Cloud computing data secure transmission system and method
By adopting hybrid encryption mechanisms and multi-level security measures in the cloud computing environment, security and privacy protection issues in the cloud computing data transmission process are solved, and efficient and secure data transmission and management are achieved.
Patent Information
- Application Number
- CN202510193825.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-21
- Publication Date
- 2025-05-16
AI Technical Summary
Security and privacy protection issues during data transmission in cloud computing environments include inconvenient key management, slow encryption and decryption speed, security of data segmentation transmission and vulnerability to identity authentication.
A hybrid encryption mechanism combining asymmetric encryption and symmetric encryption is adopted, and the application of dynamic key management, two-factor authentication, data segmentation and reorganization, real-time transmission monitoring and blockchain technology is realized through the data encryption module, key management module, identity authentication module, data segmentation and reorganization, real-time transmission monitoring and blockchain technology.
It improves the security, integrity and transmission efficiency of data transmission on the cloud, enhances the confidentiality and privacy protection of data, and achieves comprehensive data monitoring and auditing capabilities.
Smart Images

Figure CN120017386A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of information technology, and in particular to a cloud computing data secure transmission system and method. Background Art
[0002] With the continuous development of Internet technology, cloud computing technology has been widely used in data processing and storage needs of various enterprises and individual users. Cloud computing provides efficient computing power, large-scale storage space and rich application services by centrally managing computing resources, greatly reducing the investment cost of information technology (IT) infrastructure and improving the flexibility and efficiency of data processing. However, data security issues in cloud computing environments are becoming increasingly prominent, especially the security and privacy protection of data during transmission on the cloud, which has become one of the most concerned issues for users.
[0003] In existing technologies, encryption technology is usually used to protect data security before uploading it to the cloud. However, traditional encryption methods have problems such as inconvenient key management and low key security. For example, (1) although symmetric encryption has high encryption and decryption efficiency, the key distribution and management process has great security risks; and although asymmetric encryption solves the key distribution problem, the encryption and decryption speed is relatively slow and inefficient when processing big data. (2) Once the data uploaded to the cloud is divided into multiple parts for transmission, how to ensure that these scattered data can be accurately reassembled at the receiving end while ensuring the security of each part of the data is another technical problem that needs to be solved. (3) The identity authentication process often relies only on simple usernames and passwords, which are vulnerable to hacker attacks, resulting in illegal access or tampering of data. Summary of the invention
[0004] The present invention proposes a cloud computing data secure transmission system and method that combines asymmetric encryption with a hybrid encryption mechanism of symmetric encryption, aiming to improve the security, integrity and transmission efficiency of data transmission on the cloud.
[0005] The technical solution adopted by the present invention is: a cloud computing data security transmission system, which is composed of a data encryption module, a key management module, an identity authentication module, a data segmentation module, and a transmission monitoring module.
[0006] The data encryption module is used to encrypt the data packets uploaded to the cloud according to the dynamic key generated in real time, and the encryption algorithm supports asymmetric encryption and symmetric encryption hybrid synchronization mode;
[0007] The key management module is used to store and manage all static keys and dynamic keys, and to create new dynamic keys to ensure key uniqueness during each transmission process;
[0008] The identity verification module is used to perform dual authentication on the identity of the receiver, firstly performing a preliminary verification based on the preset identity information, and secondly performing a secondary verification through biometric recognition technology to ensure the legitimacy of the receiver;
[0009] The data segmentation module is used to segment the large file to be encrypted into several small files according to a preset length, and generate a unique identification code for each small file to facilitate subsequent decryption operations;
[0010] The transmission monitoring module is used to monitor the transmission status of data packets in the network in real time. By setting detection rules for abnormal transmission, it can effectively identify and prevent unauthorized data access or malicious attacks. At the same time, it uses blockchain technology to ensure the security and non-tamperability of the data transmission process, providing a novel and secure data upload and sharing mechanism.
[0011] As a further improvement of the present invention, the data encryption module uses a digital certificate exchange key based on a public key infrastructure (PKI) to achieve secure communication between the server and the client, ensuring that both parties can exchange information securely on an open network.
[0012] As a further improvement of the present invention, the key management module has an automatic key rotation function, which can automatically replace the dynamic key in use within a fixed period or before and after sensitive operations, thereby enhancing the security of the system.
[0013] As a further improvement of the present invention, the identity authentication module supports a multi-factor authentication mechanism, including traditional username and password authentication and at least two additional identity authentication methods: hardware token, SMS verification code, and dynamic password.
[0014] As a further improvement of the present invention, the data segmentation module generates a check code when segmenting a file. After the receiving end completes data reception, the data integrity can be verified according to the check code to ensure that the received data has not been tampered with.
[0015] A method for securely transmitting cloud computing data comprises the following steps:
[0016] S1: The client requests to upload data to the cloud;
[0017] S2: The cloud responds to the request and starts the data encryption module to generate a new dynamic key for this transmission;
[0018] S3: The client uses the obtained dynamic key to encrypt the data packet and divides it into multiple small files through the data segmentation module;
[0019] S4: Each encrypted small file is uploaded to different nodes in the cloud with an identification code;
[0020] S5: The cloud deletes the local cache immediately after receiving each small file to prevent leakage;
[0021] S6: After the receiving end verifies its identity through the identity verification module, it downloads the relevant small files from the cloud;
[0022] S7: The receiving end decrypts the received small file using the key provided by the key management module, and reassembles it into the original data packet according to the identification code;
[0023] S8: After the data download is completed, the integrity and authenticity of the data are verified through the check code provided by the transmission monitoring module.
[0024] As a further improvement of the present invention, in S1, the upload request initiated by the client includes the data storage validity period and access permission settings selected by the user, allowing the user to flexibly set data protection measures according to actual needs.
[0025] As a further improvement of the present invention, in S2, the dynamic key generation algorithm is based on the influence of time factors and transmission environment factors, thereby ensuring the unpredictability and high security of the key.
[0026] As a further improvement of the present invention, in S4, a segmented transmission protocol is adopted during the process of uploading the encrypted small files to different nodes in the cloud to ensure that each small file can be transmitted independently and securely. Even if part of the data is lost or tampered with during the transmission process, it will not affect the integrity and security of other small files.
[0027] As a further improvement of the present invention, after the data transmission is completed, both the cloud and the receiving end will generate a transmission log to record the detailed process of data transmission, including transmission time, file size, and transmission status, for subsequent auditing and tracking, further improving the security and traceability of data transmission.
[0028] Beneficial effects of the present invention: (1) Enhanced data security and privacy protection: The present invention not only ensures high efficiency in the data transmission process, but also greatly enhances data security and privacy protection by combining asymmetric encryption with symmetric encryption. Asymmetric encryption solves the security problem of key distribution, while symmetric encryption improves encryption efficiency and key security by using dynamic keys. In addition, multi-factor authentication mechanisms such as biometrics are used to effectively prevent access by illegal users and ensure the confidentiality and integrity of data.
[0029] (2) Improved data transmission efficiency and reliability: The data segmentation module of the present invention decomposes a large file into multiple small files and generates a unique identifier for each small file, which not only speeds up the file transmission speed but also improves the stability of data transmission. Even under poor network conditions, the loss of a single small file will not affect the transmission of the entire data packet. The receiving end can still accurately reassemble the file according to the identification code, thereby ensuring the reliability and integrity of data transmission. The use of a segmented transmission protocol further ensures the security and independence of each small file.
[0030] (3) Comprehensive data monitoring and auditing capabilities are achieved: The transmission monitoring module of the present invention can not only monitor the transmission status of data in the network in real time, detect and respond to abnormal transmission in a timely manner, and prevent unauthorized data access and malicious attacks, but also ensure the immutability of data transmission by introducing blockchain technology, thereby enhancing data security. In addition, the generated transmission log records the detailed process of data transmission, including transmission time, file size, transmission status and other information, which not only facilitates subsequent data auditing and tracking, but also provides users with clear data management transparency and enhances the credibility of the system. BRIEF DESCRIPTION OF THE DRAWINGS
[0031] Figure 1 It is a system block diagram of a cloud computing data security transmission system and method of the present invention;
[0032] Figure 2 It is a flow chart of a cloud computing data secure transmission system and method of the present invention. DETAILED DESCRIPTION
[0033] In order to make the technical problems, technical solutions and beneficial effects to be solved by the present application more clearly understood, the present application is further described in detail below in conjunction with the accompanying drawings and embodiments. It should be understood that the embodiments described herein are only used to explain the present application and are not used to limit the present application.
[0034] The present invention provides a cloud computing data security transmission system, which consists of a data encryption module, a key management module, an identity authentication module, a data segmentation module, and a transmission monitoring module.
[0035] The data encryption module of the present invention is used to encrypt the data packets uploaded to the cloud according to the dynamic key generated in real time. The encryption algorithm supports the hybrid synchronization of asymmetric encryption and symmetric encryption. The data encryption module uses a digital certificate exchange key based on the public key infrastructure (PKI) to achieve secure communication between the server and the client, ensuring that both parties can exchange information securely on an open network.
[0036] The key management module of the present invention is used to store and manage all static keys and dynamic keys, and to create new dynamic keys to ensure the uniqueness of the keys during each transmission process. The key management module has an automatic key rotation function, which can automatically replace the dynamic keys in use within a fixed period or before and after sensitive operations, thereby enhancing the security of the system;
[0037] The identity authentication module of the present invention is used to perform dual authentication on the identity of the receiving end, firstly performing preliminary authentication based on preset identity information, and secondly performing secondary authentication through biometric recognition technology to ensure the legitimacy of the receiver. The identity authentication module supports a multi-factor authentication mechanism, including traditional username and password authentication and at least two additional authentication methods: hardware token, SMS verification code, and dynamic password;
[0038] The data segmentation module in the present invention is used to segment the large file to be encrypted into several small files according to a preset length, and generate a unique identification code for each small file to facilitate subsequent decryption operations. The data segmentation module will generate a check code when segmenting the file. After the receiving end completes data reception, the data integrity can be verified according to the check code to ensure that the received data has not been tampered with;
[0039] The transmission monitoring module described in the present invention is used to monitor the transmission status of data packets in the network in real time. By setting detection rules for abnormal transmission, it can effectively identify and prevent unauthorized data access or malicious attacks. At the same time, blockchain technology is used to ensure the security and non-tamperability of the data transmission process, providing a novel and secure data upload and sharing mechanism.
[0040] A method for securely transmitting cloud computing data comprises the following steps:
[0041] S1: The client requests to upload data to the cloud. The upload request initiated by the client includes the data storage validity period and access permission settings selected by the user, allowing the user to flexibly set data protection measures according to actual needs;
[0042] S2: The cloud responds to the request and starts the data encryption module to generate a new dynamic key for the transmission. The dynamic key generation algorithm is based on the influence of time factors and transmission environment factors, ensuring the unpredictability and high security of the key;
[0043] S3: The client uses the obtained dynamic key to encrypt the data packet and divides it into multiple small files through the data segmentation module;
[0044] S4: Each encrypted small file is uploaded to different cloud nodes with an identification code. During the upload of each encrypted small file to different cloud nodes, a segmented transmission protocol is used to ensure that each small file can be transmitted independently and securely. Even if some data is lost or tampered with during the transmission process, it will not affect the integrity and security of other small files.
[0045] S5: The cloud deletes the local cache immediately after receiving each small file to prevent leakage;
[0046] S6: After the receiving end verifies its identity through the identity verification module, it downloads the relevant small files from the cloud;
[0047] S7: The receiving end decrypts the received small file using the key provided by the key management module, and reassembles it into the original data packet according to the identification code;
[0048] S8: After the data download is completed, the integrity and authenticity of the data are verified through the check code provided by the transmission monitoring module.
[0049] After the data transmission described in the present invention is completed, both the cloud and the receiving end will generate a transmission log to record the detailed process of data transmission, including transmission time, file size, and transmission status, for subsequent auditing and tracking, further improving the security and traceability of data transmission.
[0050] Example:
[0051] Background: A certain enterprise needs to upload a large amount of sensitive financial data to the cloud so as to share data between different branches. In order to ensure the security and privacy protection of data, the enterprise adopts a cloud computing data security transmission system and method of the present invention.
[0052] Implementation steps
[0053] (1) Client requests to upload data to the cloud: The enterprise user's IT administrator initiates a data upload request through the client application and sets the data storage validity period to 6 months. Access rights are limited to the company's financial department personnel.
[0054] (ii) The cloud responds to the request and generates a dynamic key: After receiving the upload request, the cloud server starts the data encryption module and generates a new dynamic key for the transmission. The dynamic key generation algorithm combines the current timestamp and the random factors of the transmission environment to ensure the uniqueness and security of the key.
[0055] (III) The client uses the dynamic key to encrypt data and split files: The client application uses the generated dynamic key to encrypt the entire financial data file. The data splitting module splits the encrypted data file into several small files according to the preset length of 1MB, and generates a unique identification code and check code for each small file.
[0056] (IV) The encrypted small files are uploaded to different cloud nodes: Each small file is uploaded to a different cloud node through the client application, and each small file is accompanied by its unique identification code. During the upload process, a segmented transmission protocol is used to ensure that each small file can be transmitted independently and securely. Even if some data is lost or tampered with, it will not affect the integrity and security of other small files.
[0057] (V) Deleting the local cache after receiving a small file on the cloud: Every time a cloud node receives a small file, it immediately deletes the local cache to prevent data leakage.
[0058] (VI) Receiver identity verification: A user in the corporate finance department initiates a data download request through a client application. The identity verification module first performs a preliminary verification based on the preset identity information (user name and password), and then performs a secondary verification through biometric recognition (such as fingerprint recognition or facial recognition) to ensure the legitimacy of the recipient.
[0059] (VII) The receiving end downloads and decrypts data: After the identity authentication is passed, the client application downloads the relevant small files from different nodes in the cloud. After the download is completed, the client application uses the dynamic key provided by the key management module to decrypt each small file and reassemble it into the original financial data file based on the identification code.
[0060] (VIII) Data integrity verification: The client application uses the checksum that comes with the downloaded file to verify the integrity of each small file. The reorganized data file is further verified for integrity and authenticity through the checksum to ensure that the data has not been tampered with.
[0061] (IX) Transfer log records: Both the cloud and the client generate transfer logs to record the detailed process of data transfer, including transfer time, file size, transfer status and other information for subsequent auditing and tracking.
[0062] Through the above embodiments, it can be seen that the cloud computing data security transmission system and method of the present invention can effectively improve the security, integrity and transmission efficiency of data. The system not only supports flexible data storage validity period and access permission settings, but also ensures the security and privacy protection of data during transmission through a variety of encryption and verification mechanisms. At the same time, real-time transmission monitoring and transmission log recording functions provide strong support for data auditing and tracking.
[0063] The above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit the same. Although the present invention has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that the technical solutions described in the aforementioned embodiments may still be modified, or some of the technical features thereof may be replaced by equivalents. However, these modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the embodiments of the present invention.
Claims
1. A cloud computing data security transmission system, characterized in that: It consists of data encryption module, key management module, identity authentication module, data segmentation module and transmission monitoring module. The data encryption module is used to encrypt the data packets uploaded to the cloud according to the dynamic key generated in real time, and the encryption algorithm supports asymmetric encryption and symmetric encryption hybrid synchronization mode; The key management module is used to store and manage all static keys and dynamic keys, and to create new dynamic keys to ensure key uniqueness during each transmission process; The identity verification module is used to perform dual authentication on the identity of the receiver, firstly performing a preliminary verification based on the preset identity information, and secondly performing a secondary verification through biometric recognition technology to ensure the legitimacy of the receiver; The data segmentation module is used to segment the large file to be encrypted into several small files according to a preset length, and generate a unique identification code for each small file to facilitate subsequent decryption operations; The transmission monitoring module is used to monitor the transmission status of data packets in the network in real time. By setting detection rules for abnormal transmission, it can effectively identify and prevent unauthorized data access or malicious attacks. At the same time, it uses blockchain technology to ensure the security and non-tamperability of the data transmission process, providing a novel and secure data upload and sharing mechanism.
2. A cloud computing data secure transmission system according to claim 1, characterized in that: The data encryption module uses digital certificates based on public key infrastructure (PKI) to exchange keys, realize secure communication between the server and the client, and ensure that both parties can exchange information securely on an open network.
3. A cloud computing data secure transmission system according to claim 1, characterized in that: The key management module has an automatic key rotation function, which can automatically replace the dynamic key in use within a fixed period or before and after sensitive operations, thereby enhancing the security of the system.
4. A cloud computing data secure transmission system according to claim 1, characterized in that: The identity authentication module supports a multi-factor authentication mechanism, including traditional username and password authentication and at least two additional identity authentication methods: hardware token, SMS verification code, and dynamic password.
5. A cloud computing data secure transmission system according to claim 1, characterized in that: The data segmentation module generates a check code when segmenting a file. After the receiving end completes data reception, the receiving end can verify the data integrity based on the check code to ensure that the received data has not been tampered with.
6. A cloud computing data secure transmission method, characterized in that: The following steps are involved: S1: The client requests to upload data to the cloud; S2: The cloud responds to the request and starts the data encryption module to generate a new dynamic key for this transmission; S3: The client uses the obtained dynamic key to encrypt the data packet and divides it into multiple small files through the data segmentation module; S4: Each encrypted small file is uploaded to different nodes in the cloud with an identification code; S5: The cloud deletes the local cache immediately after receiving each small file to prevent leakage; S6: After the receiving end verifies its identity through the identity verification module, it downloads the relevant small files from the cloud; S7: The receiving end decrypts the received small file using the key provided by the key management module, and reassembles it into the original data packet according to the identification code; S8: After the data download is completed, the integrity and authenticity of the data are verified through the check code provided by the transmission monitoring module.
7. A cloud computing data secure transmission method according to claim 6, characterized in that: In S1, the upload request initiated by the client includes the data storage validity period and access permission settings selected by the user, allowing the user to flexibly set data protection measures according to actual needs.
8. A cloud computing data secure transmission method according to claim 6, characterized in that: In S2, the dynamic key generation algorithm is based on the influence of time factors and transmission environment factors, which ensures the unpredictability and high security of the key.
9. A cloud computing data secure transmission method according to claim 6, characterized in that: In S4, when the encrypted small files are uploaded to different nodes in the cloud, a segmented transmission protocol is used to ensure that each small file can be transmitted independently and securely. Even if some data is lost or tampered with during the transmission process, it will not affect the integrity and security of other small files.
10. A cloud computing data secure transmission method according to claim 6, characterized in that: After the data transmission is completed, both the cloud and the receiving end will generate a transmission log to record the detailed process of data transmission, including transmission time, file size, and transmission status, for subsequent auditing and tracking, further improving the security and traceability of data transmission.
Citation Information
Cited By
Security encryption verification method based on cloud service
CN120238304A