Evidence fixing method and device based on double caches of file system and storage medium
By using file system double caching technology in the evidence fixation method, the file system metadata and device are written as two objects for data, the problem that the existing technology cannot meet the powerful file management and efficient performance at the same time is solved, and a more efficient evidence fixation process is achieved.
Patent Information
- Application Number
- CN202411837844.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-13
- Publication Date
- 2025-05-06
AI Technical Summary
The existing evidence fixation method cannot be met in application scenarios that require both strong file management capabilities and efficient performance.
Using a file system double cache method, file system metadata and device are used as two objects, and data is written through double cache to improve performance.
It realizes the improvement of evidence fixation performance on the basis of strong file management capabilities, ensures efficient reading and writing of metadata and file content, and avoids the impact of metadata cache and write failure on evidence solidification.
Smart Images

Figure CN119937912A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of information security technology, and in particular to a method, device and storage medium for fixing evidence based on file system double cache. Background Art
[0002] In the process of evidence collection and preservation, sometimes it is not necessary to extract the entire hard disk data, but only to extract the information in certain files or folders (such as extracting only certain file data in a USB flash drive). Sometimes, logical data acquisition is also used to extract special areas of the disk (unallocated clusters). The logical evidence file structure of different forensic manufacturers is different. The following are several popular evidence fixation methods in the industry.
[0003] (1) Non-file system solutions: file aggregation tools such as Tar and custom formats. Multiple files or directories can be easily combined into one file for easy storage, transmission or backup. It does not directly involve the management of the file system, but is a tool for file operations, used for archiving and compression of files.
[0004] (2) File system solutions: EXT4, NTFS, exFAT, etc. FAT32 is one of the oldest file systems with the best compatibility but poor performance; NTFS has better performance than FAT32 but is not as compatible as FAT32; exFAT is designed specifically for flash memory devices and has better compatibility and better performance than FAT32 and NTFS; EXT4 has better performance than FAT32 and NTFS but is not as compatible as FAT32 and NTFS; XFS and Btrfs are newer generation file systems with better performance than FAT32, NTFS, and EXT4 but not as compatible as FAT32 and NTFS.
[0005] Existing technologies only focus on one aspect of evidence fixation, such as convenient storage, powerful file management, automatic expansion, real-time mounting, etc. They cannot meet the application scenarios that require powerful file management capabilities and high performance at the same time. Summary of the invention
[0006] In order to solve the above technical problems, the present invention provides an evidence fixing method, device and storage medium based on file system double cache, which takes file system metadata and device as two objects, writes data based on double cache, and improves performance.
[0007] The present invention adopts the following technical solution:
[0008] In a first aspect, a method for fixing evidence based on file system double cache includes:
[0009] Define two objects: file system metadata and device; file system metadata is the structural data used by the file system to manage file storage, and device is the physical device where the target file fixed by the evidence is to be written;
[0010] When writing to the metadata cache, determine whether the metadata exists in all metadata cache blocks of the file system metadata object. If so, write the new metadata content into the matching metadata cache block; otherwise, dynamically add a new metadata cache block to record the target file information.
[0011] When writing to the target file cache, the file content block is written to the partition and / or physical device corresponding to the device cache area according to the fixed device cache area size and the size of the file content block;
[0012] After the target file cache is written, the device cache area that caches the file content blocks is written to the physical device; after the metadata cache is written, all metadata cache blocks are written to the physical device.
[0013] Preferably, data with a modification frequency greater than a preset value is attributed to a file system metadata object, and data with a modification frequency less than or equal to the preset value is attributed to a device object.
[0014] Preferably, when data cache that belongs to the file system metadata object but does not belong to the metadata is written, it is processed by dynamically adding cache blocks; when data cache that belongs to the device object but does not belong to the target file content is written, it is processed by fixing the device cache area.
[0015] Preferably, the metadata cache writing process is as follows:
[0016] S21, using the offset and length of the target file as keywords, determine whether the written metadata exists in all metadata cache blocks of the file system metadata object. If yes, go to S22; otherwise, go to S23.
[0017] S22, writing the metadata content to be written into the matching metadata cache block;
[0018] S23, apply for a new metadata cache block, write the metadata content to be written into the new metadata cache block, and record the offset, length and offset of the target file in the metadata cache.
[0019] Preferably, the target file cache writing process is as follows:
[0020] When writing to the target file cache, the current cache usage size of the device cache is recorded. When the current cache is full, it is written to the physical device in real time, and then jumps to the next cache in combination with the physical offset of the written file content block, and loops in sequence until the file content block is written or the written cache reaches the preset number.
[0021] Preferably, when writing to the target file cache, the current cache usage size of the device cache is recorded. When the current cache is full, it is written to the physical device in real time, and then jumps to the next cache in combination with the physical offset of the written file content block, and the cycle is repeated until the file content block is written or the written cache reaches a preset number, as follows:
[0022] S31, let the physical device offset corresponding to the starting position of the current buffer area be X, and write the first file content block at the starting position of the current buffer area;
[0023] S32, determine the physical offset and length of the written file content block, if it is in the current buffer area, go to S33, if it is in the next buffer area, go to S34, if it is after two buffer areas, go to S35;
[0024] S33, directly write the file content block into the corresponding position of the current buffer area, and go to S36;
[0025] S34, divide the file content block into two parts, fill the current buffer area with the first half, and write the current buffer area into the physical device; write the second half of the file content into the next buffer area, and go to S36;
[0026] S35, write the file content block directly into the physical device, and go to S36;
[0027] S36, jump to the next file content block.
[0028] Preferably, the evidence fixing method based on file system double cache also includes: associating metadata cache reading and writing with device cache writing and device reading, so that evidence can be solidified through device cache writing after metadata cache writing fails, and can be obtained through device reading after metadata cache reading fails.
[0029] In a second aspect, an evidence fixing device based on file system double cache includes:
[0030] The object partitioning module is used to define two objects: file system metadata and device; wherein the file system metadata is the structural data used by the file system to manage file storage, and the device is the physical device to which the target file fixed by the evidence is to be written;
[0031] The metadata cache writing module is used to determine whether the metadata exists in all metadata cache blocks of the file system metadata object when writing the metadata cache. If so, write the new metadata content into the matching metadata cache block; otherwise, dynamically add a new metadata cache block to record the information of the target file;
[0032] The target file cache writing module is used to write the file content block into the partition and / or physical device corresponding to the device cache area according to the fixed device cache area size and the size of the file content block when the target file cache is written;
[0033] The evidence fixing module is used to write the device cache area with the file content blocks cached in it to the physical device after the target file cache is written; and to write all metadata cache blocks to the physical device after the metadata cache is written.
[0034] According to a third aspect, an electronic device includes:
[0035] one or more processors;
[0036] a storage device for storing one or more programs,
[0037] When the one or more programs are executed by the one or more processors, the one or more processors implement the evidence fixing method based on file system double cache.
[0038] In a fourth aspect, a computer-readable storage medium is provided, wherein a computer program code is stored on the storage medium, and wherein the evidence fixing method based on file system double cache is executed when the computer program code is executed by a computer.
[0039] The present invention has the following beneficial effects:
[0040] (1) Based on the powerful file management and expansion capabilities of conventional file systems, the present invention treats file system metadata and devices as two objects, performs reading and writing based on double buffering, and improves performance;
[0041] (2) Since metadata is small and scattered, while file content is large and relatively concentrated (in evidence fixation, continuous storage is generally used, and fragmented storage is rare), the metadata cache of the present invention is composed of multiple cache blocks, each of which corresponds to a data structure that records the offset of the metadata in the target file, the offset in the cache, and the length information. The metadata cache is increased based on the metadata application written; while the device cache is of a fixed size, which is set in combination with the actual operating environment and memory size to meet the needs of fast caching;
[0042] (3) The present invention associates the reading and writing of the metadata cache with the writing and reading of the device cache. After the reading and writing of the metadata cache fails, the writing and reading of the device cache can meet the reading and writing requirements of the metadata, so that the failure of the reading and writing of the metadata cache does not affect the fixation of evidence, but only has a certain impact on the performance.
[0043] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the drawings required for use in the description of the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work. BRIEF DESCRIPTION OF THE DRAWINGS
[0044] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the drawings required for use in the description of the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative work.
[0045] Figure 1 is an exemplary device architecture diagram to which an embodiment of the present application may be applied;
[0046] Figure 2 A flowchart of a method for fixing evidence based on file system double cache according to an embodiment of the present application;
[0047] Figure 3 A schematic diagram of file system metadata according to an embodiment of the present application;
[0048] Figure 4 A schematic diagram of a device processing object (file content) according to an embodiment of the present application;
[0049] Figure 5 A schematic diagram of an evidence fixing device based on file system double cache according to an embodiment of the present application;
[0050] Figure 6 It is a schematic diagram of the structure of a computer device suitable for implementing the electronic device of the embodiment of the present application. DETAILED DESCRIPTION
[0051] The technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention; it is obvious that the described embodiments are only part of the embodiments of the present invention, rather than all the embodiments, and all other embodiments obtained by ordinary technicians in this field based on the embodiments of the present invention without making creative work are within the scope of protection of the present invention.
[0052] In the description of the present invention, it should be noted that the terms "comprises", "includes" or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements includes not only those elements, but also includes other elements not explicitly listed, or also includes elements inherent to such process, method, article or device. In the absence of further restrictions, an element defined by the sentence "comprises a ..." does not exclude the existence of other identical elements in the process, method, article or device including the element.
[0053] In the description of the present invention, it should be noted that, unless otherwise clearly specified and limited, step identifiers S1, S2, S3, etc. are only used for convenient expression and do not represent the execution order. The corresponding execution order can be adjusted as needed.
[0054] Figure 1 An exemplary device architecture 100 is shown to which the evidence fixing method based on file system double cache or the evidence fixing device based on file system double cache according to the embodiment of the present application can be applied.
[0055] like Figure 1 As shown, the device architecture 100 may include a terminal device 1 101, a terminal device 2 102, a terminal device 3 103, a network 104, and a server 105. The network 104 is used to provide a medium for a communication link between the terminal device 1 101, the terminal device 2 102, the terminal device 3 103, and the server 105. The network 104 may include various connection types, such as wired, wireless communication links, or optical fiber cables, etc.
[0056] The user can use the terminal device 101, the terminal device 2 102, and the terminal device 3 103 to interact with the server 105 through the network 104 to receive or send messages, etc. Various applications, such as data processing applications, file processing applications, etc., can be installed on the terminal device 101, the terminal device 2 102, and the terminal device 3 103.
[0057] Terminal device 1 101, terminal device 2 102, and terminal device 3 103 can be hardware or software. When terminal device 1 101, terminal device 2 102, and terminal device 3 103 are hardware, they can be various electronic devices, including but not limited to smart phones, tablet computers, laptop computers, and desktop computers, etc. When terminal device 1 101, terminal device 2 102, and terminal device 3 103 are software, they can be installed in the electronic devices listed above. It can be implemented as multiple software or software modules (for example, software or software modules used to provide distributed services), or it can be implemented as a single software or software module. No specific limitation is made here.
[0058] The server 105 may be a server that provides various services, such as a background data processing server that processes files or data uploaded by the terminal device 101, the terminal device 2 102, and the terminal device 3 103. The background data processing server may process the acquired files or data and generate processing results.
[0059] It should be noted that the evidence fixing method based on file system double cache provided in the embodiment of the present application can be executed by the server 105, and can also be executed by the terminal device 1 101, the terminal device 2 102, and the terminal device 3 103. Accordingly, the evidence fixing device based on file system double cache can be set in the server 105, and can also be set in the terminal device 1 101, the terminal device 2 102, and the terminal device 3 103.
[0060] It should be understood that Figure 1 The number of terminal devices, networks and servers in the embodiment is only for illustration. Any number of terminal devices, networks and servers may be provided as required. In the case where the processed data does not need to be obtained remotely, the above device architecture may not include a network, but only a server or a terminal device.
[0061] like Figure 2 As shown, the present invention discloses an evidence fixing method based on file system double cache, which includes the following steps.
[0062] S1, define two objects: file system metadata and device; wherein, file system metadata is structural data used by the file system to manage file storage, and device is the physical device to which the target file fixed by the evidence is to be written.
[0063] Specifically, the metadata structure organization of each file system is different. You can refer to the corresponding standard documents. The device's processing object is mainly the file content. The reference standard for distinguishing between the two objects of file system metadata and device is whether they need to be modified during the fixing process. File content is generally not rewritten after writing, but metadata needs to be rewritten. For example, in the Ext4 file system, the file system metadata includes super blocks, group descriptors, block bitmaps, node bitmaps, and node tables. File system metadata and device processing objects (file content) are as follows Figure 3 and Figure 4 shown.
[0064] Furthermore, the special points of the file system are classified as one of the two objects: file system metadata or device. For example, there is a special point in Ext4, where the file has a concept of an indirect node block. This part does not belong to the file content, but it may be released for modification in the middle, so it can be classified as a metadata object according to the reference standard. Other file systems also have special points. The supplementary judgment standard provided by the present invention is: the part between the metadata and the file content needs to be verified and adjusted in combination with the actual read and write frequency, because it can be written to the target device in real time. The adjustment method is: the one with a low modification frequency is classified as a device object, and the one with a high modification frequency is classified as a file system metadata object. The modification frequency is set according to the actual application, and it does not have much impact on the performance.
[0065] S2, when writing metadata cache, determine whether the metadata exists in all metadata cache blocks of the file system metadata object. If so, write the new metadata content into the matching metadata cache block; otherwise, dynamically add a new metadata cache block to record the information of the target file.
[0066] Specifically, it is necessary to define caches for two objects, file system metadata and device. The difference between file system metadata and file content is that metadata is small and scattered, while file content is large and relatively concentrated (continuous storage is generally used in evidence fixation, and fragmented storage scenarios are relatively rare). Therefore, in the present invention, the metadata cache is set to consist of multiple cache blocks, each cache block corresponds to a data structure, and the structure records three information: the offset of the metadata in the target file, the offset in the cache, and the length. The metadata cache is increased based on the metadata application written; the device cache is a fixed size, and the larger the better, combined with the actual operating environment and memory size. For example, if the physical memory is 8G, the device cache can be selected as 1G, 2G, etc.
[0067] In this embodiment, the metadata cache is read and written, and the focus is on dynamically adding cache blocks in the metadata cache write to achieve fast matching in the subsequent metadata cache read process. The metadata cache write process is as follows:
[0068] S21, using the offset and length of the target file as keywords, determine whether the written metadata exists in all metadata cache blocks of the file system metadata object. If yes, go to S22; otherwise, go to S23.
[0069] S22, writing the metadata content to be written into the matching metadata cache block;
[0070] S23, apply for a new metadata cache block, write the metadata content to be written into the new metadata cache block, and record the offset, length and offset of the target file in the metadata cache.
[0071] It should be noted that for the special point of the file system, if some cache blocks are recycled during the evidence fixation process, an invalidation mark needs to be added. The role of the mark is not to participate in the cache block judgment in S21 and not to write to the device in S4 to avoid overwriting the file content in the end.
[0072] S3, when the target file cache is written, the file content block is written into the partition and / or physical device corresponding to the device cache area according to the fixed device cache area size and the size of the file content block.
[0073] When implementing device cache writing (file content is generally not rewritten after writing, so cache reading is not required), the following situations need to be considered: the write position is in the current cache area; the write position is in the next cache area; the write position is after two cache areas, etc. At the same time, the usage size of the current cache area is recorded. When the current cache area is full, it is written to the physical device in real time, and then jumps to the next cache area in combination with the physical offset. Let the cache area length be L.
[0074] The processing process is as follows:
[0075] S31, the current buffer start position corresponds to the physical device offset X, initially X=0, and the first file content block is written;
[0076] S32, determine the physical offset + length of the written data, if it is in the current cache area, go to S33, if it is in the next cache area, go to S34, if it is after two cache areas, go to S35;
[0077] S33, write the file content block directly into the corresponding position of the current buffer area (physical offset of the written data - X), and go to S36;
[0078] S34, divide the file content block into two parts, fill the current buffer area with the first half, and write the current buffer area into the device; the starting position of the current buffer area corresponds to the physical device offset X+L, and the second half of the file content is written into the current buffer area, and then go to S36;
[0079] S35, write the file content block directly into the physical device, and go to S36;
[0080] S36 jumps to the next file content block.
[0081] S4, after the target file cache is written, the device cache area with the file content blocks cached is written to the physical device; after the metadata cache is written, all metadata cache blocks are written to the physical device.
[0082] It should be noted that writing the device cache area with the file content block cached to the physical device can actually be understood as writing the last device cache area to the physical device. The last device cache area is defined as the physical device offset address Y corresponding to the starting position of the cache area, where Y = target file size - target file size % device cache size.
[0083] Furthermore, the evidence fixation method based on file system double cache also includes: associating metadata cache reading and writing with device cache writing and device reading, and being able to fix evidence through device cache writing after metadata cache writing fails, and being able to obtain evidence through device reading after metadata cache reading fails. This ensures that metadata cache reading and writing failure does not affect business processing and evidence fixation, and only has a certain impact on performance.
[0084] The time consumption of using the tar tool to solidify evidence and using the EXT4 solution optimized by the present invention to solidify evidence is compared as follows.
[0085] Application scenarios:
[0086] Source data (mechanical disk Y disk): 5G size, 46535 files, 34450 folders.
[0087] Target image (mechanical disk X disk 1.9T, remaining 439G status): copy an image immediately after writing it.
[0088] The total time taken to package using the tar tool is 840 seconds, of which traversing the files before creating the image takes 120 seconds. The optimized EXT4 solution of the present invention takes 761 seconds. It can be seen that the evidence fixing method based on file system double cache of the present invention performs better than the existing non-file system solution.
[0089] In summary, based on the existing file system solutions (based on the powerful file management and expansion capabilities of conventional file systems), the present invention proposes an evidence fixation method based on file system double cache, which takes the file system metadata and file content as two objects, the file system metadata is based on cache reading and writing, and the file content is based on cache writing (no need to read, when reading, it is read directly from the physical device, not from the cache). It is suitable for all file systems and has been successfully applied to the logical evidence rapid fixation method of smart terminals, thereby improving the performance of evidence fixation.
[0090] like Figure 5 As shown, the present invention provides an embodiment of an evidence fixing device based on file system double cache, and the device embodiment is Figure 2 Corresponding to the method embodiment shown, the device can be specifically applied to various electronic devices, including:
[0091] The object division module 501 is used to define two objects: file system metadata and device; wherein the file system metadata is the structural data used by the file system to manage file storage, and the device is the physical device to which the target file fixed by the evidence is to be written;
[0092] The metadata cache writing module 502 is used to determine whether the metadata exists in all metadata cache blocks of the file system metadata object when writing the metadata cache. If yes, write the new metadata content into the matching metadata cache block; otherwise, dynamically add a new metadata cache block to record the information of the target file;
[0093] The target file cache writing module 503 is used to write the file content block into the partition and / or physical device corresponding to the device cache area according to the fixed device cache area size and the size of the file content block when writing the target file cache;
[0094] The evidence fixing module 504 is used to write the device cache area with the file content blocks cached into the physical device after the target file cache is written; and to write all metadata cache blocks into the physical device after the metadata cache is written.
[0095] like Figure 6 As shown, it shows an electronic device (eg, Figure 1 A schematic diagram of the structure of a computer device 600 (a server or terminal device as shown). Figure 6 The electronic device shown is only an example and should not limit the functions and scope of use of the embodiments of the present application. Figure 6As shown, the computer device 600 includes a central processing unit (CPU) 601 and a graphics processing unit (GPU) 602, which can perform various appropriate actions and processes according to the program stored in the read-only memory (ROM) 603 or the program loaded from the storage part 609 to the random access memory (RAM) 604. In the RAM 604, various programs and data required for the operation of the computer device 600 are also stored. The CPU 601, GPU 602, ROM 603 and RAM 604 are connected to each other through a bus 605. The input / output (I / O) interface 606 is also connected to the bus 605. The following components are connected to the I / O interface 606: an input part 607 including a keyboard, a mouse, etc.; an output part 608 including a display such as, a liquid crystal display (LCD), etc. and a speaker; a storage part 609 including a hard disk, etc.; and a communication part 610 including a network interface card such as a LAN card, a modem, etc. The communication part 610 performs communication processing via a network such as the Internet. The driver 611 can also be connected to the I / O interface 606 as needed. A removable medium 612, such as a magnetic disk, an optical disk, a magneto-optical disk, a semiconductor memory, or the like, is mounted on the drive 611 as needed so that a computer program read therefrom is installed into the storage section 609 as needed.
[0096] In particular, according to an embodiment of the present disclosure, the process described above with reference to the flowchart can be implemented as a computer software program. For example, an embodiment of the present disclosure includes a computer program product, which includes a computer program carried on a computer-readable medium, and the computer program includes a program code for executing the method shown in the flowchart. In such an embodiment, the computer program can be downloaded and installed from a network through a communication part 610, and / or installed from a removable medium 612. When the computer program is executed by a central processing unit (CPU) 601 and a graphics processing unit (GPU) 602, the above-mentioned functions defined in the method of the present application are executed.
[0097] It should be noted that the computer-readable medium described in the present application may be a computer-readable signal medium or a computer-readable medium or any combination of the above two. The computer-readable medium may be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared or semiconductor device, device or component, or any combination of the above. More specific examples of computer-readable media may include, but are not limited to: an electrical connection with one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In the present application, a computer-readable medium may be any tangible medium containing or storing a program that can be used by or in combination with an instruction execution device, device or device. In the present application, a computer-readable signal medium may include a data signal propagated in a baseband or as part of a carrier wave, which carries a computer-readable program code. This propagated data signal may take a variety of forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the above. The computer-readable signal medium may also be any computer-readable medium other than a computer-readable medium that can send, propagate or transmit a program for use by or in conjunction with an instruction execution device, apparatus or device. The program code contained on the computer-readable medium may be transmitted using any appropriate medium, including but not limited to: wireless, wire, optical cable, RF, etc., or any suitable combination of the above.
[0098] Computer program code for performing operations of the present application may be written in one or more programming languages, or a combination thereof, including object-oriented programming languages such as Java, Smalltalk, C++, and conventional procedural programming languages such as "C" or similar programming languages. The program code may execute entirely on the user's computer, partially on the user's computer, as a stand-alone software package, partially on the user's computer and partially on a remote computer, or entirely on the remote computer or server.
[0099] In the case of a remote computer, the remote computer can be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or it can be connected to an external computer (e.g., through the Internet using an Internet service provider).
[0100] The flowcharts and block diagrams in the accompanying drawings illustrate the possible architecture, functions and operations of the devices, methods and computer program products according to various embodiments of the present application. In this regard, each box in the flowchart or block diagram can represent a module, a program segment or a part of a code, and the module, a program segment or a part of the code contains one or more executable instructions for realizing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the box can also occur in a different order from the order marked in the accompanying drawings. For example, two boxes represented in succession can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each box in the block diagram and / or flowchart and the combination of boxes in the block diagram and / or flowchart can be implemented with a dedicated hardware-based device that performs a specified function or operation, or can be implemented with a combination of dedicated hardware and computer instructions.
[0101] The modules involved in the embodiments described in this application may be implemented by software or hardware, and the modules described may also be set in a processor.
[0102] As another aspect, the present application further provides a computer-readable medium, which may be included in the electronic device described in the above embodiment; or may exist independently without being assembled into the electronic device.
[0103] The computer-readable medium carries one or more programs. When the one or more programs are executed by the electronic device, the electronic device: defines two objects, file system metadata and device; wherein the file system metadata is structural data used by the file system to manage file storage, and the device is a physical device to which the target file with fixed evidence is to be written; when writing the metadata cache, it is determined whether the metadata exists in all metadata cache blocks already existing in the file system metadata object. If so, the new metadata content is written into the matching metadata cache block; otherwise, a new metadata cache block is dynamically added to record the information of the target file; when writing the target file cache, the file content block is written into the partition and / or physical device corresponding to the device cache area according to the fixed device cache area size and the file content block size; after the target file cache is written, the device cache area with the cached file content block is written to the physical device; after the metadata cache is written, all metadata cache blocks are written to the physical device.
[0104] The above description is only a preferred embodiment of the present application and an explanation of the technical principles used. Those skilled in the art should understand that the scope of the invention involved in the present application is not limited to the technical solution formed by a specific combination of the above technical features, but should also cover other technical solutions formed by any combination of the above technical features or their equivalent features without departing from the above invention concept. For example, the above features are replaced with the technical features with similar functions disclosed in this application (but not limited to) by each other to form a technical solution.
Claims
1. A method for fixing evidence based on file system double cache, characterized in that: include: Define two objects: file system metadata and device; file system metadata is the structural data used by the file system to manage file storage, and device is the physical device where the target file fixed by the evidence is to be written; When writing to the metadata cache, determine whether the metadata exists in all metadata cache blocks of the file system metadata object. If so, write the new metadata content into the matching metadata cache block; otherwise, dynamically add a new metadata cache block to record the target file information. When writing to the target file cache, the file content block is written to the partition and / or physical device corresponding to the device cache area according to the fixed device cache area size and the size of the file content block; After the target file cache is written, the device cache area that caches the file content blocks is written to the physical device; after the metadata cache is written, all metadata cache blocks are written to the physical device.
2. The evidence fixing method based on file system double cache according to claim 1 is characterized in that: Data with a modification frequency greater than a preset value is attributed to the file system metadata object, and data with a modification frequency less than or equal to the preset value is attributed to the device object.
3. The evidence fixing method based on file system double cache according to claim 2 is characterized in that: When writing data cache that belongs to the file system metadata object but does not belong to the metadata, it is processed by dynamically adding cache blocks; when writing data cache that belongs to the device object but does not belong to the target file content, it is processed by fixing the device cache area.
4. The evidence fixing method based on file system double cache according to claim 1 is characterized in that: The metadata cache write process is as follows: S21, using the offset and length of the target file as keywords, determine whether the written metadata exists in all metadata cache blocks of the file system metadata object. If yes, go to S22; otherwise, go to S23. S22, writing the metadata content to be written into the matching metadata cache block; S23, apply for a new metadata cache block, write the metadata content to be written into the new metadata cache block, and record the offset, length and offset of the target file in the metadata cache.
5. The evidence fixing method based on file system double cache according to claim 1 is characterized in that: The target file cache write process is as follows: When writing to the target file cache, the current cache usage size of the device cache is recorded. When the current cache is full, it is written to the physical device in real time, and then jumps to the next cache in combination with the physical offset of the written file content block, and loops in sequence until the file content block is written or the written cache reaches the preset number.
6. The evidence fixing method based on file system double cache according to claim 5 is characterized in that: When writing to the target file cache, the current cache usage size of the device cache is recorded. When the current cache is full, it is written to the physical device in real time, and then jumps to the next cache in combination with the physical offset of the written file content block, and cycles in sequence until the file content block is written or the written cache reaches the preset number, as follows: S31, let the physical device offset corresponding to the starting position of the current buffer area be X, and write the first file content block at the starting position of the current buffer area; S32, determine the physical offset and length of the written file content block, if it is in the current buffer area, go to S33, if it is in the next buffer area, go to S34, if it is after two buffer areas, go to S35; S33, directly write the file content block into the corresponding position of the current buffer area, and go to S36; S34, dividing the file content block into two parts, filling the current buffer area with the first half, and writing the current buffer area into the physical device; The second half of the file content is written into the next buffer area, and the process goes to S36; S35, write the file content block directly into the physical device, and go to S36; S36, jump to the next file content block.
7. The evidence fixing method based on file system double cache according to claim 1 is characterized in that: Also includes: The reading and writing of the metadata cache is associated with the writing of the device cache and the reading of the device. When the metadata cache writing fails, the evidence can be solidified through the writing of the device cache, and when the metadata cache reading fails, the evidence can be obtained through the reading of the device.
8. An evidence fixing device based on file system double cache, characterized in that: include: The object partitioning module is used to define two objects: file system metadata and device; wherein the file system metadata is the structural data used by the file system to manage file storage, and the device is the physical device to which the target file fixed by the evidence is to be written; The metadata cache writing module is used to determine whether the metadata exists in all metadata cache blocks of the file system metadata object when writing the metadata cache. If so, write the new metadata content into the matching metadata cache block; otherwise, dynamically add a new metadata cache block to record the information of the target file; The target file cache writing module is used to write the file content block into the partition and / or physical device corresponding to the device cache area according to the fixed device cache area size and the size of the file content block when the target file cache is written; The evidence fixing module is used to write the device cache area with the file content blocks cached in it to the physical device after the target file cache is written; and to write all metadata cache blocks to the physical device after the metadata cache is written.
9. An electronic device, comprising: one or more processors; a storage device for storing one or more programs, When the one or more programs are executed by the one or more processors, the one or more processors implement the evidence fixing method based on file system double cache as described in any one of claims 1-7.
10. A computer-readable storage medium having a computer program code stored thereon, characterized in that: When the computer program code is executed by a computer, the evidence fixing method based on file system double cache described in any one of claims 1 to 7 is executed.
Citation Information
Patent Citations
Data access / storage method and device for cloud storage service system
CN106021381A
Data caching method based on high concurrency
CN113311994A
Metadata access method and device, electronic equipment and storage medium
CN117193639A
System and method for providing continuous data protection
US20070276878A1
Metadata access method and device, and storage medium
WO2024104073A1