Priority classification module: categorizes high-frequency call nodes into encryption priorities according to resource occupancy and call levels, and transmits the determined priority information to the encryption optimization module;

[0037] Encryption optimization module: optimizes the encryption algorithm for high-priority paths and simplifies repeated encryption and decryption operations. The output optimization strategy is passed to the routing strategy module;

[0038] Routing strategy module: applies optimization strategies to the dynamic routing module to merge similar requests and shorten the cross-node access depth.

[0039] When a distributed storage system processes cross-node data requests, the division of call chains is the basis for optimizing performance. Due to the differences in time, space, and business logic between different requests, it is difficult to accurately divide independent call chains by directly using simple time sorting or node identification for classification, resulting in errors in coupling degree calculation and optimization strategy formulation in subsequent analysis. Therefore, this module focuses on building an accurate call chain division model through comprehensive quantitative evaluation of multi-dimensional factors to support the identification and encryption optimization design of subsequent high-frequency call nodes.

[0040] The call chain partitioning module includes the following:

[0041] When differentiating cross-node requests recorded in a distributed storage system into multiple independent call chains, it is necessary to identify the relationship between the requests based on a determination mechanism and eliminate unnecessary redundant associations during the differentiation process.

[0042] First, read the original records of all cross-node requests in the log, form a request vector through timestamp, node sequence number and session identifier, and then perform quantitative calculation on the similarity between request vectors; construct a judgment function F(r i , r j ) to measure the request r i With r j Whether they belong to the same call chain, let r i With r jContains the following key parameters: D i represents the number of node-level hops that a request goes through in a distributed environment, T i , T j Represents the time when the request occurred, U i , U j Represents the identifier of the request in the upper layer business; select positive real constants α and β to adjust the relative influence weights of different factors, and define the following judgment formula:

[0043]

[0044] Item 1 It is used to measure the similarity of requests in cross-node transmission depth. If the request r i and request r j In the distributed storage system, the number of node hops passed during the transmission process is large and the time difference (T i -T j ) is smaller, the exponential term tends to a smaller value, the overall denominator converges, and the value is higher, indicating that the two cross-node requests are more likely to belong to the same chain in terms of spatial and temporal distribution.

[0045] Item 2 Introducing upper layer service identifier U i with U j If the difference between the two is not big, It is close to 1, which makes this item smaller, suggesting that the business scenarios are more consistent, thereby enhancing the reliability of the same-chain judgment.

[0046] By traversing all request pairs in the log (r i , r j ) and calculate the decision function. If the result exceeds the decision threshold, the request r i With request r j Belong to the same call chain. After traversal, output multiple independent call chain lists and the cross-node requests contained in each chain.

[0047] After the call chain division is completed, the independent call chain list will be passed to the coupling calculation module, which is used to mark the function call frequency and calculate the number of encryption and decryption times in each call chain, and output the coupling table. After this process is completed, a call chain division result can be obtained, which lays the foundation for the subsequent identification of performance blocking points and design priorities.

[0048] In the call chain division module, the cross-node requests in the distributed storage system have been successfully divided into multiple independent call chains. Next, the coupling degree calculation module needs to conduct an in-depth analysis of each independent call chain, including marking the call frequency of each function, recording the corresponding number of encryption and decryption operations, and calculating the coupling degree of each call chain based on this. By generating a coupling degree table and analyzing it in detail, it is possible to identify key nodes with high frequency calls and intensive encryption and decryption operations. These nodes are often potential sources of system performance blockage. This process provides the necessary quantitative basis and data support for encryption priority division and optimization strategy formulation in subsequent modules.

[0049] The coupling degree calculation module includes the following contents:

[0050] From the independent call chain set obtained by the call chain partitioning module, process each call chain one by one. For each call chain, parse the system operation log and monitoring data, and extract all the function call records involved. For each function, record its call frequency F in the call chain. m And the number of encryption and decryption operations triggered F e Ensure accurate call frequency and encryption and decryption times data by accurately matching function calls with encryption and decryption operations.

[0051] In order to fully reflect the impact of function call frequency and encryption and decryption operations on the coupling degree of the call chain, the coupling degree is calculated using the following formula:

[0052] in:

[0053] L represents the current call chain;

[0054] N L Represents the total number of functions in the call chain L;

[0055] Indicates the calling frequency of the nth function in the call chain L;

[0056] Indicates the number of encryption and decryption operations of the nth function in the call chain L;

[0057] S n Indicates the total number of operations of the nth function in the call chain L;

[0058] M max Indicates the maximum function call frequency of all call chains in the system.

[0059] Combination of logarithms and exponentials: It is used to alleviate the linear growth problem caused by high call frequency. It emphasizes the proportion of encryption and decryption operations in the total operations, and nonlinearly amplifies the impact of high-proportion encryption and decryption operations on the coupling degree.

[0060] Sum of squares of fourth roots: The influence of combined call frequency and encryption and decryption operations is smoothed by fourth root operation to avoid excessive amplification of the overall coupling degree by a single extreme value.

[0061] Sine modulation: It is used to perform sinusoidal modulation on the calling frequency, so that the coupling contribution tends to be maximum when the calling frequency is high, while maintaining a low coupling value when the calling frequency is low.

[0062] This formula comprehensively considers the relationship between call frequency and encryption and decryption operations through multi-level nonlinear transformations, ensuring that functions with high frequency and high encryption and decryption load have significantly improved call chain coupling.

[0063] The coupling value is used to quantify the combined impact of the function call frequency and the encryption and decryption operation intensity in each independent call chain. Specifically, a higher coupling value indicates that there are frequent function calls and a large number of encryption and decryption operations in the call chain, suggesting that the link may become a performance bottleneck under high load conditions, and therefore needs to be optimized as a priority. On the contrary, a lower coupling value indicates that the function call frequency and encryption and decryption operations in the call chain are relatively small, the system load on this link is light, and the performance impact is small. Therefore, the size of the coupling value directly reflects the potential impact of the call chain on performance and security in the distributed storage system, and assists in identifying key nodes that need to be focused on and optimized to achieve an effective balance between system performance and security.

[0064] For each call chain L, calculate its coupling Φ(L). Sort the coupling values ​​of all call chains from high to low to generate a detailed coupling table. The coupling table should contain the unique identifier of each call chain, the calculated coupling value, and detailed data such as the call frequency and encryption and decryption operation times of each function involved, so as to facilitate subsequent analysis and decision-making.

[0065] Based on the coupling table, the coupling threshold is used to filter out call chains with coupling higher than the coupling threshold. For these high-coupling call chains, the calling frequency and encryption and decryption operation times of each function within them are further analyzed to filter out function nodes that meet both high calling frequency standards and high encryption and decryption operation times standards, and mark them as high-frequency call nodes. These high-frequency call nodes are potential performance blocking points and need to be optimized first in subsequent modules.

[0066] Through the above processing, the coupling degree of each call chain can be accurately quantified, and key nodes with high frequency calls and intensive encryption and decryption operations can be identified. The generated coupling degree table not only provides reliable data support for the division of encryption priorities in subsequent modules, but also points out the direction for the location of system performance bottlenecks and the formulation of optimization strategies. This process ensures that in the distributed storage system, targeted encryption optimization can be carried out based on accurate coupling degree analysis to achieve an effective balance between performance and security.

[0067] In the coupling calculation module, the coupling table is used to identify the key nodes in the distributed storage system that are frequently called and have intensive encryption and decryption operations. These nodes potentially constitute system performance bottlenecks. Next, the priority division module will further analyze the call links where these high-frequency call nodes are located, and classify their encryption priorities according to resource occupancy and call level to ensure the effective allocation of optimized resources and the improvement of overall system performance.

[0068] The prioritization module includes the following:

[0069] First, for the high-frequency call nodes identified in the coupling calculation module, the resource usage data of the call link is extracted, including but not limited to the CPU usage R cpu 、Memory consumption R mem and I / O load R io , and record its position H in the call hierarchy (such as core service layer, middleware layer or auxiliary service layer). Calculate the encryption priority score P(L) to quantify the impact of resource usage and call hierarchy on encryption priority, for example, through the following calculation formula:

[0070] in:

[0071] L represents the current call link;

[0072] M L is the total number of high-frequency call nodes in the call link L;

[0073] They represent the CPU usage, memory consumption, and I / O load of the mth high-frequency call node in the call link L, respectively;

[0074] H m Indicates the hierarchical position of the mth node in the call chain, ranging from 1 to K, where K is the maximum number of levels;

[0075] T m and U m Dynamically adjust the memory and I / O load parameters of the mth node.

[0076] Combining logarithms with cosines: Alleviate the linear growth caused by high CPU usage, and The contribution to the priority is adjusted according to the calling hierarchy, with the core hierarchy (lower hierarchy positions) being given higher priority.

[0077] Exponential and hyperbolic tangent functions: Map memory consumption in an S-shaped manner, ensuring that memory usage has a significant impact on priorities when it is in the medium range, and tends to be stable when it is extremely high or low; The I / O load is mapped to the (-1, 1) interval, emphasizing the effect of high I / O load on improving priority.

[0078] Square root adjustment: The overall square root operation smoothes the combined impact of various factors to avoid excessive amplification of the priority by a single high value.

[0079] The encryption priority score is used to quantify the encryption optimization requirements of each call link in the distributed storage system. Its value reflects the comprehensive importance of the call link in terms of resource occupancy and call level. Specifically, a higher encryption priority score indicates that the call link occupies more resources in the system and is at a critical call level. Therefore, it is necessary to prioritize encryption algorithm optimization and simplification of repeated encryption and decryption operations to ensure that the optimization effect of system performance and security is maximized. On the contrary, a lower encryption priority score means that the call link occupies less resources and is at a lower call level. Its optimization requirements are relatively low, and it can be moderately optimized when resources are sufficient. Therefore, the size of the encryption priority score directly guides the allocation order of optimization resources, ensuring that the system achieves the best balance between performance and security under limited resources.

[0080] By applying the above priority calculation formula to each high-frequency call link, an encryption priority score is generated; then, the corresponding standards are compared according to the encryption priority score, and the call links are classified into high priority and low priority accordingly to guide subsequent encryption optimization measures. This process ensures that nodes with high resource usage and at the key call level receive higher encryption optimization priority, thereby achieving orderly optimization of encryption strategies in distributed storage systems and improving overall system performance and security.

[0081] Through the above processing, the system can divide the encryption priority for the call links where high-frequency call nodes are located based on a comprehensive analysis of resource usage and call levels. This process not only ensures that key nodes are given priority during the optimization process, improves the performance of the system under high load conditions, but also maintains the security of the distributed storage system. The generated encryption priority classification provides clear guidance for subsequent encryption algorithm optimization and dynamic routing adjustments, ensuring that the implementation of the optimization strategy is targeted and efficient, and achieving a coordinated improvement in system performance and security.

[0082] After completing the identification of high-priority paths in the priority division module, the encryption optimization module needs to fine-tune the encryption algorithms of these paths and eliminate redundant encryption and decryption operations to improve the balance between performance and security.

[0083] The encryption optimization module includes the following:

[0084] First, we retrieve the configuration of encryption and decryption modules in the high-priority path and their reuse at the node level, and determine the repeated or redundant encryption and decryption trigger points by comparing the node logs and call information. Then we optimize the decision for each high-priority path to select the best solution from multiple encryption algorithms and determine whether to merge some repeated operations. The path encryption optimization function Ξ(ε, q, s, u) can be written as: Where ε represents the category of candidate encryption algorithms; n core and Ω aux They refer to the high-intensity core encryption scheme set and the auxiliary encryption scheme set respectively; q represents the repeated encryption trigger frequency counted in the path; u records the cumulative number of key synchronization actions related to the corresponding algorithm in this path.

[0085] s represents the comprehensive impact level of the current encryption algorithm on system performance, and its value is calculated by analyzing and calculating multi-dimensional performance indicators during the algorithm execution process. Specifically, it includes core indicators such as the algorithm's CPU usage, memory consumption, and number of I / O operations per unit time, as well as its contribution to the delay of system response time under high concurrency. For example, the calculation formula can be: Among them, α1, β1, and γ1 are positive real constants for adjusting the weights of different dimensions. By combining the above performance indicators, the larger the value, the higher the execution overhead of the current algorithm and the heavier the burden on system performance. It is suitable for evaluating the performance impact of the algorithm and guiding the selection of optimization strategies.

[0086] The upper branch in the formula is used to process the core algorithm route, which nonlinearly combines the repeated encryption frequency q with the performance overhead s, and comprehensively considers the restraining relationship between repetition and overhead through arccos and cube root operations; the lower branch is used to evaluate the auxiliary algorithm route, using arccos and tanh functions to smoothly map repetition and synchronization overhead in a wider range to avoid excessive fluctuations caused by extreme scenarios.

[0087] After the calculation is completed, a set of algorithm configuration schemes that minimize the value of the path encryption optimization function is selected, and the repeated encryption and decryption call points that appear in them are streamlined through merging operations or segmented caching.

[0088] After the above optimization is completed, the new algorithm scheme and streamlined strategy are written into the path configuration file, and the results are applied by the dynamic routing module of the routing strategy module. Ultimately, this process provides a more efficient basis for subsequent monitoring and encryption mode switching, accelerates the execution efficiency of high-priority paths in distributed storage systems, and maintains the necessary security protection level.

[0089] After completing the encryption algorithm for high-priority paths and streamlining redundant encryption and decryption operations in the encryption optimization module, the routing strategy module needs to inject the resulting optimization strategy into the dynamic routing module in order to merge similar requests and shorten the cross-node access depth.

[0090] The routing policy module includes the following:

[0091] The specific process first obtains the optimized encryption scheme and deduplication processing information from the high-priority path configuration, and then screens out cross-node requests that are compatible or have little difference by retrieving request parameters and node distribution, and then merges and evaluates them. In order to quantify the merge decision, the following formula is defined as the merge coordination function Where δ is the average difference of the parameters or data structures of the requests to be merged, ψ is the concurrency coefficient of the batch of requests, Γ(·) is the Gamma function, and Ei(·) is the exponential integral function.

[0092] If the value of the merge coordination function is lower than the preset threshold, it is determined that this batch of cross-node requests has a strong merging value in terms of execution order and resource scheduling. The dynamic routing module then merges them and compresses the repeated encryption and parsing links into a single execution, significantly reducing the access link depth.

[0093] Once completed, write the new route mapping and merge strategy to the routing configuration and immediately deploy these updates in the distributed storage system. The system should automatically perform the configuration verification process to ensure the correctness and effectiveness of the new routing and merge strategy to avoid introducing additional delays or security vulnerabilities. At the same time, the updated routing configuration will be synchronized to all relevant nodes through the distributed configuration management tool to ensure global consistency and coordination.

[0094] By integrating the optimized encryption strategy into the dynamic routing module, the system can intelligently merge similar requests and shorten the cross-node access depth, thereby significantly improving the overall performance and resource utilization efficiency of the distributed storage system. Specifically, the optimized routing strategy automatically identifies and merges cross-node requests with high similarity or compatibility by quantitatively evaluating the merge coordination of requests, reducing the number of repeated encryption and decryption operations and optimizing the data transmission path. This process not only reduces the delay time of request processing, improves the throughput and response speed of the system, but also effectively reduces the utilization rate of CPU and memory, extends the service life of hardware devices, and reduces operating costs. At the same time, despite the reduction of encryption and decryption operations, the system still ensures the security of data transmission through refined encryption strategies and dynamic routing adjustments. In addition, the intelligent adjustment capability of the dynamic routing module enhances the scalability and adaptability of the system, enabling it to flexibly respond to changing request patterns and network conditions, further improving user experience and system competitiveness. Overall, the optimization strategy achieves multiple improvements in performance, resource utilization, security and scalability, ensuring that the distributed storage system can still operate efficiently and securely in high concurrency and complex environments.

[0095] The above formulas are all dimensionless and numerical calculations. The formula is a formula for the most recent real situation obtained by collecting a large amount of data and performing software simulation. The preset parameters in the formula are set by technicians in this field according to actual conditions.

[0096] The above description is only by way of illustration of certain exemplary embodiments of the present invention. It is undoubted that those skilled in the art can modify the described embodiments in various ways without departing from the spirit and scope of the present invention. Therefore, the above drawings and descriptions are illustrative in nature and should not be construed as limiting the scope of protection of the claims of the present invention.

[0097] It should be noted that, in this article, if there are relational terms such as first and second, etc., they are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Moreover, the terms "include", "comprise" or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, article or device. In the absence of further restrictions, the elements defined by the sentence "including a..." do not exclude the existence of other identical elements in the process, method, article or device including the elements.

[0098] The above is only a specific implementation of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art who is familiar with the present technical field can easily think of changes or substitutions within the technical scope disclosed in the present application, which should be included in the protection scope of the present application. Therefore, the protection scope of the present application should be based on the protection scope of the claims.

Claims

1. An intelligent encryption control system for a distributed storage system, characterized in that: include: Call chain division module, coupling degree calculation module, priority division module, encryption optimization module and routing strategy module; Call chain division module: divides the cross-node requests recorded in the distributed storage system into multiple independent call chains, and transmits the generated independent call chain data to the coupling degree calculation module; Coupling degree calculation module: Mark the function call frequency item by item in each call chain and record the number of encryption and decryption times, calculate the coupling degree table, identify the high-frequency call nodes, and send the high-frequency call nodes to the priority division module; Priority classification module: categorizes high-frequency call nodes into encryption priorities according to resource occupancy and call levels, and transmits the determined priority information to the encryption optimization module; Encryption optimization module: optimizes the encryption algorithm for high-priority paths and simplifies repeated encryption and decryption operations. The output optimization strategy is passed to the routing strategy module; Routing strategy module: applies optimization strategies to the dynamic routing module to merge similar requests and shorten the cross-node access depth.

2. The intelligent encryption control system of a distributed storage system according to claim 1, characterized in that: The call chain partitioning module includes the following: First, read the original records of all cross-node requests in the log, form a request vector through timestamp, node sequence number and session identifier, and then perform quantitative calculation on the similarity between request vectors; construct the judgment function F(r i ,r j ) to measure the request r i With r j Whether they belong to the same call chain, let r i With r j Contains the following key parameters: D i represents the number of node-level hops that a request goes through in a distributed environment, T i , T j Represents the time when the request occurred, U i , U j Represents the identifier of the request in the upper layer business; Positive real constants α and β are selected to adjust the relative influence weights of different factors, and the following judgment formula is defined: By traversing all request pairs in the log (r i ,r j ) and calculate the decision function. If the result exceeds the decision threshold, the request r i With request r j Belong to the same call chain.

3. The intelligent encryption control system of a distributed storage system according to claim 2, characterized in that: The coupling degree calculation module includes the following contents: For each call chain, parse the system operation log and monitoring data to extract all the function call records involved; for each function, record its call frequency F in the corresponding call chain m And the number of encryption and decryption operations triggered F e ; The coupling degree is calculated by the following formula: Where: L represents the current call chain; N L Represents the total number of functions in the call chain L; Indicates the calling frequency of the nth function in the call chain L; Indicates the number of encryption and decryption operations of the nth function in the call chain L; S n Indicates the total number of operations of the nth function in the call chain L; M max Indicates the maximum function call frequency of all call chains in the system.

4. The intelligent encryption control system of a distributed storage system according to claim 3, characterized in that: The coupling degree calculation module also includes the following: For each call chain, calculate its coupling degree separately; Sort the coupling values ​​of all call chains from high to low to generate a coupling table; Based on the coupling table, use the coupling threshold to filter out call chains with coupling higher than the coupling threshold. For these high-coupling call chains, analyze the calling frequency and encryption and decryption operation times of each function within them, filter out function nodes that meet both high calling frequency and high encryption and decryption operation times standards, and mark them as high-frequency call nodes. These high-frequency call nodes are potential performance blocking points and need to be optimized first.

5. The intelligent encryption control system of a distributed storage system according to claim 4, characterized in that: The prioritization module includes the following: First, for the identified high-frequency call nodes, extract the resource usage data of the call link where they are located, including the CPU usage R cpu 、Memory consumption R mem and I / O load R io , and record its position H in the calling hierarchy; The encryption priority score P(L) is calculated to quantify the impact of resource usage and call level on encryption priority, which is calculated using the following formula: Where: L represents the current call link; M L is the total number of high-frequency call nodes in the call link L; represent the CPU usage, memory consumption, and I / O load of the mth high-frequency call node in the call link L; H m Indicates the hierarchical position of the mth node in the call link, ranging from 1 to K, where K is the maximum number of levels; T m and U m Dynamically adjust the memory and I / O load parameters of the mth node.

6. The intelligent encryption control system of a distributed storage system according to claim 5, characterized in that: The prioritization module also includes the following: An encryption priority score is calculated for each high-frequency call link; then, the corresponding standard is compared according to the encryption priority score, and the call link is classified into high priority and low priority accordingly.

7. The intelligent encryption control system of a distributed storage system according to claim 6, characterized in that: The encryption optimization module includes the following: First, we retrieve the encryption and decryption module configurations in the high-priority path and their reuse at the node level. By comparing the node logs and call information, we determine the repeated or redundant encryption and decryption trigger points. Then, we optimize the decision for each high-priority path to select the best solution from multiple encryption algorithms and determine whether to merge some repeated operations. Let the path encryption optimization function Ξ(ε,q,s,u) be: Where ε represents the category of candidate encryption algorithms; Ω core and Ω aux They refer to the high-intensity core encryption scheme set and the auxiliary encryption scheme set respectively; q represents the repeated encryption trigger frequency counted in the corresponding path; s represents the impact level of the current algorithm on system performance; u records the cumulative number of key synchronization actions related to the corresponding algorithm in this path.

8. The intelligent encryption control system of a distributed storage system according to claim 7, characterized in that: The encryption optimization module also includes the following: After the calculation is completed, a set of algorithm configuration schemes that minimize the value of the path encryption optimization function is selected, and the repeated encryption and decryption call points that appear in them are streamlined through merging operations or segmented caching.

9. The intelligent encryption control system of a distributed storage system according to claim 8, characterized in that: The routing policy module includes the following: First, obtain the optimized encryption scheme and deduplication processing information from the high-priority path configuration, and filter out cross-node requests that are compatible or have small differences by retrieving request parameters and node distribution, and merge and evaluate them; in order to quantify the merging decision, define the following formula as the merging coordination function Where δ is the average difference of the parameters or data structures of the requests to be merged, ψ is the concurrency coefficient of the corresponding batch requests, Γ(·) is the Gamma function, and Ei(·) is the exponential integral function.

10. The intelligent encryption control system of a distributed storage system according to claim 9, characterized in that: The routing policy module also includes the following: If the value of the merge coordination function is lower than the preset threshold, it is determined that this batch of cross-node requests has a strong merging value in terms of execution order and resource scheduling. The dynamic routing module then merges them and compresses the repeated encryption and parsing links into a single execution to reduce the access link depth. After completion, the new routing mapping and merging strategy are written into the routing configuration, and these updates are immediately deployed in the distributed storage system. At the same time, the updated routing configuration will be synchronized to all relevant nodes through the distributed configuration management tool.