Computer information security storage system
By designing a computer information security storage system, using dynamic desensitization strategies and hybrid encryption algorithms to process private information, and using optimistic concurrency control and graph structure-based rollback algorithms to perform conflict detection and rollback processing, the data loss or corruption caused by untimely rollback processing in the existing technology is solved, data consistency and integrity are achieved, and the reliability and stability of transaction processing are improved.
Patent Information
- Application Number
- CN202510056269.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-14
- Publication Date
- 2025-05-16
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
In the prior art, if the rollback process is not promptly or improperly processed, data may be lost or corrupted.
A computer information security storage system is designed, including a processing encryption module, an analysis and comparison module, a detection and processing module and a write storage module. Privacy information is processed through dynamic desensitization strategies and hybrid encryption algorithms, and conflict detection and rollback processing are performed using optimistic concurrency control and graph structure-based rollback algorithms to ensure data consistency and integrity.
It realizes the rollback mechanism that can be triggered in time when a conflict occurs, restores the data to the state before the conflict, avoids data corruption or loss caused by delayed rollback, and improves the reliability and stability of transaction processing.
Smart Images

Figure CN120012176A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of information security technology, and in particular to a computer information security storage system. Background Art
[0002] The significance of information security lies in protecting the security of information itself and the security of information storage carriers, namely information systems. Information security does not change fundamentally due to the form of carriers and information systems. It is a broader concept that includes the protection of all information and information systems, including data security. Information security is not only related to personal privacy, but also to national security, social stability and economic order. Data storage security has become the focus of attention for enterprises and individuals.
[0003] After searching, the invention patent with Chinese patent number CN118296591A discloses a privacy information security storage system in a computer network, which belongs to the field of information security technology. It includes a processing encryption module, an analysis and comparison module, a detection and processing module, and a write storage module. The detection and processing module performs concurrent write conflict detection and rollback processing according to the analysis of the buffer overflow risk in the analysis and comparison module. Compared with the prior art, the invention patent with Chinese patent number CN118296591A, the conflict detection unit analyzes the command that there is no buffer overflow risk in the analysis and comparison module, and when receiving the command that there is no buffer overflow risk, obtains the encrypted privacy information from the processing encryption module, and detects the concurrent write conflict of the encrypted privacy information, which can ensure that the data will not be erroneous or damaged when it is modified by multiple concurrent write operations at the same time, especially in the case of encrypted data involving sensitive information, ensuring the integrity of the data can avoid the risk of data leakage or tampering, and improve the protection of data integrity.
[0004] However, during the above use, if the rollback process is not timely or improperly handled, data may be lost or damaged. Therefore, a computer information security storage system is proposed. Summary of the invention
[0005] The purpose of the present invention is to solve the shortcomings of the prior art that if the rollback process is not timely or improperly processed, data may be lost or damaged, and to propose a computer information security storage system.
[0006] In order to achieve the above object, the present invention adopts the following technical solutions:
[0007] A computer information security storage system, comprising:
[0008] Processing encryption module: responsible for obtaining the storage space size of the text privacy information and the buffer, processing it using a dynamic desensitization strategy, encrypting the privacy information using a hybrid encryption algorithm, and calculating the size of the storage space for the privacy information. When the processing encryption module receives a command that indicates a buffer overflow risk in the analysis and comparison module, it calculates the size of the segmented blocks of the encrypted privacy information using an encryption segmentation method;
[0009] Analysis and comparison module: receiving the information size calculated in the encryption module, and analyzing and comparing it with the storage space size of the buffer, evaluating the risk of buffer overflow, and according to the comparison result, passing the command of the analysis of non-existence or existence of buffer overflow risk to the detection and processing module, receiving the segmentation block size calculated in the encryption module, and analyzing and comparing it with the storage space size of the buffer again, so that the segmented encrypted blocks can be stored;
[0010] The detection and processing module includes a conflict detection unit and a rollback processing unit. The conflict detection unit is responsible for receiving commands analyzed in the analysis and comparison module that do not have a buffer overflow risk, and using the optimistic concurrency control simulation method to detect concurrent write conflicts, record the time when the conflict occurs, the conflicting data items, the transaction ID involved, and the type of conflict. When a conflict is detected, the rollback processing unit triggers a rollback mechanism, uses a graph-based rollback algorithm to record the execution path and state changes of the transaction, uses a graph structure to represent the dependencies and state changes between data, performs a rollback operation, and restores the transaction to the state before the conflict. The conflict detection and rollback processing process is integrated into the distributed transaction management framework to achieve the atomicity, consistency, isolation, and durability (ACID) characteristics of transactions, ensuring that the rollback mechanism can be triggered in time and the consistency of the data can be restored when a conflict occurs.
[0011] Writing storage module: receiving the encrypted privacy information or encrypted block set processed in the detection processing module, and writing it into the buffer for secure storage.
[0012] The above technical solution further includes:
[0013] Furthermore, the specific steps of processing using the dynamic desensitization strategy are:
[0014] Information acquisition: Obtain the text privacy information to be processed, which usually includes sensitive data such as user personal information, transaction records, and communication content, and obtain the storage space size of the buffer to ensure that data is not lost or processing fails due to insufficient storage space during the desensitization process;
[0015] Sensitivity level assessment: Conduct a sensitivity level assessment on the acquired text privacy information, and classify the text privacy information into different sensitivity levels, such as highly sensitive, moderately sensitive, and low sensitive, based on the assessment results;
[0016] Dynamic desensitization strategy application: Desensitization strategies are dynamically selected based on the assessed sensitivity level and user access rights. For highly sensitive privacy information, highly desensitized strategies are adopted, including complete replacement (replacing sensitive information with specific symbols or placeholders) and hash processing (converting sensitive information into a hash value of fixed length); for less sensitive information, partial hiding (such as hiding some characters) and blurring (such as replacing sensitive characters with similar characters) are performed.
[0017] Desensitization: Apply the selected desensitization strategy to desensitize the text privacy information, ensuring that the desensitized information retains some features of the original information and effectively protects sensitive information from being leaked;
[0018] Storage space calculation and adjustment: During the desensitization process, the storage space occupied by the processed text privacy information is calculated. If the storage space is found to be insufficient, the buffer size is adjusted or other measures are taken to ensure the safe storage of data.
[0019] Furthermore, when the encryption processing module receives the command analyzed by the analysis and comparison module that there is a buffer overflow risk, the specific steps of calculating the size of the segmented blocks of the encrypted private information using the encryption segmentation method are as follows:
[0020] Risk analysis confirmation: Receive the output of the analysis and comparison module to confirm whether the encrypted privacy information has a buffer overflow risk. If there is a risk, enter the encryption segmentation calculation step; if there is no risk, process it in the conventional encryption method;
[0021] Evaluate the characteristics of encrypted private information: Evaluate the characteristics of encrypted private information, including the sensitivity, size, and format of the data. Measure the size of the private information to be encrypted by calculating the number of bytes or bits of the data.
[0022] Dynamically calculate the size of the segmented blocks: According to the risk analysis results and the characteristics of the encrypted privacy information, an encryption segmentation algorithm is designed. The encryption segmentation algorithm dynamically calculates the size of the segmented blocks, which is expressed as Block Size = f(Risk, Data Characteristics), where f is a function. The size of the segmented blocks is calculated based on the risk and data characteristics. The specific function form may need to be determined according to the actual situation, including but not limited to using weighted average, linear regression and other methods to integrate risk and characteristic information;
[0023] Block encryption: Use encryption algorithms to encrypt the divided data blocks, ensuring that the keys used in the encryption process are secure and the key management strategy is effective;
[0024] Merge and decryption: When data needs to be accessed, the encrypted data blocks are merged and decrypted to ensure the integrity and security of the data during the decryption process.
[0025] Furthermore, the analysis and comparison module receives the information size calculated in the processing encryption module, and analyzes and compares it with the storage space size of the buffer to assess the buffer overflow risk, including the following steps:
[0026] Received encrypted information size: The analysis and comparison module receives information size data from the encryption processing module. The data is usually expressed in bytes, indicating the size of the space occupied by the encrypted data.
[0027] Get buffer storage space: The analysis and comparison module obtains the storage space size of the target buffer;
[0028] Calculate overflow risk: After the encrypted information size and the buffer storage space size are known, the analysis and comparison module calculates the overflow risk. If the encrypted information size is less than or equal to the buffer storage space size, there is no overflow risk; if the encrypted information size is greater than the buffer storage space size, there is an overflow risk. The overflow risk is quantified by introducing a risk coefficient, which is expressed as When RC<0, it means there is no overflow risk, and when RC≥0, it means there is overflow risk, and the larger the RC value, the higher the risk;
[0029] Support for multiple buffer types: The analysis and comparison module handles different types of buffers, including fixed-size buffers and dynamically expanding buffers. For dynamically expanding buffers, its maximum expandable size and currently used size are considered;
[0030] Output results and alarms: Based on the calculation results, the analysis and comparison module should output the overflow risk assessment results. If overflow risk is detected, the alarm mechanism should be triggered to notify the relevant system or administrator to take corresponding measures.
[0031] Furthermore, the analysis and comparison module receives the segmentation block size calculated in the processing encryption module, and performs another analysis and comparison with the storage space size of the acquisition buffer, including the following steps:
[0032] Receiving the segmentation block size: the analysis and comparison module receives the segmentation block size data calculated by the encryption module;
[0033] Get buffer storage space: The analysis and comparison module obtains the storage space size of the target buffer;
[0034] Analyze and compare again: Step a: verify whether the segmentation block size complies with the preset segmentation strategy (such as segmentation by fixed size, segmentation by data volume ratio, etc.); Step b: compare the segmentation block size with the buffer storage space size. If the segmentation block size is less than or equal to the buffer storage space size, proceed to the next step. If the segmentation block size is larger than the buffer storage space size, trigger a warning or error handling mechanism, recalculate the segmentation block size or adjust the buffer size;
[0035] Calculate storage efficiency and risk: Calculate storage efficiency (SE) and risk coefficient (RC). The storage efficiency is expressed as When there is a segmentation block larger than the buffer size, the risk factor is expressed as Storage efficiency SE reflects the usage of buffer space. A higher SE value indicates better space utilization. Risk coefficient RC is used to quantify overflow risk. A larger RC value indicates a higher risk.
[0036] Configure segmentation strategy: According to the comparison results and the calculation of storage efficiency and risk factor, the analysis and comparison module configures the segmentation strategy. For example, if the buffer space is sufficient and the storage efficiency is low, you can choose to segment by fixed size to simplify storage management; if the data volume is large and the buffer space is limited, you can choose to segment by data volume ratio to optimize storage efficiency;
[0037] Storing encrypted blocks: After confirming that the size of the segmented blocks meets the storage space requirements of the buffer, the analysis and comparison module stores the segmented encrypted blocks in the buffer;
[0038] Recording and monitoring: After the storage operation is completed, the analysis and comparison module should record the relevant information of the storage operation (such as storage time, storage location, segmentation strategy, etc.) and monitor the operating status of the storage system. This will help with subsequent data management and troubleshooting.
[0039] Furthermore, the rollback processing unit triggers a rollback mechanism, uses a rollback algorithm based on a graph structure to record the execution path and state changes of the transaction, uses a graph structure to represent the dependency relationship and state changes between data, performs a rollback operation, and restores the transaction to a state before the conflict, including the following steps:
[0040] Transaction execution path and status record: During the transaction execution process, a graph structure is used to record the execution path of each transaction. Nodes represent operations or states in a transaction, and edges represent dependencies between operations. A unique identifier is assigned to each transaction, and each operation or state node is marked with its own identifier in the graph structure.
[0041] Dependency and state change representation: In the graph structure, the dependency between data is represented by edges. For example, if an operation of transaction A depends on a result of transaction B, a directed edge is established between the operation node of A and the result node of B to record the state changes before and after each operation. The state vector or state matrix is used to represent it. The state vector is an array containing the current values of all related data items, and the state matrix is a two-dimensional array used to represent the association and changes between data items.
[0042] Rollback operation: When a conflict is detected or a rollback is required, the affected operation or state node is found according to the graph structure. Starting from the current state, reverse traverse along the edges in the graph structure to find the state node before the conflict. According to the state vector or state matrix, restore the data item to the value before the conflict.
[0043] Furthermore, the conflict detection and rollback process is integrated into the distributed transaction management framework, including the following steps:
[0044] Transaction management framework design: Design a distributed transaction management framework that supports transaction creation, commit, and rollback operations. The framework includes the roles of transaction coordinator and transaction participant.
[0045] Integration of conflict detection mechanism: Optimistic concurrency control is used to detect conflicts during transaction execution;
[0046] Rollback processing flow integration: After a conflict is detected, the rollback mechanism is triggered to undo all operations performed in the transaction and restore the data to the state before the transaction started. The framework maintains transaction log information and performs undo operations during rollback.
[0047] Furthermore, the writing storage module writes the processed encrypted privacy information or the encrypted block set into the buffer for secure storage, including the following steps:
[0048] Select a buffer: determine a safe and reliable buffer to store the encrypted data or encrypted block set. The buffer can be a part of the memory or a specific area on the disk.
[0049] Perform a write operation: write the encrypted data or encrypted block set into the buffer. During the writing process, the integrity and accuracy of the data should be ensured to avoid data loss or damage. The buffer is set to B, and the formula is expressed as B=B∪{C1,C2,...,Cn}, where B represents the buffer, and C1,C2,...,Cn represent multiple encrypted data blocks or encrypted block sets;
[0050] Data storage: Write the data in the buffer to a long-term storage device. The data persistence and accessibility should be ensured during the storage process.
[0051] Data verification: After writing, the data is verified to ensure its integrity and accuracy. The verification process can include checking the hash value of the data, comparing the length of the data, or performing other forms of verification.
[0052] The present invention has the following beneficial effects:
[0053] In the present invention, the rollback processing unit triggers the rollback mechanism, and adopts a rollback algorithm based on a graph structure to record the execution path and state changes of the transaction. The graph structure is used to represent the dependencies and state changes between data, so that when a conflict or error occurs, it can quickly and accurately roll back to the state before the transaction starts, avoiding data damage or loss caused by delayed rollback. Integrating the conflict detection and rollback processing flow into the distributed transaction management framework realizes the atomicity, consistency, isolation and durability (ACID) characteristics of the transaction, and improves the reliability and stability of transaction processing. BRIEF DESCRIPTION OF THE DRAWINGS
[0054] Figure 1 This is a system block diagram of a computer information security storage system proposed by the present invention. DETAILED DESCRIPTION
[0055] The following will be combined with the drawings in the embodiments of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.
[0056] See also Figure 1 As shown, the present invention is a computer information security storage system, comprising:
[0057] Processing encryption module: responsible for obtaining the storage space size of the text privacy information and the buffer, processing it using a dynamic desensitization strategy, encrypting the privacy information using a hybrid encryption algorithm, and calculating the size of the storage space for the privacy information. When the processing encryption module receives a command that indicates a buffer overflow risk in the analysis and comparison module, it calculates the size of the segmented blocks of the encrypted privacy information using an encryption segmentation method;
[0058] Analysis and comparison module: receiving the information size calculated in the encryption module, and analyzing and comparing it with the storage space size of the buffer, evaluating the risk of buffer overflow, and according to the comparison result, passing the command of the analysis of non-existence or existence of buffer overflow risk to the detection and processing module, receiving the segmentation block size calculated in the encryption module, and analyzing and comparing it with the storage space size of the buffer again, so that the segmented encrypted blocks can be stored;
[0059] The detection and processing module includes a conflict detection unit and a rollback processing unit. The conflict detection unit is responsible for receiving commands analyzed in the analysis and comparison module that do not have a buffer overflow risk, and using the optimistic concurrency control simulation method to detect concurrent write conflicts, record the time when the conflict occurs, the conflicting data items, the transaction ID involved, and the type of conflict. When a conflict is detected, the rollback processing unit triggers a rollback mechanism, uses a graph-based rollback algorithm to record the execution path and state changes of the transaction, uses a graph structure to represent the dependencies and state changes between data, performs a rollback operation, and restores the transaction to the state before the conflict. The conflict detection and rollback processing process is integrated into the distributed transaction management framework to achieve the atomicity, consistency, isolation, and durability (ACID) characteristics of transactions, ensuring that the rollback mechanism can be triggered in time and the consistency of the data can be restored when a conflict occurs.
[0060] Writing storage module: receiving the encrypted privacy information or encrypted block set processed in the detection processing module, and writing it into the buffer for secure storage.
[0061] In one embodiment, for the above-mentioned processing using the dynamic desensitization strategy, the specific steps of the processing using the dynamic desensitization strategy are:
[0062] Information acquisition: Obtain the text privacy information to be processed, which usually includes sensitive data such as user personal information, transaction records, and communication content, and obtain the storage space size of the buffer to ensure that data is not lost or processing fails due to insufficient storage space during the desensitization process;
[0063] Sensitivity level assessment: Conduct a sensitivity level assessment on the acquired text privacy information, and classify the text privacy information into different sensitivity levels, such as highly sensitive, moderately sensitive, and low sensitive, based on the assessment results;
[0064] Dynamic desensitization strategy application: Desensitization strategies are dynamically selected based on the assessed sensitivity level and user access rights. For highly sensitive privacy information, highly desensitized strategies are adopted, including complete replacement (replacing sensitive information with specific symbols or placeholders) and hash processing (converting sensitive information into a hash value of fixed length); for less sensitive information, partial hiding (such as hiding some characters) and blurring (such as replacing sensitive characters with similar characters) are performed.
[0065] Desensitization: Apply the selected desensitization strategy to desensitize the text privacy information, ensuring that the desensitized information retains some features of the original information and effectively protects sensitive information from being leaked;
[0066] Storage space calculation and adjustment: During the desensitization process, the storage space occupied by the processed text privacy information is calculated. If the storage space is found to be insufficient, the buffer size is adjusted or other measures are taken to ensure the safe storage of data.
[0067] In one embodiment, for the above-mentioned encryption processing module, when the encryption processing module receives the command analyzed by the analysis and comparison module that there is a buffer overflow risk, the specific steps of calculating the size of the segmented blocks of the encrypted private information using the encryption segmentation method are as follows:
[0068] Risk analysis confirmation: Receive the output of the analysis and comparison module to confirm whether the encrypted privacy information has a buffer overflow risk. If there is a risk, enter the encryption segmentation calculation step; if there is no risk, process it in the conventional encryption method;
[0069] Evaluate the characteristics of encrypted private information: Evaluate the characteristics of encrypted private information, including the sensitivity, size, and format of the data. Measure the size of the private information to be encrypted by calculating the number of bytes or bits of the data.
[0070] Dynamically calculate the size of the segmented blocks: According to the risk analysis results and the characteristics of the encrypted privacy information, an encryption segmentation algorithm is designed. The encryption segmentation algorithm dynamically calculates the size of the segmented blocks, which is expressed as Block Size = f(Risk, DataCharacteristics), where f is a function. The size of the segmented blocks is calculated according to the risk and data characteristics. The specific function form may need to be determined according to the actual situation, including but not limited to using weighted average, linear regression and other methods to integrate risk and characteristic information;
[0071] Block encryption: Use encryption algorithms to encrypt the divided data blocks, ensuring that the keys used in the encryption process are secure and the key management strategy is effective;
[0072] Merge and decryption: When data needs to be accessed, the encrypted data blocks are merged and decrypted to ensure the integrity and security of the data during the decryption process.
[0073] In one embodiment, for the above-mentioned analysis and comparison module, the analysis and comparison module receives the information size calculated in the processing encryption module, and analyzes and compares it with the storage space size of the buffer to evaluate the buffer overflow risk, including the following steps:
[0074] Received encrypted information size: The analysis and comparison module receives information size data from the encryption processing module. The data is usually expressed in bytes, indicating the size of the space occupied by the encrypted data.
[0075] Get buffer storage space: The analysis and comparison module obtains the storage space size of the target buffer;
[0076] Calculate overflow risk: After the encrypted information size and the buffer storage space size are known, the analysis and comparison module calculates the overflow risk. If the encrypted information size is less than or equal to the buffer storage space size, there is no overflow risk; if the encrypted information size is greater than the buffer storage space size, there is an overflow risk. The overflow risk is quantified by introducing a risk coefficient, which is expressed as When RC<0, it means there is no overflow risk, and when RC≥0, it means there is overflow risk, and the larger the RC value, the higher the risk;
[0077] Support for multiple buffer types: The analysis and comparison module handles different types of buffers, including fixed-size buffers and dynamically expanding buffers. For dynamically expanding buffers, its maximum expandable size and currently used size are considered;
[0078] Output results and alarms: Based on the calculation results, the analysis and comparison module should output the overflow risk assessment results. If overflow risk is detected, the alarm mechanism should be triggered to notify the relevant system or administrator to take corresponding measures.
[0079] Assume that the information size of the output of a processing encryption module is 1024 bytes, and the target buffer is a fixed-size buffer of 512 bytes.
[0080] Step 1: Receive encrypted message size = 1024 bytes.
[0081] Step 2: Get buffer storage space = 512 bytes.
[0082] Step 3: Calculate the spillover risk:
[0083] The size of the encrypted information is greater than the size of the buffer storage space, so there is an overflow risk.
[0084] The risk factor RC = (1024 - 512) / 512 = 1 (indicating that the overflow risk is very high because the message size is twice the buffer size).
[0085] Step 4: Since this is a fixed-size buffer, there is no need to consider its dynamic expansion.
[0086] Step 5: Output the overflow risk assessment results and trigger the alarm mechanism.
[0087] In one embodiment, for the above-mentioned analysis and comparison module, the analysis and comparison module receives the segmentation block size calculated in the encryption module and performs another analysis and comparison with the storage space size of the acquisition buffer, including the following steps:
[0088] Receiving the segmentation block size: the analysis and comparison module receives the segmentation block size data calculated by the encryption module;
[0089] Get buffer storage space: The analysis and comparison module obtains the storage space size of the target buffer;
[0090] Analyze and compare again: Step a: verify whether the segmentation block size complies with the preset segmentation strategy (such as segmentation by fixed size, segmentation by data volume ratio, etc.); Step b: compare the segmentation block size with the buffer storage space size. If the segmentation block size is less than or equal to the buffer storage space size, proceed to the next step. If the segmentation block size is larger than the buffer storage space size, trigger a warning or error handling mechanism, recalculate the segmentation block size or adjust the buffer size;
[0091] Calculate storage efficiency and risk: Calculate storage efficiency (SE) and risk coefficient (RC). The storage efficiency is expressed as When there is a segmentation block larger than the buffer size, the risk factor is expressed as Storage efficiency SE reflects the usage of buffer space. A higher SE value indicates better space utilization. Risk coefficient RC is used to quantify overflow risk. A larger RC value indicates a higher risk.
[0092] Configure segmentation strategy: According to the comparison results and the calculation of storage efficiency and risk factor, the analysis and comparison module configures the segmentation strategy. For example, if the buffer space is sufficient and the storage efficiency is low, you can choose to segment by fixed size to simplify storage management; if the data volume is large and the buffer space is limited, you can choose to segment by data volume ratio to optimize storage efficiency;
[0093] Storing encrypted blocks: After confirming that the size of the segmented blocks meets the storage space requirements of the buffer, the analysis and comparison module stores the segmented encrypted blocks in the buffer;
[0094] Recording and monitoring: After the storage operation is completed, the analysis and comparison module should record the relevant information of the storage operation (such as storage time, storage location, segmentation strategy, etc.) and monitor the operating status of the storage system. This will help with subsequent data management and troubleshooting.
[0095] Assume that the size of the segmented block output by an encryption module is 256 bytes, and the target buffer is a dynamically expanding buffer with a current storage space of 512 bytes and a maximum expandable space of 1024 bytes.
[0096] Step 1: Receive segment block size = 256 bytes.
[0097] Step 2: Get buffer storage space = 512 bytes (currently), which can be expanded to a maximum of 1024 bytes.
[0098] Step 3: Analyze and compare again:
[0099] The segmentation block size (256 bytes) is smaller than the current storage space of the buffer (512 bytes), which meets the storage requirements.
[0100] Step 4: Calculate storage efficiency and risk:
[0101] Storage efficiency SE=256 / 512=0.5 (indicating that half of the space in the current buffer is used).
[0102] Since there are no split blocks larger than the buffer size, the risk factor RC does not apply.
[0103] Step 5: Flexibly configure segmentation strategy:
[0104] In this case, there is no need to adjust the split strategy because the split block size already meets the storage requirements.
[0105] Step 6: Storing the encrypted blocks:
[0106] Store the split encrypted blocks (256 bytes) into a buffer.
[0107] Step 7: Recording and Monitoring:
[0108] Records information about storage operations and monitors the operating status of the storage system.
[0109] In one embodiment, for the rollback processing unit, the rollback processing unit triggers a rollback mechanism, uses a graph-based rollback algorithm to record the execution path and state changes of the transaction, uses a graph structure to represent the dependency relationship and state changes between data, performs a rollback operation, and restores the transaction to a state before the conflict, including the following steps:
[0110] Transaction execution path and status record: During the transaction execution process, a graph structure is used to record the execution path of each transaction. Nodes represent operations or states in a transaction, and edges represent dependencies between operations. A unique identifier is assigned to each transaction, and each operation or state node is marked with its own identifier in the graph structure.
[0111] Dependency and state change representation: In the graph structure, the dependency between data is represented by edges. For example, if an operation of transaction A depends on a result of transaction B, a directed edge is established between the operation node of A and the result node of B to record the state changes before and after each operation. The state vector or state matrix is used to represent it. The state vector is an array containing the current values of all related data items, and the state matrix is a two-dimensional array used to represent the association and changes between data items.
[0112] Rollback operation: When a conflict is detected or a rollback is required, the affected operation or state node is found according to the graph structure. Starting from the current state, reverse traverse along the edges in the graph structure to find the state node before the conflict. According to the state vector or state matrix, restore the data item to the value before the conflict.
[0113] Suppose there are two transactions T1 and T2, which operate on data items X and Y respectively. Transaction T1 first updates the value of X from 1 to 2, and then transaction T2 attempts to update the value of X to 3. If a conflict between T1 and T2 is detected at this time (because they both try to modify the value of X), the system triggers a rollback mechanism.
[0114] During the rollback process, the system will find T2's update operation on X and traverse the graph structure backward to the state before T1 updated X. Then, the system will restore the value of X to 1 based on the state vector (i.e., S_new = 1 = S_old (before T1 update) - ΔS (T2 update)).
[0115] In one embodiment, for integrating the conflict detection and rollback process into the distributed transaction management framework, integrating the conflict detection and rollback process into the distributed transaction management framework includes the following steps:
[0116] Transaction management framework design: Design a distributed transaction management framework that supports transaction creation, commit, and rollback operations. The framework includes the roles of transaction coordinator and transaction participant.
[0117] Integration of conflict detection mechanism: Optimistic concurrency control is used to detect conflicts during transaction execution;
[0118] Rollback processing flow integration: After a conflict is detected, the rollback mechanism is triggered to undo all operations performed in the transaction and restore the data to the state before the transaction started. The framework maintains transaction log information and performs undo operations during rollback.
[0119] Suppose there are two transactions T1 and T2, which attempt to update the same data item. If T1 executes first and successfully updates the data item, and T2 detects a conflict with T1 when it commits, T2 should trigger a rollback mechanism to undo its update operation and restore the data item to the state before T1 updated it.
[0120] In one embodiment, for the above-mentioned writing storage module, the writing storage module writes the processed encrypted privacy information or the encrypted block set into the buffer for secure storage, including the following steps:
[0121] Select a buffer: determine a safe and reliable buffer to store the encrypted data or encrypted block set. The buffer can be a part of the memory or a specific area on the disk.
[0122] Perform a write operation: write the encrypted data or encrypted block set into the buffer. During the writing process, the integrity and accuracy of the data should be ensured to avoid data loss or damage. The buffer is set to B, and the formula is expressed as B=B∪{C1,C2,...,Cn}, where B represents the buffer, and C1,C2,...,Cn represent multiple encrypted data blocks or encrypted block sets;
[0123] Data storage: Write the data in the buffer to a long-term storage device. The data persistence and accessibility should be ensured during the storage process.
[0124] Data verification: After writing, the data is verified to ensure its integrity and accuracy. The verification process can include checking the hash value of the data, comparing the length of the data, or performing other forms of verification.
[0125] Although embodiments of the present invention have been shown and described, it will be appreciated by those skilled in the art that various changes, modifications, substitutions and variations may be made to the embodiments without departing from the principles and spirit of the present invention, and that the scope of the present invention is defined by the appended claims and their equivalents.
Claims
1. A computer information security storage system, characterized in that: include: Processing encryption module: responsible for obtaining the storage space size of the text privacy information and the buffer, processing it using a dynamic desensitization strategy, encrypting the privacy information using a hybrid encryption algorithm, and calculating the size of the storage space for the privacy information. When the processing encryption module receives a command that indicates a buffer overflow risk in the analysis and comparison module, it calculates the size of the segmented blocks of the encrypted privacy information using an encryption segmentation method; Analysis and comparison module: receiving the information size calculated in the encryption module, and analyzing and comparing it with the storage space size of the buffer, evaluating the risk of buffer overflow, and according to the comparison result, passing the command of the analysis of the absence or presence of buffer overflow risk to the detection processing module, the analysis and comparison module receives the segmentation block size calculated in the encryption module, and analyzes and compares it again with the storage space size of the buffer, so that the segmented encrypted blocks can be stored; The detection and processing module includes a conflict detection unit and a rollback processing unit. The conflict detection unit is responsible for receiving commands analyzed by the analysis and comparison module that do not have buffer overflow risks, and using the optimistic concurrency control simulation method to detect concurrent write conflicts, record the time when the conflict occurs, the conflicting data items, the transaction ID involved, and the type of conflict. When a conflict is detected, the rollback processing unit triggers a rollback mechanism, uses a graph-based rollback algorithm to record the execution path and state changes of the transaction, uses a graph structure to represent the dependencies and state changes between data, performs a rollback operation, restores the transaction to the state before the conflict, and integrates the conflict detection and rollback processing process into the distributed transaction management framework to achieve the atomicity, consistency, isolation, and persistence characteristics of the transaction. Writing storage module: receiving the encrypted privacy information or encrypted block set processed in the detection processing module, and writing it into the buffer for secure storage.
2. A computer information security storage system according to claim 1, characterized in that: The specific steps of processing using the dynamic desensitization strategy are: Information acquisition: obtain the text privacy information to be processed and the storage space size of the buffer; Sensitivity level assessment: Conduct sensitivity level assessment on the acquired text privacy information, and classify the text privacy information into different sensitivity levels based on the assessment results; Dynamic desensitization strategy application: Desensitization strategies are dynamically selected based on the assessed sensitivity level and user access rights. For highly sensitive privacy information, highly desensitized strategies are adopted, including complete replacement and hash processing; for less sensitive information, partial hiding and obfuscation are performed; Desensitization: Apply the selected desensitization strategy to desensitize the text privacy information; Storage space calculation and adjustment: During the desensitization process, the storage space occupied by the processed text privacy information is calculated. If the storage space is insufficient, the buffer size is adjusted.
3. A computer information security storage system according to claim 1, characterized in that: The specific steps of calculating the size of the segmented blocks of the encrypted private information by using the encryption segmentation method when the encryption processing module receives the command that the analysis and comparison module analyzes that there is a buffer overflow risk are as follows: Risk analysis confirmation: Receive the output of the analysis and comparison module to confirm whether the encrypted privacy information has a buffer overflow risk. If there is a risk, enter the encryption segmentation calculation step; if there is no risk, process it in the conventional encryption method; Evaluate the characteristics of encrypted privacy information: Evaluate the characteristics of encrypted privacy information; Dynamically calculate the segmentation block size: According to the risk analysis results and the characteristics of the encrypted privacy information, an encryption segmentation algorithm is designed. The encryption segmentation algorithm dynamically calculates the segmentation block size, which is expressed as Block Size = f (Risk, Data Characteristics), where f is a function that calculates the segmentation block size according to the risk and data characteristics; Block encryption: Use encryption algorithm to encrypt the divided data blocks; Merge and decryption: When data needs to be accessed, the encrypted data blocks are merged and decrypted.
4. A computer information security storage system according to claim 1, characterized in that: The analysis and comparison module receives the information size calculated in the processing encryption module, and analyzes and compares it with the storage space size of the buffer to assess the buffer overflow risk, including the following steps: Receiving encrypted information size: the analysis and comparison module receives information size data from the encryption processing module; Get buffer storage space: The analysis and comparison module obtains the storage space size of the target buffer; Calculate overflow risk: After the encrypted information size and the buffer storage space size are known, the analysis and comparison module calculates the overflow risk. If the encrypted information size is less than or equal to the buffer storage space size, there is no overflow risk; if the encrypted information size is greater than the buffer storage space size, there is an overflow risk. The overflow risk is quantified by introducing a risk coefficient, which is expressed as When RC<0, it means there is no overflow risk, and when RC≥0, it means there is overflow risk, and the larger the RC value, the higher the risk; Support for multiple buffer types: The analysis and comparison module handles different types of buffers, including fixed-size buffers and dynamically expanding buffers. For dynamically expanding buffers, its maximum expandable size and currently used size are considered; Output results and alarms: Based on the calculation results, the analysis and comparison module should output the overflow risk assessment results.
5. A computer information security storage system according to claim 4, characterized in that: The analysis and comparison module receives the segmentation block size calculated in the encryption module and performs another analysis and comparison with the storage space size of the acquisition buffer, including the following steps: Receiving the segmentation block size: the analysis and comparison module receives the segmentation block size data calculated by the encryption module; Get buffer storage space: The analysis and comparison module obtains the storage space size of the target buffer; Analyze and compare again: Step a: verify whether the segmentation block size complies with the preset segmentation strategy; Step b: compare the segmentation block size with the buffer storage space size. If the segmentation block size is less than or equal to the buffer storage space size, proceed to the next step. If the segmentation block size is greater than the buffer storage space size, trigger a warning or error handling mechanism, recalculate the segmentation block size or adjust the buffer size; Calculate storage efficiency and risk: Calculate storage efficiency and risk factor. The storage efficiency is expressed as When there is a segmentation block larger than the buffer size, the risk factor is expressed as Storage efficiency SE reflects the usage of buffer space. A higher SE value indicates better space utilization. Risk coefficient RC is used to quantify overflow risk. A larger RC value indicates a higher risk. Configure segmentation strategy: According to the comparison results and calculation of storage efficiency and risk factor, analyze the comparison module and configure the segmentation strategy; Storing encrypted blocks: After confirming that the size of the segmented blocks meets the storage space requirements of the buffer, the analysis and comparison module stores the segmented encrypted blocks in the buffer.
6. A computer information security storage system according to claim 1, characterized in that: The rollback processing unit triggers the rollback mechanism, uses a rollback algorithm based on a graph structure to record the execution path and state changes of the transaction, uses a graph structure to represent the dependency relationship and state changes between data, performs a rollback operation, and restores the transaction to the state before the conflict, including the following steps: Transaction execution path and status record: During the transaction execution process, a graph structure is used to record the execution path of each transaction. Nodes represent operations or states in a transaction, and edges represent dependencies between operations. A unique identifier is assigned to each transaction, and each operation or state node is marked with its own identifier in the graph structure. Dependency and state change representation: In the graph structure, the dependency between data is represented by edges, and the state changes before and after each operation are recorded. The state vector or state matrix is used to represent it. The state vector is an array containing the current values of all related data items, and the state matrix is a two-dimensional array used to represent the association and changes between data items. Rollback operation: When a conflict is detected or a rollback is required, the affected operation or state node is found according to the graph structure. Starting from the current state, reverse traverse along the edges in the graph structure to find the state node before the conflict. According to the state vector or state matrix, restore the data item to the value before the conflict.
7. A computer information security storage system according to claim 1, characterized in that: Integrating the conflict detection and rollback process into the distributed transaction management framework includes the following steps: Transaction management framework design: Design a distributed transaction management framework that supports transaction creation, commit, and rollback operations. The framework includes the roles of transaction coordinator and transaction participant. Integration of conflict detection mechanism: Optimistic concurrency control is used to detect conflicts during transaction execution; Rollback processing flow integration: After a conflict is detected, the rollback mechanism is triggered to undo all operations performed in the transaction and restore the data to the state before the transaction started. The framework maintains transaction log information and performs undo operations during rollback.
8. A computer information security storage system according to claim 7, characterized in that: The writing storage module writes the processed encrypted privacy information or the encrypted block set into the buffer for secure storage, including the following steps: Select Buffer: Determine a buffer to store the encrypted data or a set of encrypted blocks; Perform a write operation: write the encrypted data or encrypted block set into a buffer, set the buffer to B, and the formula is expressed as B=B∪{C1,C2,...,Cn}, where B represents the buffer, and C1,C2,...,Cn represent multiple encrypted data blocks or encrypted block sets; Data storage: write the data in the buffer to a long-term storage device; Data verification: After writing is completed, the data is verified.
Citation Information
Patent Citations
Private information security storage system in computer network
CN118296591A