File encryption system based on multi-level security protection

Through technical means such as three-layer architecture design and shard encryption, the shortcomings of file encryption solutions in the existing technology in the efficient operation of the system are solved, and the security, operation efficiency and scalability of the file system are improved.

CN120068104APending Publication Date: 2025-05-30CHANGYUAN INTELLIGENT EQUIP (GUANGDONG) CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510095169.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-21
Publication Date
2025-05-30

AI Technical Summary

Technical Problem

While ensuring data security, existing file encryption solutions are difficult to maintain efficient operation of the system, especially when processing large files, which requires a large amount of system memory, affecting the overall performance of the system.

Method used

It adopts a three-layer architecture design, including transparent access layer, data encryption layer and persistent storage layer. Through shard encryption, metadata encryption and on-demand decryption mechanisms, it realizes secure encryption and decryption of file content and directory structure, reduces memory usage and optimizes system performance.

Benefits of technology

It realizes security protection for dynamic data, improves the operating efficiency and scalability of the system, and ensures the security, operation efficiency and scalability of the file system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120068104A_ABST
    Figure CN120068104A_ABST
Patent Text Reader

Abstract

The invention relates to a file encryption system based on multi-level security protection, which reasonably divides a system structure, realizes efficient data protection and system operation experience through a multi-layer modular architecture, and fundamentally improves the security, the operation efficiency and the expansibility of a file system. Comprising the steps that a three-layer architecture design is adopted, a file encryption library is divided into a transparent access layer, a data encryption layer and a persistent storage layer, the transparent access layer serves as an interface layer of an application program and is responsible for receiving and managing a read-write request of the application program, and an upper layer request is converted into an encryption access instruction through a standardized file operation interface; the data encryption layer is used as a core processing layer, and ensures the security of data in storage and access processes through mechanisms such as fragmentation encryption, metadata encryption and on-demand decryption; the persistent storage layer is responsible for secure storage and management of encrypted data, and persistent storage of the data is realized through a standardized file storage interface. The method is suitable for the technical field of data encryption.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of data encryption, and in particular to a file encryption system based on multi-level security protection. Background Art

[0002] With the in-depth promotion of digital transformation, the demand for data security protection by enterprises and individuals is becoming increasingly urgent. As the last line of defense for data security protection, file encryption is of self-evident importance. However, in practical applications, existing file encryption solutions often only focus on static storage security and ignore the dynamic security protection requirements during data usage. Especially in scenarios involving sensitive data processing, how to ensure data security while maintaining the efficient operation of the system has become an urgent technical problem to be solved.

[0003] Currently, the mainstream file encryption solutions mainly adopt the following technical routes: The first is the overall encryption at the file level. This solution requires complete decryption before file usage, and the decrypted file is completely exposed in memory; the second is the transparent encryption solution based on the virtual file system. Although it provides a convenient usage experience, it still requires complete decryption operations during file reading, and there is also a risk of file content leakage during usage; finally, it is the encryption solution based on directory access control. This solution only controls at the file access level and cannot truly protect the data security of files. From the above conclusions, it can be seen that the existing technologies have the following major defects: The encryption process needs to generate temporary files, resulting in the possibility that the original data may be stolen through data recovery means; complete decryption is required during file usage, making sensitive data completely exposed in memory; the file directory structure is stored in plain text, which may leak the organizational structure information of the system; a large amount of system memory is required for large file processing, affecting the overall performance of the system. Summary of the Invention

[0004] The technical problem to be solved by the present invention is to overcome the deficiencies of the prior art and provide a file encryption system based on multi-level security protection that reasonably divides the system structure, realizes efficient data protection and system operation experience through a multi-layer modular architecture, and fundamentally improves the security, operation efficiency, and scalability of the file system.

[0005] The technical solution adopted by the present invention is as follows: The present invention adopts a three-layer architecture design. The file encryption library is divided into a transparent access layer, a data encryption layer, and a persistent storage layer. Each layer defines services for the upper layer through interface files, and only provides necessary function interfaces to ensure low coupling and stability between layers. Among them,

[0006] The transparent access layer provides a convenient file operation interface for applications, responsible for receiving and managing read and write requests from applications, converting the requests into encrypted access instructions through a standardized file operation interface, and passing them to the data encryption layer;

[0007] The data encryption layer provides an execution interface for file encryption and decryption for the transparent access layer. Through the mechanisms of sharding encryption, metadata encryption, and on-demand decryption, it performs encryption and decryption operations on the file content, and also provides independent encryption for the directory structure information to ensure the security of data during storage and access;

[0008] The persistent storage layer provides an operation interface for file data access and storage for the data encryption layer, responsible for persistently storing the encrypted data, and returning the original data during a decryption request.

[0009] Furthermore, the transparent access layer includes a file operation interface module, a logical location management module, and a data conversion management module. The operation interface module provides several standardized file operation interfaces for applications, enabling applications to directly call file read and write interfaces without concerning themselves with specific encryption and decryption details; the logical location management module is used to control the read and write positions of files and ensure transparent operations through virtual location records; the data conversion management module restores the directory structure or file path through a decryption algorithm and maps it to the physical storage location, enabling applications to correctly read files.

[0010] Furthermore, the data encryption layer includes an encryption algorithm module, a key management module, and a data authentication module. The encryption algorithm module selects an appropriate encryption algorithm according to the configuration to ensure that the data encryption process meets the specified security requirements; the key management module is used to manage the generation and replacement of encryption keys; the data authentication module includes data encryption and decryption operations to ensure the confidentiality and integrity of data during transmission.

[0011] Furthermore, in the sharding encryption mechanism, the file data is divided into fixed-size shards, and each shard is encrypted or decrypted separately to reduce memory occupancy; in the metadata encryption mechanism, through the encryption interface defined in the file, the directory structure information (such as file names, file paths) is encrypted using a symmetric encryption algorithm, and a unique encryption identifier is generated, remaining in an encrypted state during storage and reading; in the on-demand decryption mechanism, in combination with the data conversion management module and the sharding encryption mechanism, the position and content of the corresponding shard data are read, and the currently accessed shard data is decrypted.

[0012] Further, the persistent storage layer includes a buffer management module, a data storage management module, and an error handling module. The buffer management module realizes the caching write and read of data in the file system, optimizing I / O operations; the data storage management module is responsible for writing encrypted data to the underlying file system and ensuring that no unencrypted temporary data is generated during the operation; the error handling module is responsible for recording and managing the error information during the operation and providing detailed error logs.

[0013] Further, the buffer management module adopts a multi-level cache management strategy. The encryption library provides a set of data buffer operation interfaces for managing the read and write operations of the buffer. The system divides the data buffer area into several parts and caches data with different frequencies into the corresponding buffer areas, preferentially storing the data blocks with high access frequencies.

[0014] Finally, a cache cleaning mechanism is also provided in the buffer management module. By configuring a secure cleaning function, the plaintext data in the cache is immediately cleared after the data is written from the buffer to the file, ensuring that unencrypted data is not stored in the system for a long time.

[0015] Compared with the prior art, the beneficial effects of the present invention are as follows:

[0016] 1. Realize the security protection of dynamic data: Through the slice encryption and on-demand decryption of the data encryption layer, the present invention effectively reduces the risk of memory exposure of data during dynamic use. The slice encryption not only protects the file content but also reduces the memory consumption during data access, enabling the system to safely and efficiently process the data encryption and decryption requirements of large files.

[0017] 2. Improve the operation efficiency of the system: The present invention introduces a block cache management and a multi-level cache mechanism in the data encryption layer and the persistent storage layer respectively, reducing the frequent invocation of I / O resources by the system and optimizing the overall performance of the system. At the same time, the on-demand decryption method also effectively reduces the CPU occupancy rate during the decryption process, ensuring the fast response ability of the system.

[0018] 3. Strengthen the security of the directory structure: By encrypting the file system metadata (such as file names, directory structures, etc.), the present invention effectively prevents the leakage of directory structure information, eliminates the possibility of inferring the file system structure through unencrypted directories and file names, and ensures the integrity and privacy of the file system organization.

[0019] 4. Enhance the scalability and compatibility of the system: The transparent access layer and the persistent storage layer of the present invention provide standardized file interfaces, ensuring the transparency of the encryption process to the application program and enhancing the adaptability of the system among different operating platforms. The modular design of the system also makes subsequent function expansion and maintenance more convenient, meeting the file security requirements of multiple platforms and multiple scenarios. Brief Description of the Drawings

[0020] Figure 1 is the system schematic diagram of the present invention;

[0021] Figure 2 is the hierarchical relationship diagram of the three - layer architecture of the present invention;

[0022] Figure 3 is the system flow chart of the present invention. Detailed Description of the Invention

[0023] As Figures 1 to 3 shown, the present invention adopts a three - layer architecture design, and divides the file system encryption library into a transparent access layer, a data encryption layer, and a persistent storage layer to achieve secure protection and efficient processing of data during storage and access. Each layer defines services for the upper layer through interface files, and only provides necessary function interfaces to ensure low coupling and stability between layers. Among them, the transparent access layer serves as the interface layer of the application program, mainly responsible for docking application requests and providing standardized file operation interfaces for the upper layer. This layer establishes a transparent operation conversion between the user and the underlying data, so that the upper layer does not need to understand the underlying processing details when calling the encryption and decryption operations of files. The main responsibility of the transparent access layer is to receive and manage the read and write requests of the application program, convert them into encrypted access instructions, and uniformly transfer them to the data encryption layer for processing; the data encryption layer serves as the core layer of the encryption library, mainly implementing the encryption and decryption operations of file contents and directory structures. The data encryption layer processes file data in a segmented encryption manner and provides independent encryption for directory structure information at the same time. The responsibilities of this layer include segmented encryption, metadata encryption, and on - demand decryption to ensure the security of data during storage and access and reduce the resource occupancy of overall encryption and decryption; the persistent storage layer is the storage and management layer of encrypted data, responsible for securely writing the encrypted file contents and directory structure information into the underlying file system and ensuring the integrity and reliability of the data. This layer interacts with the file system through standardized file storage interfaces to ensure the secure storage of data during the persistence process. In addition, the persistent storage layer includes a temporary file security processing function to prevent the short - term exposure of unencrypted data during the decryption operation.

[0024] In the encryption and decryption read - write library of the present invention, each layer realizes clear division of labor and mutual cooperation through interface design, and supports data security and operation convenience in a modular manner. The specific relationship of the interface services provided by each layer to the upper layer is as follows:

[0025] The transparent access layer provides a standard interface for the application program: The transparent access layer is responsible for receiving the requests of the application program and providing convenient file operation interfaces, so that the upper - layer application only needs to call the interfaces of this layer to implement the read and write operations of encrypted files without understanding the underlying encryption and decryption process;

[0026] The data encryption layer provides encryption services for the transparent access layer: The interfaces provided by the data encryption layer implement the encryption and decryption of file contents and directory structures, ensuring data security. The transparent access layer calls these interfaces to perform file operations, while the data encryption layer maintains independence in the detailed processing of data, minimizing layer dependencies.

[0027] The persistent storage layer provides storage support for the data encryption layer: The persistent storage layer provides interfaces to support the access and storage operations of the data encryption layer, responsible for persistently storing encrypted data and returning the original data upon a decryption request. The data encryption layer calls the interfaces of the persistent storage layer to achieve secure data storage without having to understand the storage details.

[0028] Each layer defines services for the upper layer through interface files. Each layer only provides necessary functional interfaces to ensure low coupling and stability between layers. The management rights of the interface files belong to each layer, ensuring the reliability of the interfaces and the consistency of functions.

[0029] In the present invention, each layer is clearly divided according to the functions of the modules to achieve the security and stability of data encryption, decryption, and file operations. The modules of each layer are independent of each other, but data flow is achieved through interfaces. Among them, the transparent access layer includes a file operation interface module, a logical location management module, and a data conversion management module. The operation interface module provides standardized file operation interfaces for application programs, such as encry_open, encry_close, encry_read, encry_write, etc., enabling upper-layer applications to directly call file read and write interfaces without having to concern themselves with encryption details. The logical location management module provides functions such as encry_seek, encry_tell, encry_rewind, etc., for controlling the read and write positions of files and ensuring transparent operations through virtual location records. The data conversion management module has a decryption identifier restoration function. When a user requests access to a file, the system restores the directory structure or file path through a decryption algorithm and maps it to the physical storage location, enabling upper-layer applications to correctly read the file. This function is implemented in the operation conversion module of the transparent access layer, ensuring that the decryption and restoration process of directory information is transparent to the application program.

[0030] The data encryption layer includes an encryption algorithm module, a key management module, and a data authentication module. The encryption algorithm module selects an appropriate encryption algorithm according to the configuration to ensure that the data encryption process meets the specified security requirements. The key management module includes interfaces such as set_encryption_key and get_encryption_key, which are used to manage the generation and replacement of encryption keys to ensure data security. The data authentication module contains actual data encryption and decryption operations, such as encryption data processing in encry_write and decryption processing in encry_read, to ensure the confidentiality and integrity of data during transmission.

[0031] In the present invention, the data encryption layer adopts a dynamic encryption and decryption mechanism to ensure data security during file reading and writing through modular design. This mechanism includes functions such as dynamic selection of encryption algorithms, block-based sharding encryption and decryption processing, and on-demand decryption to enhance the security and operation efficiency of the system. The encryption algorithm module selects an appropriate encryption algorithm according to the configuration to ensure that the data encryption process meets the specified security requirements. The system supports multiple file encryption algorithms (such as AES, ChaCha20, Twofish, etc.), and users can select specific algorithms according to their needs, enabling the system to adapt to different security requirements. The sharding encryption mechanism divides file data into fixed-size shards and encrypts or decrypts them piece by piece to reduce memory occupancy. By processing data in blocks, the transmission and access efficiency of large files can be effectively improved. The on-demand decryption mechanism combines the data conversion management module and the sharding encryption mechanism to read the position and content of the corresponding shard data and decrypt the currently accessed shard data.

[0032] In the present invention, in order to protect the directory information of the file system, a directory structure encryption module is also designed to encrypt metadata such as directory structures and file names to prevent sensitive information from being inferred or leaked. This module provides an independent encryption solution for directory information through dedicated encryption algorithms and configuration options, including the metadata encryption mechanism. Through the encryption interface defined in the file, the system can encrypt directory structure information (such as file names and file paths). This encryption process uses a symmetric encryption algorithm to generate a unique encryption identifier for the file path or file name and keeps it encrypted during storage and reading. Decryption identifier restoration: When a user requests access to a file, the system restores the directory structure or file path through a decryption algorithm and maps it to the physical storage location, enabling the upper-layer application to correctly read the file. This function is implemented in the operation conversion module of the transparent access layer to ensure that the decryption and restoration process of directory information is transparent to the application program. Security control: The directory encryption protection module is combined with the access control module to ensure that only authorized requests can access the decrypted directory information, and unauthorized requests cannot directly access the directory information, effectively preventing illegal access and data leakage.

[0033] In the present invention, the persistent storage layer includes a buffer management module, a data storage management module, and an error handling module. The buffer management module provides functions such as fill_buffer and flush_buffer to achieve cached writing and reading of data in the file system, so as to optimize the efficiency of I / O operations; the data storage management module is responsible for writing encrypted data into the underlying file system and ensuring that no unencrypted temporary data is generated during the operation, thereby avoiding the risk of information leakage; the error handling module records and manages the error information during the operation, ensures timely response in case of exceptions, and provides detailed error logs for troubleshooting. Through the decomposition and cooperation of these modules, the design of each layer ensures the functional stability and scalability of the encryption / decryption read / write library, and at the same time realizes the secure transfer of data and the transparency of operations through interfaces.

[0034] The buffer management module adopts a multi-level cache management strategy. Through data buffer management and hierarchical storage mechanism, it improves the I / O efficiency of encrypted file reading and writing and reduces the occupation of storage resources during the file encryption and decryption process. The encryption library provides a set of data buffer operation interfaces for managing the reading and writing operations of the buffer, ensuring that file data is written or read in blocks. During the writing operation, the system first buffers the data in the buffer area and then writes it into the file system uniformly after the buffer area is full, reducing the performance loss caused by frequent I / O operations; the system divides the data buffer area into several parts and caches data with different frequencies in the corresponding buffer areas, preferentially storing the data blocks with high-frequency access to ensure efficient access during read and write operations. This strategy effectively reduces the read and write latency and improves the fluency of encrypted file operations. There is also a cache cleaning mechanism in the buffer management module. In order to prevent sensitive data from staying in the cache for a long time, the system provides a data cleaning function. By configuring a secure cleaning function, the plaintext data in the cache is cleared immediately after the data is written from the buffer into the file, ensuring that unencrypted data does not stay in the memory for a long time and improving the overall security.

[0035] Through the design features of the hierarchical architecture, the present invention constructs a set of secure access control systems at the file system level. In the transparent access layer, the system standardizes the access requests of application programs through standardized file operation interfaces, and converts various file operations into secure encrypted access operations; the data encryption layer, as the core control link, not only restricts the data range decrypted each time through the sharding encryption strategy, but also protects the structure information of the file system through the metadata encryption mechanism, realizing the overall security protection from data content to organizational structure; in the persistent storage layer, the system ensures the secure storage of data through secure storage interfaces and multi-level cache management mechanisms, and at the same time, in cooperation with the cache cleaning function, effectively prevents the residue of sensitive information in the cache. This hierarchical access control system realizes the standardized management of data access at the file system level through clear division of responsibilities and inter-layer cooperation. Through the cooperation of interface constraints and security mechanisms at each layer, it not only ensures the controllability of data access, but also maintains the coherence of system operations, providing a practical security guarantee scheme for the file encryption system. The present invention also pays attention to the overall security protection of the file system. Through the metadata encryption mechanism implemented in the data encryption layer, the directory structure information of the file system is independently encrypted to prevent the leakage of file organization structure information. At the same time, the multi-level cache management strategy designed by the present invention reduces frequent I / O operations through data buffer management and hierarchical storage mechanisms, and ensures data security through secure cache cleaning. The combined application of these technical solutions provides an encryption solution that takes into account both security and practicality for the file system.

[0036] Finally, it should be emphasized that the above are only the preferred embodiments of the present invention and are not used to limit the present invention. For those skilled in the art, the present invention can have various changes and modifications. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of the present invention shall be included within the protection scope of the present invention.

Claims

1. A file encryption system based on multi-level security protection, characterized by: The system adopts a three-layer architecture design, which divides the file encryption library into a transparent access layer, a data encryption layer, and a persistent storage layer. Each layer defines the service to the upper layer through an interface file and only provides necessary functional interfaces to ensure low coupling and stability between layers. The transparent access layer provides a convenient file operation interface for the application program, is responsible for receiving and managing the read and write requests of the application program, converts the requests into encryption access instructions through the standardized file operation interface, and transmits them to the data encryption layer; The data encryption layer provides the transparent access layer with an execution interface for file encryption and decryption. It performs encryption and decryption operations on file contents through slice encryption, metadata encryption, and on-demand decryption mechanisms. It also provides independent encryption for directory structure information to ensure data security during storage and access. The persistent storage layer provides an operation interface for file data access for the data encryption layer, is responsible for persistent storage of encrypted data, and returns the original data when a decryption request is made.

2. A file encryption system based on multi-level security protection according to claim 1, characterized in that: The transparent access layer includes a file operation interface module, a logical location management module and a data conversion management module. The operation interface module provides several standardized file operation interfaces for the application, so that the application can directly call the file read and write interface without paying attention to the specific encryption and decryption details; the logical location management module is used to control the read and write location of the file, and ensure transparent operation through virtual location records; the data conversion management module restores the directory structure or file path through a decryption algorithm and maps it to a physical storage location so that the application can read the file correctly.

3. A file encryption system based on multi-level security protection according to claim 2, characterized in that: The data encryption layer includes an encryption algorithm module, a key management module and a data authentication module. The encryption algorithm module selects a suitable encryption algorithm according to the configuration to ensure that the data encryption process meets the specified security requirements; The key management module is used to manage the production and replacement of encryption keys; the data authentication module includes data encryption and decryption operations to ensure the confidentiality and integrity of data during transmission.

4. A file encryption system based on multi-level security protection according to claim 3, characterized in that: The shard encryption mechanism divides the file data into shards of fixed size, and encrypts or decrypts each shard to reduce memory usage; the metadata encryption mechanism uses a symmetric encryption algorithm to encrypt directory structure information (such as file name, file path) through the encryption interface defined in the file, and generates a unique encryption identifier to maintain the encryption state during storage and reading; the on-demand decryption mechanism combines the data conversion management module and the shard encryption mechanism to read the location and content of the corresponding shard data, and decrypt the shard data currently being accessed.

5. The file encryption system based on multi-level security protection according to claim 1, characterized in that: The persistent storage layer includes a buffer management module, a data storage management module and an error handling module. The buffer management module implements data cache writing and reading in the file system and optimizes I / O operations. The data storage management module is responsible for writing encrypted data into the underlying file system and ensuring that no unencrypted temporary data is generated during the operation. The error handling module is responsible for recording and managing error information during the operation and providing a detailed error log.

6. A file encryption system based on multi-level security protection according to claim 5, characterized in that: The buffer management module adopts a multi-level cache management strategy. The encryption library provides a set of data buffer operation interfaces for managing the read and write operations of the buffer. The system divides the data buffer into several parts and caches data of different frequencies into the corresponding buffers, giving priority to storing high-frequency access data blocks.

7. A file encryption system based on multi-level security protection according to claim 6, characterized in that: The buffer management module is also provided with a cache clearing mechanism, which, by configuring a security clearing function, clears the plaintext data in the cache immediately after the data is written from the buffer to the file, ensuring that unencrypted data is not stored in the system for a long time.