Encryption protection method and system based on computer system software

By integrating multiple encryption-related modules in computer system software, providing comprehensive security guarantees, the existing encryption system lacks integrity and coordination is solved, and the performance and security of the system are significantly improved.

CN120012133AInactive Publication Date: 2025-05-16ZHENGZHOU POLYTECHNIC VOCATIONAL COLLEGE
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202510144146.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-10
Publication Date
2025-05-16
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

Existing encryption systems lack the integrity and coordination of the system and cannot effectively provide data confidentiality, integrity and availability, especially when facing the risks of complex cyber attacks and data breaches.

Method used

It provides encryption protection methods and systems based on computer system software, including user interaction interface, encryption policy configuration and management module, key generation and distribution module, data encryption and decryption engine, encryption algorithm library, encrypted data storage and management module, access control and audit module, hardware security support module and operating system interface, providing comprehensive security guarantees through the collaborative work of each module.

Benefits of technology

It realizes all-round security guarantees from encryption policy formulation to data encryption, storage, access control and auditing, improves the performance and security of the system, and effectively resists potential security threats.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120012133A_ABST
    Figure CN120012133A_ABST
Patent Text Reader

Abstract

The invention provides an encryption protection method and system based on computer system software, and relates to the field of computer system software encryption, and the method comprises the following steps: a user interaction interface interacts with an encryption strategy configuration and management module; the encryption strategy configuration and management module transmits strategy information to the key generation and distribution module and the data encryption and decryption engine; the key generation and distribution module interacts with the hardware security support module; the data encryption and decryption engine executes encryption and decryption operations by using an encryption algorithm; the data encryption and decryption engine transmits the encrypted data to the encrypted data storage and management module for storage; through cooperative work of all the modules, all-around security assurance from formulation of an encryption strategy to data encryption, storage, access control, auditing and the like can be provided; meanwhile, the system also introduces a hardware security support module, and solves the problem that the existing encryption system lacks system integrity and collaboration by using hardware acceleration and security storage functions.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of computer system software encryption, and in particular to an encryption protection method and system based on computer system software. Background Art

[0002] In the digital age, information security has become an important issue that cannot be ignored in all fields. With the rapid development of information technology and the sharp increase in data volume, how to ensure the confidentiality, integrity and availability of data has become an urgent problem to be solved. Although traditional encryption methods can provide data protection to a certain extent, their limitations are becoming increasingly prominent in the face of increasingly complex network attacks and data leakage risks.

[0003] Most existing encryption systems focus on a single encryption function and lack system integrity and synergy; for example, some systems only provide basic encryption and decryption functions, but ignore key links such as encryption policy configuration and management, key generation and distribution, data storage and management, and access control and auditing; in addition, many systems lack hardware-level security support and cannot fully utilize the advantages of hardware acceleration and secure storage, thus limiting the performance and security of the system. Summary of the invention

[0004] In view of this, the present invention provides an encryption protection method and system based on computer system software, which has a user interaction interface, an encryption policy configuration and management module, a key generation and distribution module, a data encryption and decryption engine, an encryption algorithm library, an encrypted data storage and management module, an access control and audit module, a hardware security support module and an operating system interface; through the collaborative work between the modules, the system can provide all-round security protection from the formulation of encryption policies to data encryption, storage, access control and auditing; at the same time, the system also introduces a hardware security support module, which uses hardware acceleration and secure storage functions to further improve the performance and security of the system.

[0005] The present invention provides an encryption protection method and system based on computer system software, which specifically includes: a user interaction interface, an encryption policy configuration and management module, a key generation and distribution module, a data encryption and decryption engine, an encryption algorithm library, an encrypted data storage and management module, an access control and audit module, a hardware security support module and an operating system interface; The user interaction interface is used as the interaction entrance between the user and the encryption system, and the user interaction interface interacts with the encryption policy configuration and management module to obtain encryption policy and user configuration; the encryption policy configuration and management module transmits policy information to the key generation and distribution module and the data encryption and decryption engine, and the key generation and distribution module interacts with the hardware security support module; the data encryption and decryption engine receives data requests from the user interaction interface and policy instructions from the encryption policy configuration and management module, and the data encryption and decryption engine obtains keys from the key generation and distribution module; the encryption algorithm library stores multiple encryption algorithms, and the data encryption and decryption engine uses the algorithms in the encryption algorithm library to perform encryption and decryption operations, and the data encryption and decryption engine transmits the encrypted data to the encryption data storage and management module for storage; The encrypted data storage and management module provides a data access interface for access control and audit module and other authorized entities to access, and the access control and audit module manages user access rights to data in the encrypted data storage and management module; the access control and audit module records all access and operation logs to encrypted data for auditing and monitoring, and the access control and audit module interacts with the user interaction interface to provide feedback on access control and audit results; the hardware security support module provides hardware-level encryption acceleration and secure storage functions, and the hardware security support module interacts with the key generation and distribution module and the data encryption and decryption engine to utilize hardware acceleration and secure storage; the operating system interface is integrated with the operating system to provide an encryption service interface.

[0006] In at least some embodiments, the encryption policy configuration and management module is provided with: an encryption algorithm confirmation module, an encryption strength confirmation module, an encryption status monitoring module and an encryption policy update and adjustment module; the encryption algorithm confirmation module is used to select and confirm the encryption algorithm, and the strength of the selected encryption algorithm is evaluated through the encryption strength confirmation module to ensure compliance with security requirements; the encryption status monitoring module monitors the operating status of the encryption system in real time, and the encryption policy is regularly updated and adjusted through the encryption policy update and adjustment module.

[0007] In at least some embodiments, the key generation and distribution module is provided with: a key generation module, a key update and destruction module, a key acquisition and distribution module and a key usage authorization module; the key generation module generates a high-strength encryption key, and regularly updates the encryption key through the key update and destruction module; the encryption key is securely distributed through the key acquisition and distribution module, and the key usage authorization module is used to authorize users and systems to use the encryption key for encryption and decryption operations.

[0008] In at least some embodiments, the encrypted data storage and management module is provided with: a data backup and recovery module and a performance optimization and extension module; data backup and recovery tasks are performed by using the data backup and recovery module, and system performance data is collected by using the performance optimization and extension module, and the performance optimization and extension module optimizes the application code and algorithm to improve execution efficiency and response speed; before performing data backup, the performance optimization and extension module is used to evaluate system performance to ensure that the backup operation does not cause excessive burden on the system; after data recovery, the performance optimization and extension module is used to verify system performance to ensure that the recovery operation does not introduce new performance problems.

[0009] In at least some embodiments, the access control and audit module is provided with: an access control module, a logging module, an intrusion detection module, a reporting and alarm module, and a data analysis and visualization module; the access control module authenticates and manages permissions of visitors to network resources to ensure that only authorized users and processes can access; the logging module is responsible for recording important events and access behaviors during the operation of the system; the intrusion detection module monitors the system in real time to detect potential security threats; the reporting and alarm module is responsible for sending alarms to administrators and providing detailed reports when the intrusion detection module detects a security incident; the data analysis and visualization module performs in-depth analysis of the data collected by the logging module and the intrusion detection module, and provides a visual report.

[0010] In at least some embodiments, the hardware security support module is provided with: an anti-tampering module and a programming language support module; the anti-tampering module provides tampering evidence and tampering resistance functions, the tampering evidence function leaves traces of tampering, and the tampering resistance function destroys the protected information when tampering occurs; the programming language support module can allow users to develop special programs in their programming language, thereby enhancing its flexibility and adaptability.

[0011] The present invention discloses an encryption protection method and system based on computer system software, comprising the following steps: 1. Users submit encryption and decryption requests through the user interaction interface, and the encryption policy configuration and management module processes user requests according to preset policies. The key generation and distribution module generates new key pairs and distributes keys as needed;

[0012] 2. The data encryption and decryption engine uses the algorithms and keys in the encryption algorithm library to perform encryption and decryption operations; the encrypted data is stored in the encrypted data storage and management module; the access control and audit module manages user access rights to encrypted data and records operation logs; the hardware security support module provides hardware-level encryption acceleration and secure storage; the operating system interface allows other applications and services to interact with the encryption system.

[0013] Beneficial Effects 1. The present invention, through the encryption policy configuration and management module with a built-in encryption algorithm confirmation module, can select the encryption algorithm that best suits the current security requirements to ensure data transmission and storage security; the encryption strength confirmation module evaluates the algorithm strength to ensure that the encryption level meets the established security standards and effectively resists potential security threats; the encryption status monitoring module monitors in real time to improve the system response speed and stability; the encryption policy update adjustment module ensures that the policy is flexibly adjusted with technological progress and changes in the security environment, maintains the long-term security and adaptability of the system, and effectively resists potential security threats.

[0014] 2. The present invention uses a key generation module to efficiently generate high-strength keys, provide security for data transmission and storage, and prevent unauthorized access and data leakage; the key update and destruction module ensures the timeliness and security of the key and avoids the risk of long-term use; the key acquisition and distribution module adopts a safe and reliable mechanism to protect the integrity and confidentiality of the key during transmission; the key use authorization module uses permission control to ensure that only authorized users and systems can use the key, strengthen access control, and improve key management efficiency and security.

[0015] 3. The present invention ensures reliable storage and rapid recovery of key data through the data backup and recovery module, reducing the risk of data loss and business interruption costs; the performance optimization and expansion module continuously monitors system performance, intelligently optimizes codes and algorithms, and improves the execution efficiency and response speed of encrypted data storage and management; during the data backup and recovery process, the module evaluates system performance to ensure that the backup does not interfere with normal business, verifies performance after recovery, ensures system stability and efficiency, and provides a smooth data processing experience.

[0016] 4. The present invention implements sophisticated access management through the access control module to prevent unauthorized access and data leakage; uses the log recording module to record important events, which is helpful for security auditing and troubleshooting; the intrusion detection module monitors in real time and discovers security threats in a timely manner; the reporting and alarm module sends alarms and detailed reports when a security incident is detected; the data analysis and visualization module provides intuitive visual reports to help administrators understand the system security status and performance, formulate accurate security strategies and optimization measures, and comprehensively improve system security.

[0017] 5. The present invention improves the security and credibility of the system through the anti-tampering module, the tampering evidence retention function provides evidence for auditing and accountability, and the tampering resistance function prevents the leakage of sensitive data; the programming language support module enhances the flexibility and adaptability of the system, and users can develop programs in familiar languages, reduce difficulty and improve efficiency, and adapt to complex application scenarios; this high flexibility enables the system to continue to evolve, synchronize with the latest technologies and business needs, and ensure the long-term security and efficient operation of the system. BRIEF DESCRIPTION OF THE DRAWINGS

[0018] In order to more clearly illustrate the technical solution of the embodiment of the present invention, the drawings of the embodiment are briefly introduced below.

[0019] The drawings described below are only related to some embodiments of the present invention, but are not intended to limit the present invention.

[0020] In the attached picture: Figure 1 It is a system block diagram of the present invention.

[0021] Figure 2 The present invention Figure 1 Block diagram of the encryption policy configuration and management module.

[0022] Figure 3 The present invention Figure 1 Block diagram of the key generation and distribution module.

[0023] Figure 4 The present invention Figure 1 Block diagram of the encrypted data storage and management module.

[0024] Figure 5 The present invention Figure 1 Block diagram of the access control and audit module in .

[0025] Figure 6 The present invention Figure 1 Block diagram of the hardware security support module in .

[0026] Reference numerals list 1. User interface; 2. Encryption policy configuration and management module; 201. Encryption algorithm confirmation module; 202. Encryption strength confirmation module; 203. Encryption status monitoring module; 204. Encryption policy update adjustment module; 3. Key generation and distribution module; 301. Key generation module; 302. Key update and destruction module; 303. Key acquisition and distribution module; 304. Key use authorization module; 4. Data encryption and decryption engine; 5. Encryption algorithm library; 6. Encrypted data storage and management module; 601. Data backup and recovery module; 602. Performance optimization and expansion module; 7. Access control and audit module; 701. Access control module; 702. Logging module; 703. Intrusion detection module; 704. Report and alarm module; 705. Data analysis and visualization module; 8. Hardware security support module; 801. Anti-tampering module; 802. Programming language support module; 9. Operating system interface. DETAILED DESCRIPTION

[0027] In order to make the purpose, scheme and advantages of the technical solution of the present invention clearer, the technical solution of the embodiment of the present invention will be clearly and completely described in conjunction with the drawings of the specific embodiments of the present invention. Unless otherwise specified, the terms used herein have the usual meanings in the art. The same reference numerals in the drawings represent the same components.

[0028] Example 1: Please refer to Figures 1 to 6 As shown: The present invention provides an encryption protection method and system based on computer system software, including a user interaction interface 1, an encryption policy configuration and management module 2, a key generation and distribution module 3, a data encryption and decryption engine 4, an encryption algorithm library 5, an encryption data storage and management module 6, an access control and audit module 7, a hardware security support module 8 and an operating system interface 9; the user interaction interface 1 is used as an interaction entrance between a user and an encryption system, and the user interaction interface 1 interacts with the encryption policy configuration and management module 2 to obtain encryption policies and user configurations; the encryption policy configuration and management module 2 transmits policy information to the key generation and distribution module 3 and the data encryption and decryption engine 4, and the key generation and distribution module 3 interacts with the hardware security support module 8; the data encryption and decryption engine 4 receives data requests from the user interaction interface 1 and policy instructions from the encryption policy configuration and management module 2, and the data encryption and decryption engine 4 obtains keys from the key generation and distribution module 3; the encryption algorithm library 5 stores a plurality of encryption algorithms, and the data encryption and decryption engine 4 uses the algorithms in the encryption algorithm library 5 to perform encryption and decryption operations, and the data encryption and decryption engine 4 transmits the encrypted data to the encryption data storage and management module 6 for storage; In the disclosed embodiment, the encrypted data storage and management module 6 provides a data access interface for access control and audit module 7 and other authorized entities to access, and the access control and audit module 7 manages the user's access rights to the data in the encrypted data storage and management module 6; the access control and audit module 7 records all access and operation logs to the encrypted data for auditing and monitoring, and the access control and audit module 7 interacts with the user interaction interface 1 to provide feedback on access control and audit results; the hardware security support module 8 provides hardware-level encryption acceleration and secure storage functions, and the hardware security support module 8 interacts with the key generation and distribution module 3 and the data encryption and decryption engine 4 to utilize hardware acceleration and secure storage; the operating system interface 9 is integrated with the operating system to provide an encryption service interface; its specific function is: through the collaborative work between the modules, the system can provide comprehensive security protection from the formulation of encryption strategies to data encryption, storage, access control and auditing.

[0029] Example 2: Please refer to Figures 2 to 5As shown: Based on the first embodiment, the encryption policy configuration and management module 2 is provided with: an encryption algorithm confirmation module 201, an encryption strength confirmation module 202, an encryption state monitoring module 203 and an encryption policy update adjustment module 204; the encryption algorithm confirmation module 201 is used to select and confirm the encryption algorithm, and the strength of the selected encryption algorithm is evaluated by the encryption strength confirmation module 202 to ensure that it meets the security requirements; the encryption state monitoring module 203 monitors the operating status of the encryption system in real time, and regularly updates and adjusts the encryption policy through the encryption policy update adjustment module 204; the key generation and distribution module 3 is provided with: a key generation module 301, a key update and destruction module 302, a key acquisition and distribution module 303 and a key use module 304; The key generation module 301 generates a high-strength encryption key, and the encryption key is regularly updated through the key update and destruction module 302; the encryption key is securely distributed through the key acquisition and distribution module 303, and the key use authorization module 304 is used to authorize users and systems to use the encryption key for encryption and decryption operations; the encrypted data storage and management module 6 is provided with: a data backup and recovery module 601 and a performance optimization and expansion module 602; by using the data backup and recovery module 601 to perform data backup and recovery tasks, and using the performance optimization and expansion module 602 to collect system performance data, and the performance optimization and expansion module 602 optimizes the code and algorithm of the application program to improve execution efficiency and Response speed; before performing data backup, use the performance optimization and expansion module 602 to evaluate system performance to ensure that the backup operation does not cause excessive burden on the system; after data recovery, use the performance optimization and expansion module 602 to verify system performance to ensure that the recovery operation does not introduce new performance problems; the access control and audit module 7 is equipped with: access control module 701, log recording module 702, intrusion detection module 703, report and alarm module 704 and data analysis and visualization module 705; the access control module 701 authenticates and manages the access rights of the visitors to the network resources to ensure that only authorized users and processes can access; the log recording module 702 is responsible for recording important events and access during the operation of the system. The intrusion detection module 703 monitors the system in real time to detect potential security threats. The reporting and alarming module 704 is responsible for sending alarms and providing detailed reports to the administrator when the intrusion detection module 703 detects a security incident. The data analysis and visualization module 705 conducts in-depth analysis of the data collected by the logging module 702 and the intrusion detection module 703 and provides a visual report. Its specific functions are: to achieve refined access management through the access control module 701; to use the logging module 702 to record important events, which is helpful for security auditing and troubleshooting; the intrusion detection module 703 monitors in real time and detects security threats in a timely manner; the reporting and alarming module 704 sends alarms and detailed reports when a security incident is detected.The data analysis and visualization module 705 provides intuitive visualization reports to help administrators understand the system security status and performance. ;

[0030] Example 3: Please refer to Figure 1 and Figure 6 As shown: on the basis of the first and second embodiments, the hardware security support module 8 is provided with: an anti-tampering module 801 and a programming language support module 802; the anti-tampering module 801 provides tampering evidence and tampering resistance functions, the tampering evidence function leaves traces of tampering, and the tampering resistance function destroys the protected information when tampering occurs; the programming language support module 802 can allow users to develop special programs in the programming language, thereby enhancing its flexibility and adaptability; its specific functions are: the anti-tampering module 801 improves the security and credibility of the system, the tampering evidence function provides evidence for auditing and accountability, and the tampering resistance function prevents sensitive data leakage; the programming language support module 802 enhances the flexibility and adaptability of the system.

[0031] The present invention discloses an encryption protection method and system based on computer system software, comprising the following steps: 1. The user submits encryption and decryption requests through the user interaction interface 1, and the encryption policy configuration and management module 2 processes the user request according to the preset policy, and the key generation and distribution module 3 generates new key pairs and distributes keys as needed;

[0032] 2. The data encryption and decryption engine 4 uses the algorithms and keys in the encryption algorithm library 5 to perform encryption and decryption operations; the encrypted data is stored in the encrypted data storage and management module 6; the access control and audit module 7 manages the user's access rights to the encrypted data and records the operation log; the hardware security support module 8 provides hardware-level encryption acceleration and secure storage; the operating system interface 9 allows other applications and services to interact with the encryption system.

[0033] Specific usage and function of this embodiment: In the present invention, first, the user starts the encryption system through the operating system interface 9; then the user enters the encryption policy configuration and management module 2 through the user interaction interface 1; in this module, the user uses the encryption algorithm confirmation module 201 to select and confirm the encryption algorithm, and the encryption strength confirmation module 202 ensures that the selected algorithm meets the security requirements; after the configuration is completed, the encryption policy information will be passed to the key generation and distribution module 3 and the data encryption and decryption engine 4; the key generation module 301 in the key generation and distribution module 3 generates a high-strength encryption key according to the encryption policy; through the key acquisition and distribution module 303, the encryption key is securely distributed to the required The key usage authorization module 304 ensures that only authorized entities can use these keys for encryption and decryption operations; the key update and destruction module 302 regularly updates the encryption keys and destroys old keys when necessary to ensure the continuous security of the system; the user submits a data encryption request through the user interaction interface 1; after receiving the request, the data encryption and decryption engine 4 obtains the corresponding key from the key generation and distribution module 3 and uses the algorithm in the encryption algorithm library 5 to perform the encryption operation; the encrypted data is passed to the encryption data storage and management module 6 for storage; this module provides a data access interface to ensure that only authorized entities can access these data. The access control module 701 in the access control and audit module 7 authenticates and manages the access rights of the network resources to ensure that only authorized users and processes can access the encrypted data; the logging module 702 records important events and access behaviors during the operation of the system; the intrusion detection module 703 monitors the system in real time to discover potential security threats; the reporting and alarm module 704 sends an alarm to the administrator when a security incident is detected and provides a detailed report; the data analysis and visualization module 705 performs in-depth analysis of the collected data and generates a visualization report for auditing and monitoring; the hardware security support module 8 provides hardware-level encryption acceleration and secure storage functions; anti-tampering The modification module 801 ensures the integrity and security of the data and can destroy the protected information even when tampering occurs; the programming language support module 802 allows users to develop special programs to enhance the flexibility and adaptability of the system; the data backup and recovery module 601 in the encrypted data storage and management module 6 performs data backup and recovery tasks to ensure data availability and disaster recovery capabilities; the performance optimization and expansion module 602 collects system performance data, optimizes the application code and algorithms, and improves execution efficiency and response speed; before and after data backup and recovery operations, this module is also responsible for evaluating system performance to ensure that the operation does not place too much burden on the system and introduce new performance problems.

Claims

1. An encryption system based on computer system software, characterized in that: include: User interaction interface (1), encryption policy configuration and management module (2), key generation and distribution module (3), data encryption and decryption engine (4), encryption algorithm library (5), encrypted data storage and management module (6), access control and audit module (7), hardware security support module (8) and operating system interface (9); The user interaction interface (1) is used as an interactive entry for a user and the encryption system, and the user interaction interface (1) interacts with the encryption policy configuration and management module (2) to obtain encryption policy and user configuration; the encryption policy configuration and management module (2) transmits policy information to the key generation and distribution module (3) and the data encryption and decryption engine (4), and the key generation and distribution module (3) interacts with the hardware security support module (8); the data encryption and decryption engine (4) receives a data request from the user interaction interface (1) and a policy instruction from the encryption policy configuration and management module (2), and the data encryption and decryption engine (4) obtains a key from the key generation and distribution module (3); the encryption algorithm library (5) stores a plurality of encryption algorithms, and the data encryption and decryption engine (4) uses the algorithms in the encryption algorithm library (5) to perform encryption and decryption operations, and the data encryption and decryption engine (4) transmits the encrypted data to the encryption data storage and management module (6) for storage; The encrypted data storage and management module (6) provides a data access interface for access by the access control and audit module (7) and other authorized entities, and the access control and audit module (7) manages the user's access rights to the data in the encrypted data storage and management module (6); the access control and audit module (7) records all access and operation logs to the encrypted data for auditing and monitoring, and the access control and audit module (7) interacts with the user interaction interface (1) to provide feedback on access control and audit results; The hardware security support module (8) provides hardware-level encryption acceleration and secure storage functions, and the hardware security support module (8) interacts with the key generation and distribution module (3) and the data encryption and decryption engine (4) to utilize hardware acceleration and secure storage; the operating system interface (9) is integrated with the operating system to provide an encryption service interface.

2. The computer system software-based encryption system according to claim 1, characterized in that: The encryption policy configuration and management module (2) is provided with: an encryption algorithm confirmation module (201), an encryption strength confirmation module (202), an encryption status monitoring module (203) and an encryption policy update adjustment module (204); the encryption algorithm confirmation module (201) is used to select and confirm the encryption algorithm, and the encryption strength confirmation module (202) is used to evaluate the strength of the selected encryption algorithm to ensure that it meets security requirements; the encryption status monitoring module (203) monitors the operating status of the encryption system in real time, and the encryption policy is regularly updated and adjusted through the encryption policy update adjustment module (204).

3. The encryption system based on computer system software according to claim 1, characterized in that: The key generation and distribution module (3) is provided with: a key generation module (301), a key update and destruction module (302), a key acquisition and distribution module (303) and a key use authorization module (304); the key generation module (301) generates a high-strength encryption key, and regularly updates the encryption key through the key update and destruction module (302); the encryption key is securely distributed through the key acquisition and distribution module (303), and the key use authorization module (304) is used to authorize users and systems to use the encryption key for encryption and decryption operations.

4. The computer system software-based encryption system according to claim 1, characterized in that: The encrypted data storage and management module (6) is provided with: a data backup and recovery module (601) and a performance optimization and extension module (602); the data backup and recovery tasks are performed by using the data backup and recovery module (601), and the system performance data is collected by using the performance optimization and extension module (602); the performance optimization and extension module (602) optimizes the code and algorithm of the application program to improve the execution efficiency and response speed; before performing data backup, the performance optimization and extension module (602) is used to evaluate the system performance to ensure that the backup operation does not cause excessive burden on the system; after data recovery, the performance optimization and extension module (602) is used to verify the system performance to ensure that the recovery operation does not introduce new performance problems.

5. The computer system software-based encryption system according to claim 1, characterized in that: The access control and audit module (7) is provided with: an access control module (701), a log recording module (702), an intrusion detection module (703), a report and alarm module (704) and a data analysis and visualization module (705); the access control module (701) performs identity authentication and permission management on visitors to network resources to ensure that only authorized users and processes can access; the log recording module (702) is responsible for recording important events and access behaviors during the operation of the system; the intrusion detection module (703) is responsible for real-time monitoring of the system to discover potential security threats; the report and alarm module (704) is responsible for sending an alarm to an administrator and providing a detailed report when the intrusion detection module (703) detects a security event; the data analysis and visualization module (705) performs in-depth analysis on the data collected by the log recording module (702) and the intrusion detection module (703) and provides a visualization report.

6. The computer system software-based encryption system according to claim 1, characterized in that: The hardware security support module (8) is provided with: an anti-tampering module (801) and a programming language support module (802); the anti-tampering module (801) provides tampering evidence retention and tampering resistance functions, the tampering evidence retention function leaves traces of tampering behavior, and the tampering resistance function destroys protected information when tampering occurs; The programming language support module (802) allows users to develop special programs using the programming language, thereby enhancing its flexibility and adaptability.

7. The encryption protection method and system based on computer system software according to any one of claims 1 to 6, characterized in that: The following steps are involved:

1. The user submits encryption and decryption requests through the user interaction interface (1), the encryption policy configuration and management module (2) processes the user request according to the preset policy, and the key generation and distribution module (3) generates new key pairs and distributes keys as needed;. 8.

2. The data encryption and decryption engine (4) uses the algorithms and keys in the encryption algorithm library (5) to perform encryption and decryption operations; the encrypted data is stored in the encryption data storage and management module (6); the access control and audit module (7) manages the user's access rights to the encrypted data and records the operation log; the hardware security support module (8) provides hardware-level encryption acceleration and secure storage; the operating system interface (9) allows other applications and services to interact with the encryption system.

Citation Information

Patent Citations

  • Cloud computing encryption storage service system and method

    CN117454420A

  • CT cloud and edge cloud security platform

    CN118432835A

  • Data encryption method and device, equipment and storage medium

    CN119272294A