Computer distributed storage encryption system
By using a combination technology of quantum key entanglement engine, dynamic topology perception module, space-time folding encryption module and implicit disaster recovery channel in distributed storage systems, the problems of rigid key management, sharding redundancy and security contradictions in the existing technology are solved, and high security, high reliability and dynamic adaptability are achieved.
Patent Information
- Application Number
- CN202510180110.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-18
- Publication Date
- 2025-05-16
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
The existing distributed storage encryption technology has problems such as rigid key management, conflicts between sharding redundancy and security, insufficient environmental perception capabilities, and inability to effectively deal with quantum computing threats and side channel attacks, resulting in high-value data facing the risk of leakage.
The quantum key entanglement engine is used to perform key segmentation and geographical binding, combined with the dynamic topology perception module to monitor the node status in real time, and the space-time folding encryption module is used to generate differential ciphertexts through chaotic fractal cutting and PUF noise injection technology, and the hidden data transmission against quantum computing is realized through implicit disaster recovery channels.
It realizes high security, high reliability and dynamic adaptability, ensuring that a single node leak cannot reconstruct the complete key, quickly respond to side channel attacks, cracking the global data threatened by a single node, and ensuring the ability to resist quantum computing attacks through hidden channels.
Smart Images

Figure CN120017383A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of computer storage, and in particular to a computer distributed storage encryption system. Background Art
[0002] With the widespread application of distributed storage systems in cloud computing, edge computing and other fields, the contradiction between data security and storage efficiency has become increasingly prominent. Traditional distributed storage encryption technologies mostly use centralized key management or static sharding encryption strategies, which have problems such as rigid key management, sharding redundancy and security conflicts, and insufficient environmental perception capabilities.
[0003] In the prior art, although some studies have attempted to improve security by combining homomorphic encryption or attribute-based encryption (ABE), they are still limited by excessive computational overhead or complicated policy management. In addition, the existing system fails to effectively deal with quantum computing threats and side-channel attacks, resulting in the risk of leakage of high-value data. Therefore, there is an urgent need for a computer distributed storage encryption system with high security, high reliability and the ability to dynamically adapt to changes in the storage environment to solve the defects in the prior art. For this purpose, a computer distributed storage encryption system is proposed. Summary of the invention
[0004] In view of the deficiencies of the prior art, the present invention provides a computer distributed storage encryption system to solve the background technical problems.
[0005] To achieve the above-mentioned purpose, the present invention provides the following technical solutions: a computer distributed storage encryption system, comprising a quantum key entanglement engine, a dynamic topology perception module, a space-time folding encryption module and an implicit disaster recovery channel;
[0006] Quantum key entanglement engine: The quantum key distribution (QKD) device deployed at the edge node generates entangled photon pairs, which divides the key into geographically bound quantum segments. If any geographical segment is leaked alone, the complete key cannot be reconstructed.
[0007] Dynamic topology perception module: collects the physical characteristics of storage nodes in real time, builds a dynamic security scoring matrix, and automatically triggers the migration of key segments to nodes with higher credibility when the node security score is lower than the threshold;
[0008] Time-space folding encryption module: Using the NTRU lattice cryptographic algorithm, a physical unclonable function (PUF) noise bound to the hardware fingerprint of the storage node is injected during data sharding, so that the same data block generates different ciphertexts after encryption at different nodes, and can only be decrypted when the original node cluster is online at the same time;
[0009] Implicit disaster recovery channel: A covert communication link based on optical pulse phase modulation is established between storage nodes, and encrypted metadata is embedded in normal traffic. When the main communication link is blocked, covert data transmission that is resistant to quantum computing is achieved by adjusting the optical pulse phase.
[0010] Preferably, the quantum key entanglement engine adopts multi-dimensional Hilbert space encoding to bind the key segment to the latitude and longitude coordinates and altitude of the node. When it is detected that the node position deviation exceeds a preset range, the local key segment is automatically destroyed and cross-regional quantum relay reconstruction is initiated.
[0011] Preferably, the dynamic topology perception module includes a hardware fingerprint fuse mechanism: when the node CPU micro-architecture characteristics deviate from the baseline value at the time of registration by more than 5%, the node is determined to be under a side channel attack and all quantum key segments stored in it are immediately fused.
[0012] Preferably, the space-time folding encryption module adopts a chaotic fractal cutting algorithm during the data sharding process:
[0013] Map the original data to the three-dimensional Mandelbrot fractal space;
[0014] Cut along the discontinuous mutation points of the fractal surface to generate data slices with self-similar properties;
[0015] The encryption key of each shard contains the chaotic parameters of the previous shard, forming a topology-dependent decryption chain.
[0016] Preferably, the implicit disaster recovery channel supports photon orbital angular momentum modulation and is transmitted simultaneously in a single optical fiber:
[0017] Conventional data flow, using OAM mode l = 0;
[0018] Emergency metadata,adopts the high-order modes of l=±10, which overlap in the frequency,domain but can be separated by the vortex phase to achieve bit-level,steganography.
[0019] Preferably, the system deploys an anti-quantum phishing module: an artificially designed quantum trap state is embedded in the key distribution process. When an attacker attempts to measure the quantum channel, the trap state collapses into a preset erroneous key and triggers the reorganization of the key segments of the entire network.
[0020] Preferably, the NTRU lattice cryptographic algorithm also includes the following improvements:
[0021] Chaotic parameter injection: In the key generation phase, Logistic chaotic mapping is used to generate random polynomial coefficients. The initial value of the chaotic system is determined by the hardware fingerprint hash value of the storage node to ensure the uniqueness and unpredictability of the key.
[0022] Polynomial ring accelerator: During encryption and decryption, FPGA hardware is used to implement modular multiplication and modular addition operations on polynomial rings, and the parallel computing unit is used to increase the computing speed to more than 8 times that of traditional CPUs.
[0023] Fault-tolerant decryption mechanism: In the decryption stage, an error compensation polynomial is introduced to pre-calculate the range of rounding errors that may occur during the decryption process, dynamically adjust the decryption result, and reduce the decryption error rate to 10 -9 the following.
[0024] Compared with the prior art, the present invention has the following beneficial effects:
[0025] The present invention uses quantum key segmentation and geographic binding technology to ensure that the complete key cannot be reconstructed if a single node is leaked; the dynamic topology perception module monitors the node status in real time and quickly responds to side channel attacks through the hardware fingerprint fuse mechanism; the space-time folding encryption module uses chaotic fractal cutting and PUF noise injection to generate different ciphertexts for the same data block at different nodes, and cracking a single node cannot threaten the global data; the implicit disaster recovery channel realizes quantum-resistant hidden transmission and key self-repair through photon orbital angular momentum modulation and quantum trap state embedding; the improved NTRU algorithm significantly improves encryption efficiency and reduces decryption error rate through chaotic parameter injection and FPGA acceleration. The system has high security, quantum computing resistance and dynamic environment adaptability, and solves the problems of key rigidity, sharding redundancy and security contradictions in traditional distributed storage encryption.
[0026] Other features and advantages of the present invention will be described in the following description, and partly become apparent from the description, or understood by practicing the present invention. The purpose and other advantages of the present invention can be realized and obtained by the structures pointed out in the description, claims and drawings. BRIEF DESCRIPTION OF THE DRAWINGS
[0027] Figure 1 This is a block diagram of the computer distributed storage encryption system of the present invention. DETAILED DESCRIPTION
[0028] The following will be combined with the drawings in the embodiments of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this technical field without creative work are within the scope of protection of the present invention.
[0029] See also Figure 1 , a computer distributed storage encryption system in the present invention mainly includes the following core modules:
[0030] Quantum key entanglement engine: responsible for the division and geographical binding of keys;
[0031] Dynamic topology awareness module: monitors the physical status of storage nodes in real time and adjusts key distribution;
[0032] Space-time folding encryption module: realizes data sharding and encryption to ensure data security and recoverability;
[0033] Implicit disaster recovery channel: provides a covert communication link to ensure the anti-interference capability of data transmission.
[0034] Specifically include the following:
[0035] 1. Quantum Key Entanglement Engine
[0036] Key generation and splitting process
[0037] 1. Quantum key generation:
[0038] The QKD devices of edge nodes A and B generate entangled photon pairs and negotiate to share a 256-bit initial key KmasterKmaster through the BB84 protocol.
[0039] Anti-quantum phishing mechanism: embed quantum trap states in photon transmission (for example, randomly insert |+> states when preparing |0> states). If the attacker measures, the trap state collapses to an invalid state and triggers an alarm.
[0040] 2. Geographically bound segmentation:
[0041] Using multidimensional Hilbert space encoding:
[0042] The key K master Map to three-dimensional space (longitude λ, latitude φ, altitude h) and generate a piecewise function:
[0043]
[0044] Where H is the SHA3-256 hash function, It is an XOR operation.
[0045] Example: Beijing node stores K segment1 =K master [0:76], Shanghai node storage K segment2 =K master [77:255].
[0046] 3. Key migration and reconstruction:
[0047] Trigger condition: When the node position deviation exceeds the preset threshold (such as longitude ±0.1°, altitude ±10 meters), migration is initiated.
[0048] Quantum relay protocol: The key segment is transmitted to the new node through quantum teleportation. After the transmission is completed, the key segment of the original node is automatically erased (overwritten with all 0s).
[0049] Technical effect verification
[0050] Anti-attack test: simulate an attacker stealing the K of the Beijing node segment1 , due to the lack of Shanghai node K segment2 Geographically bound hash value, cracking probability is less than 10 -38 .
[0051] 2. Dynamic Topology Awareness Module
[0052] Physical feature collection and score calculation
[0053] 1. Data collection layer:
[0054] Hardware fingerprint: read the CPU microcode version and cache timing (L1 Cache access delay benchmark value Tbase=2.1nsTbase=2.1ns) through the CPUID instruction set.
[0055] Electromagnetic radiation: The ADALM-PLUTO spectrum analyzer is used to monitor the radiation intensity of the node cabinet (frequency band 1GHz-3GHz, resolution 1MHz).
[0056] 2. Dynamic Security Scoring Matrix:
[0057] Scoring formula:
[0058]
[0059] L current : The distance between the node and the center point of the preset geo-fence (unit: km);
[0060] ΔT: Deviation between the current CPU cache latency and the baseline value;
[0061] E noise : The number of frequencies where electromagnetic radiation exceeds the standard.
[0062] Threshold rule: If S<0.6S<0.6, the node is determined to be untrustworthy.
[0063] 3. Hardware fingerprint fuse mechanism:
[0064] Abnormal detection: Real-time monitoring of CPU cache latency. If ΔT>5% (i.e. T current >2.205ns), it is determined to be subject to a side channel attack.
[0065] Fuse operation:
[0066] Immediately interrupt all data access requests of the node;
[0067] Trigger the migration of the key segment to the standby node (migration time < 50ms < 50ms);
[0068] Record attack events to the blockchain audit log (using the Hyperledger Fabric framework).
[0069] 3. Space-time folding encryption module
[0070] 1. Chaotic fractal cutting and PUF noise injection
[0071] Fractal data cutting:
[0072] Step 1: Map the original data stream D to the three-dimensional Mandelbrot fractal space to generate a complex number sequence:
[0073]
[0074] Step 2: Cut the data block along the mutation point of the fractal surface (the area where the Lyapunov exponent λ>0) to generate self-similar fragments {D1, D2, ..., D n}.
[0075] PUF noise generation:
[0076] Extract the hardware fingerprint of the storage node (such as the hard disk serial number) and generate the noise sequence N through SRAM PUF puf ;
[0077] N puf Injection shard encryption process:
[0078]
[0079] Differential ciphertext: The same data block is encrypted at different nodes. puf Different, the ciphertext difference is >99%.
[0080] 4. Technology for improving NTRU algorithm
[0081] 1. Chaos parameter injection:
[0082] Key generation phase:
[0083] Use the Logistic Chaotic Map x n+1 =4x n (1-x n ), initial value
[0084] x0=SHA256(CPU I D) mod1.
[0085] Generator polynomial coefficients in
[0086] 2. FPGA Accelerator Design
[0087] Hierarchical parallel architecture:
[0088] First layer: Split the polynomial coefficients into 4 sub-blocks, each of which is processed by an independent computing unit of the FPGA;
[0089] Second layer: In each computing unit, SIMD instructions are used to parallelize 32 sets of modular multiplication operations (a×b mod q);
[0090] The third layer: Pre-calculate the modular inverse table through BRAM cache to reduce real-time computing latency.
[0091] 3. Fault-tolerant decryption mechanism
[0092] Error compensation polynomial generation:
[0093] The error range of the pre-calculated noise polynomial r(x)r(x) during encryption is δ=max(|r i |);
[0094] Generate compensation polynomial
[0095] Decryption optimization:
[0096] m'(x)=NTRU Decrypt(c(x))+e(x)mod p
[0097] The error is compensated by adaptive threshold filtering, and the error rate is reduced from 10 -5 Down to 10 -9 .
[0098] 5. Hidden transmission protocol of implicit disaster recovery channel
[0099] 1. Photon Orbital Angular Momentum (OAM) Modulation
[0100] Multi-mode multiplexing transmission:
[0101] Conventional data flow: Use OAM mode l = 0 to transmit AES-GCM encrypted storage data;
[0102] Emergency metadata: Use l=±10 high-order mode to embed the location mapping table of the encrypted fragments.
[0103] Vortex Phase Separation Technology:
[0104] A spiral phase plate is used at the receiving end to separate different OAM modes; anti-interference index: bit error rate <10 -12 , can resist 50dB channel noise.
[0105] 2. Anti-quantum relay attack
[0106] Quantum trap state trigger logic:
[0107] Random insertion of trapped states in quantum channels If the attacker measures |ψ trap >, which collapses to |0> or |1>, causing key verification failure;
[0108] The system automatically starts the reorganization of the key segment of the entire network, and the reorganization time is <200ms.
[0109] 6. System joint debugging test data
[0110] Test items index Test Results Key Splitting Security Strength Anti-brute force cracking ability <![CDATA[2 256 Equivalent]]> Dynamic topology awareness response time Node anomaly detection delay <10ms NTRU decryption error rate After the fault tolerance mechanism is enabled <![CDATA[3.2×10 -10 ]]> Implicit disaster recovery channel throughput OAM high-order mode transmission rate 100Mbps (covert channel)
[0111] This embodiment uses a quantum key entanglement engine to achieve geographical binding and dynamic migration of key segments, and combines multi-dimensional Hilbert space coding to resist physical layer attacks; the dynamic topology perception module monitors the node security status in real time based on the hardware fingerprint fuse mechanism, and the detection error in response to side channel attacks is less than 5%; the space-time folding encryption module uses a chaotic fractal cutting algorithm and PUF noise injection technology to generate heterogeneous ciphertexts after the same data is encrypted at different nodes, and cracking a single node cannot threaten global data; the implicit disaster recovery channel realizes bit-level steganography of conventional traffic and emergency metadata through photon orbital angular momentum modulation, and embeds quantum trap states to trigger the reorganization of the entire network key to ensure the ability to resist quantum computing attacks. The system integrates quantum security, environmental perception and physical non-cloning characteristics to achieve high security, high reliability and dynamic adaptability of distributed storage encryption.
Claims
1. A computer distributed storage encryption system, characterized in that: Including quantum key entanglement engine, dynamic topology perception module, space-time folding encryption module and implicit disaster recovery channel; Quantum key entanglement engine: The quantum key distribution (QKD) device deployed at the edge node generates entangled photon pairs, which divides the key into geographically bound quantum segments. If any geographical segment is leaked alone, the complete key cannot be reconstructed. Dynamic topology perception module: collects the physical characteristics of storage nodes in real time, builds a dynamic security scoring matrix, and automatically triggers the migration of key segments to nodes with higher credibility when the node security score is lower than the threshold; Time-space folding encryption module: Using the NTRU lattice cryptographic algorithm, a physical unclonable function (PUF) noise bound to the hardware fingerprint of the storage node is injected during data sharding, so that the same data block generates different ciphertexts after encryption at different nodes, and can only be decrypted when the original node cluster is online at the same time; Implicit disaster recovery channel: A covert communication link based on optical pulse phase modulation is established between storage nodes, and encrypted metadata is embedded in normal traffic. When the main communication link is blocked, covert data transmission that is resistant to quantum computing is achieved by adjusting the optical pulse phase.
2. A computer distributed storage encryption system according to claim 1, characterized in that: The quantum key entanglement engine uses multi-dimensional Hilbert space encoding to bind the key segment to the latitude and longitude coordinates and altitude of the node. When it is detected that the node position deviation exceeds the preset range, the local key segment is automatically destroyed and cross-regional quantum relay reconstruction is initiated.
3. A computer distributed storage encryption system according to claim 1, characterized in that: The dynamic topology perception module includes a hardware fingerprint fuse mechanism: when the node CPU micro-architecture characteristics deviate from the baseline value at the time of registration by more than 5%, the node is determined to have suffered a side channel attack and all quantum key segments stored in it are immediately fused.
4. A computer distributed storage encryption system according to claim 1, characterized in that: The space-time folding encryption module adopts a chaotic fractal cutting algorithm during the data sharding process: Map the original data to the three-dimensional Mandelbrot fractal space; Cut along the discontinuous mutation points of the fractal surface to generate data slices with self-similar properties; The encryption key of each shard contains the chaotic parameters of the previous shard, forming a topology-dependent decryption chain.
5. A computer distributed storage encryption system according to claim 1, characterized in that: The implicit disaster recovery channel supports photon orbital angular momentum modulation and transmits simultaneously in a single optical fiber: Conventional data flow, using OAM mode l = 0; Emergency metadata,adopts the high-order modes of l=±10, which overlap in the frequency,domain but can be separated by the vortex phase to achieve bit-level,steganography.
6. A computer distributed storage encryption system according to claim 1, characterized in that: The system deploys an anti-quantum phishing module: an artificially designed quantum trap state is embedded in the key distribution process. When an attacker attempts to measure the quantum channel, the trap state collapses into a preset erroneous key and triggers the reorganization of the key segments of the entire network.
7. A computer distributed storage encryption system according to claim 1, characterized in that: The NTRU lattice cryptographic algorithm also includes the following improvements: Chaotic parameter injection: In the key generation phase, Logistic chaotic mapping is used to generate random polynomial coefficients. The initial value of the chaotic system is determined by the hardware fingerprint hash value of the storage node to ensure the uniqueness and unpredictability of the key. Polynomial ring accelerator: During encryption and decryption, FPGA hardware is used to implement modular multiplication and modular addition operations on polynomial rings, and the parallel computing unit is used to increase the computing speed to more than 8 times that of traditional CPUs. Fault-tolerant decryption mechanism: In the decryption stage, an error compensation polynomial is introduced to pre-calculate the range of rounding errors that may occur during the decryption process, dynamically adjust the decryption result, and reduce the decryption error rate to 10 -9 the following.
Citation Information
Cited By
Secret communication system of unmanned aerial vehicle
CN120281476A
A secure communication system for drones
CN120281476B
Low-power-consumption hardware encryption system based on geological disaster monitoring scene
CN120434040A
Method and system for media processing in distributed cloud
CN121000707A
Wireless fast ad hoc network node security access and key management method based on quantum random number
CN121463034A