Data storage method and device, electronic equipment and computer readable medium
By adopting a data warehouse storage structure and independent encryption processing method in the data storage, the problems of low security and low reading efficiency in the prior art are solved, and high security and fast response data storage are realized.
Patent Information
- Application Number
- CN202510132732.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-06
- Publication Date
- 2025-05-30
- Estimated Expiration
- 2045-02-06
AI Technical Summary
In the prior art, when data is stored, all data is concentrated in one encrypted data packet, resulting in the risk of leakage when the encryption key is leaked or cracked, all data faces the risk of leakage, and the reading efficiency is inefficient and the response time is long.
The data warehouse storage structure is adopted to divide the storage data set sent by the target device into multiple independent data warehouse grids, and unique storage warehouse location information and encryption information are generated for each data warehouse grid, and encryption processing and storage are carried out by storing mapping relationship data.
Improves the security of data storage, reduces the response time of data acquisition, prevents data leakage caused by leakage of a single encryption key, and improves reading efficiency.
Smart Images

Figure CN120068147A_ABST
Abstract
Description
Technical Field
[0001] Embodiments of the present disclosure relate to the field of computer technologies, and more particularly, to data storage methods, apparatuses, electronic devices, and computer-readable media. Background Art
[0002] Data storage is a technology for storing data sent by a target device. Currently, when storing data sent by a target device, the commonly adopted method is to directly encapsulate the data set sent by the target device into an encrypted data packet for storage.
[0003] However, when storing the data set sent by the target device in the above manner, the following technical problems often exist:
[0004] Directly encapsulating the data set sent by the target device into an encrypted data packet for storage, all the data is concentrated in one encrypted data packet. Once the encryption key of this data packet is leaked or cracked, all the data will face the risk of leakage, and the security of data storage is relatively low. At the same time, when the target device reads one piece of data in the data set, it is necessary to decrypt the entire data packet first, and then search for the required data in the entire data packet, resulting in low reading efficiency and a long data acquisition response time.
[0005] The above information disclosed in this background art section is only used to enhance the understanding of the background of the inventive concept, and thus, it may include information that does not constitute the prior art known to those of ordinary skill in the art. Summary of the Invention
[0006] The content part of the present disclosure is used to introduce the concepts in a brief form, and these concepts will be described in detail in the following detailed implementation part. The content part of the present disclosure is not intended to identify the key features or essential features of the claimed technical solution, nor is it intended to limit the scope of the claimed technical solution.
[0007] Some embodiments of the present disclosure propose data storage methods, apparatuses, electronic devices, and computer-readable media to solve one or more of the technical problems mentioned in the above background art section.
[0008] In a first aspect, some embodiments of the present disclosure provide a data storage method, the method comprising: creating a data cell storage structure; in response to receiving storage request information sent by a target device, determining the storage request information as to-be-processed storage request information, wherein the to-be-processed storage request information includes a storage data set and a storage data identifier set, and each storage data in the storage data set corresponds one-to-one to each storage data identifier in the storage data identifier set; for each storage data in the storage data set included in the to-be-processed storage request information, performing the following storage steps: determining the storage data identifier corresponding to the storage data; generating storage cell location information corresponding to the storage data based on the storage data identifier; generating encryption information corresponding to the storage data based on a preset encryption information library; generating storage mapping relation data based on the encryption information, the storage data identifier, and the storage cell location information; storing the storage mapping relation data into a preset storage mapping relation table to update the preset storage mapping relation table; encrypting the storage data based on the encryption information to obtain encrypted storage data; storing the encrypted storage data into a data cell in the data cell storage structure based on the storage cell location information; encrypting the updated preset storage mapping relation table to obtain an encrypted preset storage mapping relation table.
[0009] In a second aspect, some embodiments of the present disclosure provide a data storage device, the device comprising: a creating unit configured to create a data cell storage structure; a determining unit configured to, in response to receiving storage request information sent by a target device, determine the storage request information as to-be-processed storage request information, wherein the to-be-processed storage request information includes a storage data set and a storage data identifier set, and each storage data in the storage data set corresponds one-to-one to each storage data identifier in the storage data identifier set; a storing unit configured to, for each storage data in the storage data set included in the to-be-processed storage request information, perform the following storage steps: determining the storage data identifier corresponding to the storage data; generating storage cell location information corresponding to the storage data based on the storage data identifier; generating encryption information corresponding to the storage data based on a preset encryption information library; generating storage mapping relation data based on the encryption information, the storage data identifier, and the storage cell location information; storing the storage mapping relation data into a preset storage mapping relation table to update the preset storage mapping relation table; encrypting the storage data based on the encryption information to obtain encrypted storage data; storing the encrypted storage data into a data cell in the data cell storage structure based on the storage cell location information; an encrypting unit configured to encrypt the updated preset storage mapping relation table to obtain an encrypted preset storage mapping relation table.
[0010] In a third aspect, some embodiments of the present disclosure provide an electronic device, including: one or more processors; a storage device storing one or more programs thereon, and when the one or more programs are executed by the one or more processors, the one or more processors implement the method described in any implementation manner of the above first aspect.
[0011] In a fourth aspect, some embodiments of the present disclosure provide a computer-readable medium storing a computer program thereon, wherein when the program is executed by a processor, the method described in any implementation manner of the above first aspect is implemented.
[0012] The above-mentioned various embodiments of the present disclosure have the following beneficial effects: Through the data storage method of some embodiments of the present disclosure, the security of data storage is improved and the response time for data acquisition is reduced. Specifically, the reasons for the poor security of data storage and the long response time for data acquisition are as follows: The data set sent by the target device is directly encapsulated into an encrypted data packet for storage, and all data is concentrated in one encrypted data packet. Once the encryption key of this data packet is leaked or cracked, all data will face the risk of leakage, and the security of data storage is relatively low. At the same time, when the target device reads a piece of data in the data set, it needs to decrypt the entire data packet first and then search for the required data in the entire data packet, resulting in low reading efficiency and a long response time for data acquisition. Based on this, in the data storage method of some embodiments of the present disclosure, first, a data grid storage structure is created. Thus, a storage data set sent by the target device can be created for storage. Then, in response to receiving the storage request information sent by the target device, the above-mentioned storage request information is determined as the to-be-processed storage request information, where the above-mentioned to-be-processed storage request information includes a storage data set and a storage data identifier set, and each storage data in the above-mentioned storage data set corresponds one-to-one with each storage data identifier in the above-mentioned storage data identifier set. Next, for each storage data in the storage data set included in the above-mentioned to-be-processed storage request information, the following storage steps are executed: The first step is to determine the storage data identifier corresponding to the above-mentioned storage data. Thus, the storage data identifier of the storage data can be determined. The second step is to generate the storage grid position information corresponding to the above-mentioned storage data based on the above-mentioned storage data identifier. Thus, the storage grid position information for storing the above-mentioned storage data can be generated. The third step is to generate the encryption information corresponding to the above-mentioned storage data based on a preset encryption information library. Thus, the encryption information for encrypting the storage data can be obtained. The fourth step is to generate storage mapping relationship data based on the above-mentioned encryption information, the above-mentioned storage data identifier, and the above-mentioned storage grid position information. Thus, the storage mapping relationship data representing the corresponding relationship between the above-mentioned encryption information, the above-mentioned storage data identifier, and the storage grid position information can be generated. The fifth step is to store the above-mentioned storage mapping relationship data in a preset storage mapping relationship table to update the above-mentioned preset storage mapping relationship table. Thus, the storage mapping relationship data can be stored in the preset storage mapping relationship table. The sixth step is to encrypt the above-mentioned storage data based on the above-mentioned encryption information to obtain encrypted storage data. Thus, the storage data can be encrypted separately. Based on the above-mentioned storage grid position information, the above-mentioned encrypted storage data is stored in a data grid in the above-mentioned data grid storage structure. Thus, the encrypted storage data can be stored in a data grid in the data grid storage structure.Even if the encrypted storage data in some of the data cells in the data cell storage structure is cracked or leaked, since the stored data is encrypted separately and stored in different data cells, the data in other cells except for the data stored in the cracked or leaked cell can still be protected, improving the security of data storage. Encrypt the updated preset storage mapping relation table to obtain an encrypted preset storage mapping relation table. Thus, the preset storage mapping relation table containing the storage mapping relation data of each storage data in the storage dataset can be encrypted. Also, because when storing each storage data in the storage dataset, the storage data is encrypted separately and the separately encrypted storage data is stored in a data cell in the data cell storage structure. Even if the encrypted storage data in some of the data cells in the data cell storage structure is cracked or leaked, the data in other cells can still be protected, improving the security of data storage. At the same time, storing the storage data in a data cell in the data cell storage structure can quickly locate the cell where the data to be read is located according to the read request, and only read the required data, improving the read efficiency and reducing the data acquisition response time. BRIEF DESCRIPTION OF THE DRAWINGS
[0013] In conjunction with the accompanying drawings and with reference to the following detailed description, the above and other features, advantages, and aspects of the embodiments of the present disclosure will become more apparent. Throughout the drawings, the same or similar reference numerals denote the same or similar elements. It should be understood that the drawings are schematic and the elements and elements are not necessarily drawn to scale.
[0014] Figure 1 is a flowchart of some embodiments of a data storage method according to the present disclosure;
[0015] Figure 2 is a schematic structural diagram of some embodiments of a data storage device according to the present disclosure;
[0016] Figure 3 is a schematic structural diagram of an electronic device suitable for implementing some embodiments of the present disclosure;
[0017] Figure 4 is a schematic structural diagram of some embodiments of a data cell storage structure according to the present disclosure. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0018] Embodiments of the present disclosure will be described in more detail below with reference to the accompanying drawings. Although some embodiments of the present disclosure are shown in the drawings, it should be understood that the present disclosure can be implemented in various forms and should not be construed as limited to the embodiments set forth herein. On the contrary, these embodiments are provided to more thoroughly and completely understand the present disclosure. It should be understood that the drawings and embodiments of the present disclosure are only for exemplary purposes and are not used to limit the protection scope of the present disclosure.
[0019] It should also be noted that, for the sake of convenience of description, only parts related to the relevant invention are shown in the drawings. Without conflict, the embodiments in the present disclosure and the features in the embodiments can be combined with each other.
[0020] It should be noted that the concepts such as "first" and "second" mentioned in the present disclosure are only used to distinguish different devices, modules or units, and are not used to limit the order of functions performed by these devices, modules or units or their interdependent relationships.
[0021] It should be noted that the modification of "one" and "multiple" mentioned in the present disclosure is illustrative rather than restrictive. Those skilled in the art should understand that, unless otherwise clearly specified in the context, it should be understood as "one or more".
[0022] The names of the messages or information exchanged between multiple devices in the embodiments of the present disclosure are only for illustrative purposes and are not used to limit the scope of these messages or information.
[0023] The present disclosure will be described in detail below with reference to the drawings and in combination with embodiments.
[0024] Figure 1 Flow 100 of some embodiments of the data storage method according to the present disclosure is shown. The data storage method includes the following steps:
[0025] Step 101, create a data grid storage structure.
[0026] In some embodiments, the execution subject of the data storage method (for example, a SAN storage device) can create a data grid storage structure. Among them, the above execution subject can be a storage device for storing data sent by a storage target device (for example, a SAN storage device, a storage server). The above target device can be a client device (for example, a client computer device (such as a personal computer, a server), a mobile terminal device (such as a smart phone, a tablet computer, etc.)).
[0027] In some optional implementation manners of some embodiments, the above execution subject can create a data grid storage structure through the following steps:
[0028] Step 1: Obtain data storage requirement information. In practice, the above-mentioned execution entity can obtain the data storage requirement information from the above-mentioned target device through a wired connection method or a wireless connection method. Among them, the above-mentioned storage requirement information can be the amount information of the stored data. The above-mentioned storage requirement information includes the quantity of the stored data and the maximum data volume. The quantity of the above-mentioned stored data can be the quantity of the stored data in the storage data set sent by the target device. The above-mentioned maximum data volume can be the data volume of the stored data with the largest data volume in the storage data set (for example, 500MB).
[0029] It should be noted that the above-mentioned wireless connection method can include, but is not limited to, 3G / 4G connection, WiFi connection, Bluetooth connection, WiMAX connection, Zigbee connection, UWB (ultra wideband) connection, and other currently known or future-developed wireless connection methods.
[0030] Step 2: Based on the above-mentioned storage requirement information, create a data cell storage structure. In practice, the above-mentioned execution entity can determine the quantity of the stored data included in the above-mentioned storage requirement information as the target quantity. Then, the above-mentioned execution entity can query the preset relationship table to determine the cell storage structure information corresponding to the above-mentioned target quantity as the target cell storage structure information. After that, the above-mentioned execution entity can determine the maximum data volume included in the storage requirement information as the target data volume. Finally, the above-mentioned execution entity can execute the task corresponding to the preset creation task information, use the structure corresponding to the above-mentioned target cell storage structure information as the creation structure, and use the above-mentioned target data volume as the size of the data cell to create a data cell storage structure. Among them, the above-mentioned target cell storage structure information can represent the cell storage structure (for example, the cell storage structure includes three layers, each layer includes 5 columns, and each column includes 4 data cells). Figure 4 is a schematic structural diagram of some embodiments of the data cell storage structure according to the present disclosure. As Figure 4 shown, the above-mentioned data cell storage structure includes each data cell layer, each data cell layer in the above-mentioned each data cell layer includes each data cell column, and each data cell column in the above-mentioned each data cell column includes each data cell. Figure 4 N in the above can represent a column identifier or a serial number identifier. Each data cell in the above-mentioned each data cell can be a storage unit (for example, a logical storage unit) with a storage size of the above-mentioned target data volume. Each data cell column in the above-mentioned each data cell column can be each horizontal data cell column or each vertical data cell column, which is not limited here. The above-mentioned preset creation task information can be programming language code pre-written by a developer for creating a data cell storage structure with the structure corresponding to the above-mentioned target cell storage structure information as the creation structure and the above-mentioned target data volume as the size of the data cell.
[0031] Step 102: In response to receiving the storage request information sent by the target device, determine the storage request information as the to-be-processed storage request information.
[0032] In some embodiments, the above-mentioned execution entity may, in response to receiving the storage request information sent by the target device, determine the above-mentioned storage request information as the to-be-processed storage request information. Among them, the above-mentioned to-be-processed storage request information includes a storage data set and a storage data identifier set, and each storage data in the above-mentioned storage data set corresponds one-to-one with each storage data identifier in the above-mentioned storage data identifier set. The above-mentioned storage data identifier may be the name or number of the storage data. For example, the above-mentioned storage data identifier may be "D12345". Each storage data in the above-mentioned storage data set may include, but is not limited to, one of the following: text data, audio data, image data, video data.
[0033] Step 103: For each storage data in the storage data set included in the to-be-processed storage request information, perform the following storage steps:
[0034] Step 1031: Determine the storage data identifier corresponding to the storage data.
[0035] In some embodiments, the above-mentioned execution entity may determine the storage data identifier corresponding to the above-mentioned storage data. In practice, the above-mentioned execution entity may determine the storage data identifier corresponding to the above-mentioned storage data from the above-mentioned storage data identifier set.
[0036] Step 1032: Based on the storage data identifier, generate the storage bin location information corresponding to the storage data.
[0037] In some embodiments, the above-mentioned execution entity may generate the storage bin location information corresponding to the above-mentioned storage data based on the above-mentioned storage data identifier.
[0038] In some optional implementation manners of some embodiments, the above-mentioned execution entity may generate the storage bin location information corresponding to the above-mentioned storage data based on the above-mentioned storage data identifier through the following steps:
[0039] The first step: Perform a hash operation on the above-mentioned storage data identifier to obtain the hash value corresponding to the above-mentioned storage data identifier. In practice, the above-mentioned execution entity may perform a hash operation on the above-mentioned storage data identifier through a preset hash function to obtain the hash value corresponding to the above-mentioned storage data identifier.
[0040] The second step: Determine the number of data bin layers of each data bin layer included in the above-mentioned data bin storage structure as the first target number. Among them, each data bin layer in the above-mentioned each data bin layer has a corresponding layer identifier. For example, the above-mentioned layer identifier may be "Layer 1".
[0041] Step 3: Generate a target layer identifier based on the above hash value and the above first target quantity. In practice, the above execution entity may determine the above hash value as the first target hash value. Then, based on the first target hash value, perform the following first determination step: First, determine the remainder obtained by dividing the first target hash value by the first target quantity as the initial layer identifier. Then, the above execution entity may traverse each data bin included in the data bin layer corresponding to the initial layer identifier. In response to determining that at least one data bin among the above data bins stores a random number or at least one data bin does not store data, the above execution entity may determine the initial layer identifier as the target layer identifier. In response to determining that there is no data bin storing a random number and no data bin not storing data among the above data bins, the above execution entity may update the sum of the first target hash value and a preset value (for example, 1) as the first target hash value. Then, the execution entity may perform the above first determination step again based on the updated first target hash value. Among them, the above random number may be a pre-generated random number with a preset length.
[0042] Step 4: Determine the data bin layer corresponding to the above target layer identifier among the above data bin layers as the target data bin layer.
[0043] Step 5: Determine the quantity of each data bin column included in the above target data bin layer as the second target quantity. Among them, each data bin column in the above data bin columns corresponds to a column identifier. For example, the above column identifier may be "Column 01".
[0044] Step 6: Generate a target column identifier based on the above hash value and the above second target quantity. In practice, the above execution entity may determine the above hash value as the second target hash value. Then, based on the second target hash value, perform the following second determination step: First, determine the remainder obtained by dividing the second target hash value by the second target quantity as the initial column identifier. Then, the above execution entity may traverse each data bin included in the data bin column corresponding to the initial column identifier. In response to determining that at least one data bin among the above data bins stores a random number or at least one data bin does not store data, the above execution entity may determine the initial column identifier as the target column identifier. In response to determining that there is no data bin storing a random number and no data bin not storing data among the above data bins, the above execution entity may update the sum of the second target hash value and a preset value (for example, 1) as the second target hash value. Then, the execution entity may perform the above second determination step again based on the updated second target hash value.
[0045] Step 7: Determine the data bin column corresponding to the above target column identifier among the above data bin columns as the target data bin column.
[0046] In the eighth step, determine the number of data cells included in each data cell of the above-mentioned target data cell column as the third target number. Each data cell in the above-mentioned respective data cells corresponds to a serial number identifier of the data cell in the above-mentioned target data cell column. For example, the serial number identifier can be "the 02nd in the column".
[0047] In the ninth step, generate a target serial number identifier based on the above hash value and the above third target number. In practice, the above-mentioned execution entity can determine the above hash value as the third target hash value. Then, based on the third target hash value, perform the following third determination step: First, determine the remainder obtained by dividing the third target hash value by the third target number as the initial serial number identifier. Then, the execution entity can traverse the data cell corresponding to the initial serial number identifier in the target data cell column. In response to determining that the data cell stores a random number or the data cell does not store data, the above-mentioned execution entity can determine the initial serial number identifier as the target serial number identifier. In response to determining that the data cell does not store a random number and stores data, the above-mentioned execution entity can update the sum of the third target hash value and a preset value (for example, 1) as the third target hash value. Then, the execution entity can, based on the updated third target hash value, perform the above third determination step again.
[0048] In the tenth step, determine the above-mentioned target layer identifier, the above-mentioned target column identifier, and the above-mentioned target serial number identifier as the storage cell position information corresponding to the above-mentioned stored data.
[0049] Step 1033, generate encryption information corresponding to the stored data based on a preset encryption information library.
[0050] In some embodiments, the above-mentioned execution entity can generate encryption information corresponding to the above-mentioned stored data based on a preset encryption information library. In practice, the above-mentioned execution entity can randomly select an encryption information from the above encryption information library as the encryption information corresponding to the above-mentioned stored data. The above preset encryption information library can be a database storing various encryption information. Each of the above various encryption information can represent an encryption algorithm for converting plaintext into ciphertext.
[0051] Step 1034, generate storage mapping relationship data based on the encryption information, the stored data identifier, and the storage cell position information.
[0052] In some embodiments, the above-mentioned execution entity can generate storage mapping relationship data based on the above encryption information, the above stored data identifier, and the above storage cell position information.
[0053] In some optional implementation manners of some embodiments, the above-mentioned execution entity can generate storage mapping relationship data based on the above encryption information, the above stored data identifier, and the above storage cell position information through the following steps:
[0054] Step 1: Create the mapping relationship dictionary structure information. Among them, the above mapping relationship dictionary structure information can represent a dictionary storing encrypted information, storage data identifiers, and storage bin location information, as well as the corresponding relationships among the three.
[0055] Step 2: Determine one of the above storage data identifiers or the above storage bin location information as the key to be inserted.
[0056] Step 4: In response to determining that the above storage data identifier is the key to be inserted, perform the following steps:
[0057] The first sub-step: Store the encrypted information and the storage bin location information into a preset two-dimensional array, and determine the preset two-dimensional array storing the encrypted information and the storage bin location information as the value to be inserted corresponding to the key to be inserted.
[0058] The second sub-step: Store the key to be inserted and the value to be inserted into the data structure corresponding to the mapping relationship dictionary structure information to obtain the stored mapping relationship data.
[0059] Step 5: In response to determining that the above storage bin location information is the key to be inserted, perform the following steps:
[0060] The first sub-step: Store the encrypted information and the storage data identifier into a preset two-dimensional array, and determine the preset two-dimensional array storing the encrypted information and the storage bin location information as the value to be inserted corresponding to the key to be inserted.
[0061] The second sub-step: Store the key to be inserted and the value to be inserted into the data structure corresponding to the mapping relationship dictionary structure information to obtain the stored mapping relationship data. Among them, the above stored mapping relationship data can be a dictionary containing encrypted information, storage data identifiers, and storage bin location information.
[0062] Step 1035: Store the stored mapping relationship data into a preset stored mapping relationship table to update the preset stored mapping relationship table.
[0063] In some embodiments, the above execution entity can store the above stored mapping relationship data into a preset stored mapping relationship table to update the above preset stored mapping relationship table. Among them, the above preset stored mapping relationship table can be a data table recording the stored mapping relationship data.
[0064] Step 1036: Based on the encrypted information, perform an encryption process on the stored data to obtain encrypted stored data.
[0065] In some embodiments, the above-mentioned execution entity may encrypt the above-mentioned stored data based on the above-mentioned encryption information to obtain encrypted stored data. In practice, the above-mentioned execution entity may encrypt the above-mentioned stored data with the encryption information and a preset public key to obtain encrypted stored data. Wherein, the above-mentioned encrypted stored data may be the data obtained by encrypting the stored data.
[0066] Step 1037: Store the encrypted stored data into a data bin in the data bin storage structure based on the storage bin location information.
[0067] In some embodiments, the above-mentioned execution entity may store the above-mentioned encrypted stored data into a data bin in the above-mentioned data bin storage structure based on the above-mentioned storage bin location information.
[0068] In some alternative implementation manners of some embodiments, the above-mentioned execution entity may store the above-mentioned encrypted stored data into a data bin in the above-mentioned data bin storage structure based on the above-mentioned storage bin location information through the following steps:
[0069] First step: Determine the data bin corresponding to the above-mentioned storage bin location information in the data bin storage structure as the target data bin.
[0070] Second step: Empty the above-mentioned target data bin, and store the above-mentioned encrypted stored data into the emptied target data bin.
[0071] Third step: Determine each data bin in the above-mentioned data bin storage structure that does not store data as each obfuscation data bin.
[0072] Third step: For each obfuscation data bin among the above-mentioned obfuscation data bins, store the pre-generated obfuscation data into the above-mentioned obfuscation data bin. Wherein, the above-mentioned obfuscation data may be a randomly generated number with a preset length pre-generated.
[0073] Step 104: Encrypt the updated preset storage mapping relation table to obtain an encrypted preset storage mapping relation table.
[0074] In some embodiments, the above-mentioned execution entity may encrypt the updated preset storage mapping relation table to obtain an encrypted preset storage mapping relation table. In practice, the above-mentioned execution entity may encrypt the above-mentioned preset storage mapping relation table with a preset encryption algorithm to obtain an encrypted preset storage mapping relation table. For example, the above-mentioned preset encryption algorithm may be, but is not limited to, one of the following: RSA algorithm, ECC algorithm.
[0075] In the process of adopting technical solutions to solve the problems mentioned in the background art, the following problems often accompany:
[0076] After storing the stored data set sent by the target device in the data bin storage structure, a visualization graph of the correspondence between the stored data and the storage location is not generated. Users cannot know the storage location of the stored data and are unclear about the storage structure and layout. When users need to access the data, they can only access it through the data identifier at the time of storage. When users forget the data identifier, they will be unable to access the stored data, resulting in a poor user experience.
[0077] In the face of the above technical problems, the inventor decided to adopt the following solutions:
[0078] In some optional implementation manners of some embodiments, after encrypting the updated preset storage mapping relationship table to obtain the encrypted preset storage mapping relationship table, the above execution subject may further perform the following steps:
[0079] First step, based on the above preset storage mapping relationship table, generate a visualization data storage mapping graph. In practice, for each storage mapping relationship data in the above preset storage mapping relationship table, the above execution subject may determine the storage data identifier and the storage bin location information included in the above storage mapping relationship data as mapping nodes to obtain a mapping node group. After that, the above execution subject may generate a visualization data storage mapping graph by calling a preset graph theory library (for example, the NetworkX graph theory library) based on the obtained mapping node groups. The above visualization data storage mapping graph may represent a bipartite graph of the one-to-one correspondence between each storage data identifier and each storage bin location information in each storage mapping relationship data.
[0080] Second step, send the above visualization data storage mapping graph to the above target device.
[0081] Third step, in response to receiving the data acquisition information sent by the above target device, perform a decryption operation on the encrypted preset storage mapping relationship table to obtain the preset storage mapping relationship table. Wherein, the above data acquisition information includes a storage data identifier or a storage bin location information.
[0082] Fourth step, in response to determining that the data acquisition information includes a storage data identifier, perform the following steps:
[0083] First sub-step, determine the storage data identifier included in the above data acquisition information as the data identifier to be queried.
[0084] Second sub-step, query the storage mapping relationship data including the above data identifier to be queried from the above preset storage mapping relationship table, and determine the queried storage mapping relationship data including the above data identifier to be queried as the target storage mapping relationship data.
[0085] The third sub-step is to determine the storage bin location information included in the above target storage mapping relationship data as the target storage bin location information.
[0086] In the fifth step, in response to determining that the data acquisition information includes storage bin location information, the above storage bin location information is determined as the target storage bin location information, and the storage mapping relationship data including the above storage bin location information is queried from the above preset storage mapping relationship table as the target storage mapping relationship data.
[0087] In the sixth step, storage data is obtained as the storage data to be decrypted from the storage location corresponding to the target storage bin location information in the above data bin storage structure.
[0088] In the seventh step, the encryption information included in the above target storage mapping relationship data and the above storage data to be decrypted are sent to the above target device.
[0089] The above technical solution and its related content, as an inventive point of the embodiments of the present disclosure, solve the technical problem of "poor user experience". The factors that lead to a poor user experience are often as follows: After storing the storage data set sent by the target device into the data grid storage structure, a visualization graph of the correspondence between the stored data and the storage location is not generated. Users cannot know the storage location of the data set and are unclear about the storage structure and layout. When users need to access the data, they can only access it through the data identifier during storage. When users forget the data identifier, they will be unable to access the stored data, resulting in a poor user experience. If the above factors are solved, the effect of improving the user experience can be achieved. To achieve this effect, first, based on the above preset storage mapping relationship table, a visualization data storage mapping graph is generated. Thus, a visualization graph of the correspondence between the stored data and the storage location can be generated. The above visualization data storage mapping graph is sent to the above target device. Thus, a visualization graph representing the one-to-one correspondence between the stored data and the storage location can be sent to the target device for users to understand the storage location of the stored data in the data grid storage structure. Then, in response to receiving the data acquisition information sent by the above target device, a decryption operation is performed on the encrypted preset storage mapping relationship table to obtain the preset storage mapping relationship table, where the above data acquisition information includes the stored data identifier or the storage grid location information. Thus, when receiving the data acquisition information sent by the target device, the encrypted preset storage mapping relationship table can be decrypted to obtain the preset storage mapping relationship table for determining the storage mapping relationship data containing the data identifier to be queried. Next, in response to determining that the data acquisition information includes the stored data identifier, the following steps are performed: First step, determine the stored data identifier included in the above data acquisition information as the data identifier to be queried. Second step, query the storage mapping relationship data containing the above data identifier to be queried from the above preset storage mapping relationship table, and determine the queried storage mapping relationship data containing the above data identifier to be queried as the target storage mapping relationship data. Thus, the target storage mapping relationship data for determining the target storage grid location information can be obtained. Third step, determine the storage grid location information included in the above target storage mapping relationship data as the target storage grid location information. Thus, through the above steps, in the case where the data acquisition information includes the stored data identifier, the storage location of the stored data (i.e., the target storage grid location information) can be determined by the stored data identifier. Then, in response to determining that the data acquisition information includes the storage grid location information, determine the above storage grid location information as the target storage grid location information, and query the storage mapping relationship data containing the above storage grid location information from the above preset storage mapping relationship table as the target storage mapping relationship data. Thus, in the case where the acquisition information includes the storage grid location information, the target storage mapping relationship data of the acquired stored data can be determined.Next, obtain the stored data from the storage location corresponding to the target storage bin location information in the above data bin storage structure as the stored data to be decrypted. Thus, the stored data to be decrypted stored at the storage location corresponding to the target storage bin location information can be obtained. Finally, send the encryption information included in the above target storage mapping relationship data and the above stored data to be decrypted to the above target device. Thus, the encryption information and the above stored data to be decrypted can be sent to the user's target device. Also, because after storing the storage data set sent by the target device into the data bin storage structure, a visualization graph representing the one-to-one correspondence between the stored data and the storage location is generated and sent to the target device for the user to understand the storage location of the stored data in the data bin storage structure. When the user forgets the data identifier, the visualization data storage mapping graph can help the user understand the detailed information of the previously stored storage data set (the identifiers of each stored data, the one-to-one correspondence between the stored data and the storage location). At the same time, when the user accesses the stored data, they can not only access it through the stored data identifier, but also access the stored data through the storage bin location information, improving the user experience.
[0090] In some optional implementation manners of some embodiments, the above execution subject may send the above visualization data storage mapping graph to the above target device through the following steps:
[0091] In the first step, obtain the preset encryption algorithm information and key information from the preset database. Among them, the above preset encryption algorithm information includes: extended algorithm information, round function information. The above extended algorithm information may represent a key expansion algorithm. For example, the above extended algorithm information may represent the key expansion algorithm of AES. The above round function information may represent the round function corresponding to the above extended algorithm information for confusing and transforming the data to be encrypted. The above preset database may be a MySQL database.
[0092] In the second step, generate a sequence of round key information corresponding to the above key information according to the extended algorithm information and key information included in the above encryption algorithm information. In practice, the above execution subject may expand the key corresponding to the key information by executing the key expansion algorithm corresponding to the extended algorithm information to obtain the sequence of round key information. Among them, the above key information may represent a preset initial key. The above initial key may include each character. One round key information in the above sequence of round key information may represent a round key. The above round key may be each character. For example, the above round key information may be "0b01100101".
[0093] In the third step, determine the above visualization data storage mapping graph as the data to be encrypted.
[0094] Step 4: According to the first round key information in the round key information sequence and the data to be encrypted, perform the following round key encryption process:
[0095] The first sub-step: According to the round function information included in the encryption algorithm information and the first round key information, encrypt the data to be encrypted to obtain an encrypted visual data storage mapping diagram. Among them, the above-mentioned round function information can represent the round function. In practice, the above-mentioned execution entity can convert the above-mentioned data to be encrypted into byte data. Then, the above-mentioned execution entity can input the above-mentioned byte data and the round key corresponding to the above-mentioned first round key information into the above-mentioned round function to obtain an encrypted visual data storage mapping diagram.
[0096] The second sub-step: Remove the first round key information from the round key information sequence to update the round key information sequence.
[0097] The third sub-step: In response to determining that the round key information sequence is not empty, perform the following steps:
[0098] Sub-step 1: Determine the encrypted visual data storage mapping diagram as the data to be encrypted to update the data to be encrypted.
[0099] Sub-step 2: According to the updated round key information sequence and the updated data to be encrypted, perform the above-mentioned round key encryption process again.
[0100] The fourth sub-step: In response to determining that the round key information sequence is empty, send the obtained encrypted visual data storage mapping diagram to the above-mentioned target device.
[0101] The above technical solution and its related content, as an inventive point of an embodiment of the present disclosure, solve the technical problem that "the visual data storage mapping diagram contains sensitive data such as the storage data identifier and the storage bin location information when the user stores data. Directly sending the visual data storage mapping diagram to the target device without encrypting the visual data storage mapping diagram easily causes the leakage of sensitive data such as the storage data identifier and the storage bin location information of the user's previously stored data, resulting in relatively low security of information transmission during the transmission of the visual data storage mapping diagram". The factors that result in relatively low security of information transmission during the transmission of the visual data storage mapping diagram are often as follows: sensitive data such as the storage data identifier and the storage bin location information when storing data. Directly sending the visual data storage mapping diagram to the target device without encrypting the visual data storage mapping diagram easily causes the leakage of sensitive data such as the storage data identifier and the storage bin location information of the user's previously stored data, resulting in relatively low security of information transmission during the transmission of the visual data storage mapping diagram. If the above factors are solved, the security of the transmission of the visual data storage mapping diagram can be improved. To achieve this effect, first, obtain preset encryption algorithm information and key information from a preset database, where the above preset encryption algorithm information includes: expansion algorithm information, round function information. Thus, the preset encryption algorithm information and key information can be obtained. Then, according to the expansion algorithm information and key information included in the above encryption algorithm information, generate a round key information sequence corresponding to the above key information. Thus, a round key information sequence for round key encryption processing can be obtained. After that, determine the above visual data storage mapping diagram as the data to be encrypted. Then, according to the first round key information in the round key information sequence and the data to be encrypted, perform the following round key encryption processing: First step, encrypt the data to be encrypted according to the round function information and the first round key information included in the encryption algorithm information to obtain an encrypted visual data storage mapping diagram. Thus, the first round of encryption can be performed on the data to be encrypted. Second step, remove the first round key information from the round key information sequence to update the round key information sequence. Third step, in response to determining that the round key information sequence is not empty, perform the following steps: First sub-step, determine the encrypted visual data storage mapping diagram as the data to be encrypted to update the data to be encrypted. Thus, the data to be encrypted can be updated. Second sub-step, according to the updated round key information sequence and the updated data to be encrypted, perform the above round key encryption processing again. Fourth step, in response to determining that the round key information sequence is empty, send the obtained encrypted visual data storage mapping diagram to the above target device. Thus, the encrypted visual data storage mapping diagram can be sent to the target device.Also, by encrypting the visual data storage mapping diagram to obtain an encrypted visual data storage mapping diagram, the possibility of leakage of sensitive data such as the storage data identifier and the storage bin location information of the storage data previously stored by the user is reduced. The security of the transmission of the visual data storage mapping diagram during the transmission of the visual data storage mapping diagram is improved.
[0102] The above-mentioned various embodiments of the present disclosure have the following beneficial effects: Through the data storage method of some embodiments of the present disclosure, the security of data storage is improved and the response time for data acquisition is reduced. Specifically, the reasons for the poor security of data storage and the long response time for data acquisition are as follows: The data set sent by the target device is directly encapsulated into an encrypted data packet for storage, and all the data is concentrated in one encrypted data packet. Once the encryption key of this data packet is leaked or cracked, all the data will face the risk of leakage, and the security of data storage is low. At the same time, when the target device reads a piece of data in the data set, it is necessary to first decrypt the entire data packet and then search for the required data in the entire data packet, resulting in low reading efficiency and a long response time for data acquisition. Based on this, in the data storage method of some embodiments of the present disclosure, first, a data bin storage structure is created. Thus, a storage data set sent by the target device can be created for storage. Then, in response to receiving the storage request information sent by the target device, the above storage request information is determined as the to-be-processed storage request information, where the above to-be-processed storage request information includes a storage data set and a storage data identifier set, and each storage data in the above storage data set corresponds one-to-one with each storage data identifier in the above storage data identifier set. Next, for each storage data in the storage data set included in the above to-be-processed storage request information, the following storage steps are executed: The first step is to determine the storage data identifier corresponding to the above storage data. Thus, the storage data identifier of the storage data can be determined. The second step is to generate the storage bin location information corresponding to the above storage data based on the above storage data identifier. Thus, the storage bin location information for storing the above storage data can be generated. The third step is to generate the encryption information corresponding to the above storage data based on a preset encryption information library. Thus, the encryption information for encrypting the storage data can be obtained. The fourth step is to generate storage mapping relationship data based on the above encryption information, the above storage data identifier, and the above storage bin location information. Thus, the storage mapping relationship data representing the corresponding relationship between the above encryption information, the above storage data identifier, and the storage bin location information can be generated. The fifth step is to store the above storage mapping relationship data into a preset storage mapping relationship table to update the above preset storage mapping relationship table. Thus, the storage mapping relationship data can be stored into the preset storage mapping relationship table. The sixth step is to encrypt the above storage data based on the above encryption information to obtain encrypted storage data. Thus, the storage data can be encrypted separately. Based on the above storage bin location information, the above encrypted storage data is stored into a data bin in the above data bin storage structure. Thus, the encrypted storage data can be stored into a data bin in the data bin storage structure.Even if the encrypted storage data in some of the data cells in the data cell storage structure is cracked or leaked, since the storage data is encrypted separately and stored in different data cells, the data in other cells except for the data stored in the cracked or leaked cell can still be protected, improving the security of data storage. Encrypt the updated preset storage mapping relation table to obtain an encrypted preset storage mapping relation table. Thus, the preset storage mapping relation table containing the storage mapping relation data of each storage data in the storage data set can be encrypted. Also, because when storing each storage data in the storage data set, the storage data is encrypted separately and the separately encrypted storage data is stored in a data cell in the data cell storage structure. Even if the encrypted storage data in some of the data cells in the data cell storage structure is cracked or leaked, the data in other cells can still be protected, improving the security of data storage. At the same time, storing the storage data in a data cell in the data cell storage structure can quickly locate the cell where the data to be read is located according to the read request, and only read the required data, improving the read efficiency and reducing the data acquisition response time.
[0103] Further reference is made to Figure 2 , as an implementation of the methods shown in the various figures, the present disclosure provides some embodiments of a data storage device, and these device embodiments correspond to Figure 1 the method embodiments shown, and the device can be specifically applied to various electronic devices.
[0104] As Figure 2As shown, the data storage device 200 of some embodiments includes: a creation unit 201, a determination unit 202, a storage unit 203, and an encryption unit 204. Among them, the creation unit 201 is configured to create a data grid storage structure; the determination unit 202 is configured to, in response to receiving storage request information sent by a target device, determine the storage request information as to-be-processed storage request information, where the to-be-processed storage request information includes a storage data set and a storage data identifier set, and each storage data in the storage data set corresponds one-to-one to each storage data identifier in the storage data identifier set; the storage unit 203 is configured to, for each storage data in the storage data set included in the to-be-processed storage request information, perform the following storage steps: determine the storage data identifier corresponding to the storage data; generate storage grid position information corresponding to the storage data based on the storage data identifier; generate encryption information corresponding to the storage data based on a preset encryption information library; generate storage mapping relationship data based on the encryption information, the storage data identifier, and the storage grid position information; store the storage mapping relationship data into a preset storage mapping relationship table to update the preset storage mapping relationship table; encrypt the storage data based on the encryption information to obtain encrypted storage data; store the encrypted storage data into a data grid in the data grid storage structure based on the storage grid position information; the encryption unit 204 is configured to encrypt the updated preset storage mapping relationship table to obtain an encrypted preset storage mapping relationship table.
[0105] It can be understood that the units described in the device 200 correspond to the respective steps in the method described with reference to Figure 1 above. Therefore, the operations, features, and beneficial effects described above for the method also apply to the device 200 and the units included therein, and will not be elaborated here.
[0106] Next, with reference to Figure 3 , which shows a schematic structural diagram of an electronic device 300 suitable for implementing some embodiments of the present disclosure. Figure 3 The electronic device shown is only an example and should not impose any limitations on the functions and usage scopes of the embodiments of the present disclosure.
[0107] As Figure 3As shown, the electronic device 300 may include a processing device (such as a central processing unit, a graphics processing unit, etc.) 301, which may perform various appropriate actions and processes according to a program stored in a read-only memory (ROM) 302 or a program loaded from a storage device 308 into a random access memory (RAM) 303. In the RAM 303, various programs and data required for the operation of the electronic device 300 are also stored. The processing device 301, the ROM 302, and the RAM 303 are connected to each other via a bus 304. An input / output (I / O) interface 305 is also connected to the bus 304.
[0108] Generally, the following devices may be connected to the I / O interface 305: an input device 306 including, for example, a touch screen, a touchpad, a keyboard, a mouse, a camera, a microphone, an accelerometer, a gyroscope, etc.; an output device 307 including, for example, a liquid crystal display (LCD), a speaker, a vibrator, etc.; a storage device 308 including, for example, a magnetic tape, a hard disk, etc.; and a communication device 309. The communication device 309 may allow the electronic device 300 to communicate with other devices wirelessly or wiredly to exchange data. Although Figure 3 the electronic device 300 with various devices is shown, it should be understood that it is not required to implement or include all the shown devices. Instead, more or fewer devices may be implemented or included. Figure 3 Each block shown in may represent one device or, as needed, multiple devices.
[0109] Specifically, according to some embodiments of the present disclosure, the processes described above with reference to the flowcharts may be implemented as computer software programs. For example, some embodiments of the present disclosure include a computer program product, which includes a computer program carried on a computer-readable medium, and the computer program includes program codes for performing the methods shown in the flowcharts. In such some embodiments, the computer program may be downloaded and installed from a network via the communication device 309, or installed from the storage device 308, or installed from the ROM 302. When the computer program is executed by the processing device 301, the functions defined in the methods of some embodiments of the present disclosure are executed.
[0110] It should be noted that the computer-readable media described in some embodiments of the present disclosure may be a computer-readable signal medium, a computer-readable storage medium, or any combination of the two. A computer-readable storage medium may be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination of the above. More specific examples of the computer-readable storage medium may include, but are not limited to: an electrical connection with one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination thereof. In some embodiments of the present disclosure, the computer-readable storage medium may be any tangible medium that contains or stores a program that can be used by or in conjunction with an instruction execution system, apparatus, or device. In some embodiments of the present disclosure, a computer-readable signal medium may include a data signal propagated in a baseband or as part of a carrier wave, which carries computer-readable program code. Such a propagated data signal may take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination thereof. The computer-readable signal medium may also be any computer-readable medium other than the computer-readable storage medium, which can send, propagate, or transmit a program for use by or in conjunction with an instruction execution system, apparatus, or device. The program code contained on the computer-readable medium may be transmitted using any appropriate medium, including but not limited to: wires, optical cables, RF (radio frequency), etc., or any suitable combination thereof.
[0111] In some embodiments, the client and the server can communicate using any currently known or future-developed network protocol such as HTTP (HyperText Transfer Protocol), and can be interconnected with digital data communication in any form or medium (e.g., a communication network). Examples of communication networks include local area networks ("LANs"), wide area networks ("WANs"), the Internet (e.g., the Internet), and end-to-end networks (e.g., ad hoc end-to-end networks), as well as any currently known or future-developed networks.
[0112] A computer-readable medium may be included in an electronic device or exist separately without being assembled into the electronic device. The computer-readable medium carries one or more programs. When the one or more programs are executed by the electronic device, the electronic device is caused to: create a data cell storage structure; in response to receiving storage request information sent by a target device, determine the storage request information as to-be-processed storage request information, where the to-be-processed storage request information includes a storage data set and a storage data identifier set, and each storage data in the storage data set corresponds one-to-one to each storage data identifier in the storage data identifier set; for each storage data in the storage data set included in the to-be-processed storage request information, perform the following storage steps: determine the storage data identifier corresponding to the storage data; generate storage cell position information corresponding to the storage data based on the storage data identifier; generate encryption information corresponding to the storage data based on a preset encryption information library; generate storage mapping relationship data based on the encryption information, the storage data identifier, and the storage cell position information; store the storage mapping relationship data into a preset storage mapping relationship table to update the preset storage mapping relationship table; encrypt the storage data based on the encryption information to obtain encrypted storage data; store the encrypted storage data into a data cell in the data cell storage structure based on the storage cell position information; encrypt the updated preset storage mapping relationship table to obtain an encrypted preset storage mapping relationship table.
[0113] Computer program code for performing the operations of some embodiments of the present disclosure may be written in one or more programming languages or combinations thereof. The programming languages include object-oriented programming languages such as Java, Smalltalk, C++, and also include conventional procedural programming languages such as the "C" language or similar programming languages. The program code may execute entirely on the user's computer, partially on the user's computer, execute as a stand-alone software package, execute partially on the user's computer and partially on a remote computer, or execute entirely on a remote computer or server. In the case of a remote computer, the remote computer may be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computer (for example, by using an Internet service provider to connect through the Internet).
[0114] The flowcharts and block diagrams in the accompanying drawings illustrate the possible architectures, functions, and operations of systems, methods, and computer program products according to various embodiments of the present disclosure. In this regard, each block in the flowchart or block diagram may represent a module, a segment of a program, or a part of code that contains one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions noted in the blocks may occur in an order different from that noted in the accompanying drawings. For example, two consecutive blocks shown may actually be executed substantially in parallel, and they may sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in the block diagram and / or flowchart, and combinations of blocks in the block diagram and / or flowchart, can be implemented by a dedicated hardware-based system that performs the specified functions or operations, or by a combination of dedicated hardware and computer instructions.
[0115] The units described in some embodiments of the present disclosure can be implemented in software or in hardware. The described units can also be provided in a processor. For example, it can be described as: a processor includes a creation unit, a determination unit, a storage unit, and an encryption unit. Among them, the names of these units do not constitute a limitation to the unit itself in some cases. For example, the creation unit can also be described as "the unit for creating a data grid storage structure".
[0116] The functions described above can be performed at least in part by one or more hardware logic components. For example, without limitation, exemplary types of hardware logic components that can be used include: Field Programmable Gate Arrays (FPGAs), Application Specific Integrated Circuits (ASICs), Application Specific Standard Products (ASSPs), Systems on Chip (SOCs), Complex Programmable Logic Devices (CPLDs), and so on.
[0117] The above description is only some preferred embodiments of the present disclosure and an explanation of the applied technical principles. Those skilled in the art should understand that the scope of the invention involved in the embodiments of the present disclosure is not limited to the technical solutions formed by the specific combination of technical features, and should also cover other technical solutions formed by any combination of technical features or their equivalent features without departing from the inventive concept. For example, technical solutions formed by mutually replacing features with similar functions disclosed in the embodiments of the present disclosure (but not limited to).
Claims
1. A data storage method, comprising: Create a data warehouse storage structure; In response to receiving storage request information sent by the target device, determining the storage request information as pending storage request information, wherein the pending storage request information includes a storage data set and a storage data identification set, and each storage data in the storage data set corresponds to each storage data identification in the storage data identification set in a one-to-one manner; For each storage data in the storage data set included in the storage request information to be processed, the following storage steps are performed: Determining a storage data identifier corresponding to the storage data; Based on the storage data identifier, generating storage bin location information corresponding to the storage data; Based on a preset encryption information library, generating encryption information corresponding to the stored data; Generate storage mapping relationship data based on the encryption information, the storage data identifier and the storage bin location information; Storing the storage mapping relationship data in a preset storage mapping relationship table to update the preset storage mapping relationship table; Based on the encryption information, encrypting the stored data to obtain encrypted stored data; Based on the storage cell location information, storing the encrypted storage data in a data cell in the data cell storage structure; The updated preset storage mapping relationship table is encrypted to obtain an encrypted preset storage mapping relationship table.
2. The method according to claim 1, wherein: The step of creating a data bin storage structure includes: Obtain data storage requirement information; Based on the storage requirement information, a data bin storage structure is created.
3. The method according to claim 1, wherein: The preset encryption information library includes each preset encryption algorithm information; And the step of generating encryption information corresponding to the stored data based on a preset encryption information library includes: Selecting a preset encryption algorithm information from each preset encryption algorithm information included in the preset encryption information library; The selected preset encryption algorithm information is determined as the encryption information.
4. The method according to claim 1, wherein: The storing the encrypted storage data in a data bin in the data bin storage structure based on the storage bin location information includes: Determine a data bin corresponding to the storage bin location information in the data bin storage structure as a target data bin; Clearing the target data bin, and storing the encrypted storage data in the cleared target data bin; Determine each data bin in the data bin storage structure that does not store data as each obfuscated data bin; For each obfuscated data bin in the respective obfuscated data bins, the pre-generated obfuscated data is stored in the obfuscated data bin.
5. The method according to claim 1, wherein: The generating storage mapping relationship data based on the encryption information, the storage data identifier and the storage bin location information includes: Create mapping relationship dictionary structure information; Determine one of the storage data identifier or the storage bin location information as a key to be inserted; In response to determining that the stored data is identified as a key to be inserted, the following steps are performed: Storing the encrypted information and the storage bin location information in a preset two-dimensional array, and determining the preset two-dimensional array storing the encrypted information and the storage bin location information as a value to be inserted corresponding to the key to be inserted; The key to be inserted and the value to be inserted are stored in the data structure corresponding to the mapping relationship dictionary structure information to obtain storage mapping relationship data; In response to determining that the storage bin position information is a key to be inserted, the following steps are performed: Storing the encrypted information and the stored data identifier in a preset two-dimensional array, and determining the preset two-dimensional array storing the encrypted information and the storage bin position information as a value to be inserted corresponding to the key to be inserted; The key to be inserted and the value to be inserted are stored in the data structure corresponding to the mapping relationship dictionary structure information to obtain storage mapping relationship data.
6. The method according to claim 1, wherein: The data bin storage structure includes various data bin layers, each of the various data bin layers includes various data bin columns, and each data bin column includes various data bins; And the step of generating storage bin location information corresponding to the storage data based on the storage data identifier includes: Performing a hash operation on the stored data identifier to obtain a hash value corresponding to the stored data identifier; Determining the number of data bin layers of each data bin layer included in the data bin grid storage structure as a first target number, wherein each data bin layer in the data bin layers has a corresponding layer identifier; Based on the hash value and the first target quantity, a target layer identifier is generated; Determine a data bin layer corresponding to the target layer identifier among the data bin layers as a target data bin layer; Determine the number of data bin grid columns of each data bin grid column included in the target data bin layer as a second target number, wherein each data bin grid column in each data bin grid column corresponds to a column identifier; generating a target column identifier based on the hash value and the second target quantity; Determine the data bin grid column corresponding to the target column identifier among the data bin grid columns as the target data bin grid column; Determine the number of data bins of each data bin included in the target data bin column as a third target number, wherein each of the data bins corresponds to a serial number identifier of the data bin in the target data bin column; Based on the hash value and the third target quantity, generating a target sequence number identifier; The target layer identifier, the target column identifier and the target sequence number identifier are determined as storage bin location information corresponding to the stored data.
7. A data storage device, comprising: A creation unit, configured to create a data bin storage structure; a determining unit configured to, in response to receiving storage request information sent by a target device, determine the storage request information as pending storage request information, wherein the pending storage request information includes a storage data set and a storage data identification set, and each storage data in the storage data set corresponds one-to-one to each storage data identification in the storage data identification set; The storage unit is configured to perform the following storage steps for each storage data in the storage data set included in the storage request information to be processed: determine the storage data identifier corresponding to the storage data; based on the storage data identifier, generate the storage bin location information corresponding to the storage data; based on a preset encryption information library, generate encryption information corresponding to the storage data; based on the encryption information, the storage data identifier and the storage bin location information, generate storage mapping relationship data; store the storage mapping relationship data in a preset storage mapping relationship table to update the preset storage mapping relationship table; based on the encryption information, encrypt the storage data to obtain encrypted storage data; based on the storage bin location information, store the encrypted storage data in a data bin in the data bin storage structure; The encryption unit is configured to encrypt the updated preset storage mapping relationship table to obtain an encrypted preset storage mapping relationship table.
8. An electronic device, comprising: one or more processors; a storage device having one or more programs stored thereon; When the one or more programs are executed by the one or more processors, the one or more processors implement the method according to any one of claims 1 to 6.
9. A computer readable medium having a computer program stored thereon, wherein: When the program is executed by a processor, the method according to any one of claims 1 to 6 is implemented.
Citation Information
Patent Citations
Encryption card scheduling method and device and computer readable storage medium
CN115495232A
Secure computing service environment
US10893029B1
Method, electronic device, and computer program product for looking up data
US11799962B1
Group determination based on multi-table dictionary codes
US20190095486A1
Solid state tier optmization using a content addressable caching layer
US20200225868A1