Cold storage management method with data protection function
By implementing comprehensive environmental assessment, multi-layer encryption, data storage layout planning, access control, data integrity check and data migration in the cold storage management system, the shortcomings of the existing cold storage management system in terms of data protection are solved, and efficient, secure and reliable storage and management of data are achieved.
Patent Information
- Application Number
- CN202411953225.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-27
- Publication Date
- 2025-05-30
AI Technical Summary
The existing cold storage management system has shortcomings in data protection, including the lack of accurate physical environment monitoring mechanisms, vulnerabilities in encryption methods, unreasonable data storage layout, insufficient access control, untimely and accurate data integrity checks, and inefficient data migration.
A cold storage management method with data protection functions is proposed, including storage environment evaluation, multi-layer encryption, data storage layout planning, access control, data integrity check and data migration. This method uses comprehensive deployment of sensor networks for environmental monitoring, adopts multi-layer encryption algorithms and key management, plans storage layout according to data characteristics, establishes a strict access control mechanism, conducts regular data integrity checks, and uses incremental and differential backups during data migration.
It realizes accurate monitoring and effective response to the cold storage environment, improves data confidentiality and security, optimizes data storage and access efficiency, ensures data integrity and recoverability, and improves data migration efficiency and reliability.
Smart Images

Figure CN120068173A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of cold storage management systems, and in particular to a cold storage management method with a data protection function. Background Art
[0002] With the rapid development of information technology, the amount of data has increased explosively, and a large amount of data needs to be stored for a long time to meet compliance, historical record, and backup and recovery requirements. As a data storage method, cold storage is widely used in the fields of finance, healthcare, scientific research, and government due to its low power consumption, high storage density, and suitability for long-term archiving.
[0003] In a cold storage environment, the security and integrity of data face many challenges. First, the physical environment where cold storage devices are located has a crucial impact on data preservation. Abnormal changes in temperature and humidity may cause damage to storage media, such as tapes getting damp and moldy, or hard disk heads being damaged due to high temperature. Magnetic field interference may corrupt data stored on magnetic media, and vibration may cause mechanical structure failures inside storage devices or read / write head offsets, all of which may lead to data loss or damage. However, many current cold storage systems lack precise monitoring and effective response mechanisms for the physical environment, or the monitoring is not comprehensive enough to detect potential environmental threats in a timely manner.
[0004] Secondly, data encryption is crucial in cold storage. Since cold storage data often contains a large amount of sensitive information, such as corporate financial data, patient medical records, and scientific research secrets, the consequences of data leakage would be unthinkable. Traditional encryption methods may have vulnerabilities or be imperfect in key management. Some systems only use a single encryption method, which is easily cracked, and the storage and protection measures for the encrypted keys are insufficient, which may lead to key loss or theft, leaving the data unprotected.
[0005] Furthermore, there are also problems in data management in cold storage. The data storage layout is unreasonable, without fully considering the differences in data types, access frequencies, and importance, resulting in low data access efficiency. For example, frequently accessed data may be stored deep in the storage device, increasing access latency. At the same time, in terms of data access control, the permission management is not strict and refined enough, and unauthorized access is likely to occur. Moreover, the existing access record mechanism is not reliable enough to effectively audit and track abnormal access behaviors.
[0006] In addition, data integrity checking and data migration are also weak links in cold storage management. During long-term storage, data may have integrity issues due to aging of storage media, physical damage, or software errors. However, current integrity checking methods may not be timely and accurate enough, and the data repair ability after problems are discovered is also limited. In the data migration scenario, such as when storage devices are upgraded or storage capacity is insufficient and data needs to be migrated, existing methods are often inefficient and prone to data loss or damage.
[0007] In summary, existing cold storage management has many deficiencies in data protection. There is an urgent need for a cold storage management method with comprehensive and efficient data protection functions to ensure the security, integrity, and accessibility of data. Summary of the Invention
[0008] A cold storage management method with a data protection function proposed by the present invention is used to solve the problems mentioned in the above prior art.
[0009] To achieve the above object, the present invention adopts the following technical solutions: A cold storage management method with a data protection function includes the following steps:
[0010] Storage environment assessment step: Comprehensively evaluate the physical environment where the cold storage device is located. Temperature sensors, humidity sensors, Hall effect sensors, and acceleration sensors are distributed in the cold storage area to form a sensor network. The data acquisition system collects sensor data at a preset frequency. Vibration and abnormal magnetic field intensity can trigger collection immediately. The collected data is transmitted to the data analysis unit, and the data analysis unit makes a judgment based on preset environmental parameter thresholds. The magnetic field intensity does not exceed the set Gaussian value. If it exceeds the threshold, an alarm is immediately sent to the management personnel through an audible and visual alarm and a remote notification system.
[0011] Data encryption step: Before the data is stored in the cold storage device, the data is encrypted using a multi-layer encryption algorithm. First, the AES-256 symmetric encryption algorithm is used to perform initial encryption on the data. Its key is generated through a key generation algorithm based on a hash function and a pseudo-random number generator. The data is divided into fixed-size data blocks, and each data block is encrypted separately. During the encryption process, multiple round transformations are performed on the data block, and each round includes byte substitution, row shift, column confusion, and round key addition operations. Then, the 2048-bit RSA asymmetric encryption algorithm is used to encrypt the AES key. When the RSA algorithm generates the public and private key pairs, the randomness and security of prime numbers are ensured through a large prime number generation algorithm. The public key is distributed within the system for encrypting the AES key, and the private key is stored in a key management center with multiple physical protections and access controls. Only authorized personnel can access it through authentication.
[0012] Data Storage Layout Planning Steps: Classify data according to data type, access frequency, and importance. Data types are divided into structured data, semi-structured data, and unstructured data. For the backup data of enterprise financial databases, it is stored in the inner area of the cold storage device, which is equipped with an independent power supply and a redundant cooling system, and uses enterprise-level solid-state drive storage media to reduce access latency and improve data security; for the backup data of recent business records, it is stored in the relatively outer area and uses mechanical hard disks; at the same time, set up a redundant area, the size of which is divided according to the total amount of data and the importance ratio; use the SHA-256 hash algorithm to calculate the checksum of the data, each data block corresponds to a checksum, and the checksum is stored in the redundant area together with the data;
[0013] Access Control Steps: Establish a user access authorization mechanism. Users need to pass multi-factor authentication, including username and strong password, fingerprint recognition, and smart card recognition; after the user enters the authentication information, the information is sent to the authentication server through the secure transmission TLS protocol; the authentication server verifies according to the pre-stored user information and permission settings;
[0014] Data Integrity Check Steps: Regularly check the integrity of the data in the cold storage. Based on the checksum copy set in the storage layout planning, calculate the SHA-256 hash value of the data again in parallel calculation mode in units of data blocks, and compare it with the stored checksum. If data integrity problems are found, start the data recovery operation, and use the data recovery algorithm to perform intelligent repair in combination with the copies stored in the redundant area and the association information between data blocks; at the same time, analyze the reasons for data corruption. If there are bad sectors on the storage medium, mark the bad sector area and migrate the data to other available areas; if it is a software error, check through system logs and error reports;
[0015] Data Migration Steps: When the storage capacity utilization rate of the cold storage device reaches 80% or the storage technology is updated, migrate the data. First, mark the data to be migrated by adding a migration flag bit to the data metadata, and suspend the access operations to these data; then, read the data from the original cold storage device, and use a high-speed network channel based on SSL / TLS encryption during the transmission process. At the same time, check the integrity of the data again, and perform a hash check every 100MB of data transmitted; after the new cold storage device receives the data, store the data again according to the new storage layout planning, and the new layout is determined according to the latest classification and importance evaluation results of the current data; update the access permissions according to the latest settings in the user permission management system, and at the same time update the relevant metadata information; after the migration is completed, delete the data in the original cold storage device or mark it as migrated, and notify all modules in the system to resume normal access operations to the data through the broadcast mechanism.
[0016] Furthermore, in the storage environment assessment step, machine learning algorithms are used to perform predictive analysis on environmental data. The long short-term memory network (LSTM) algorithm is adopted. Using the temperature, humidity, magnetic field intensity, and vibration data of the past year as the training set, the model is trained to learn the characteristics of seasonal changes, periodic fluctuations, and sudden abnormal situations. By continuously adjusting the number of neurons, the number of layers, and the learning rate parameters of the model, the prediction performance of the model is optimized. During actual operation, the model predicts abnormal increases or decreases in temperature, sharp changes in humidity, abnormal fluctuations in magnetic field intensity, and vibration events 1-2 hours in advance, and promptly activates preventive measures, including adjusting the parameters of the cooling system, starting the dehumidification equipment, or strengthening the physical fixation of the equipment.
[0017] Furthermore, in the data encryption step, the encrypted data is obfuscated. After the data encryption is completed, random padding data of a specific length is generated according to the size of the data block and the output result of the encryption algorithm. The generation of the padding data is based on a cryptographically secure pseudo-random number generator, and its seed value is jointly determined by multiple factors such as the system time and the hardware identifier to ensure randomness. The padding data is inserted into the encrypted data in a specific pattern.
[0018] Furthermore, it is characterized in that, in the data storage layout planning step, the distributed storage technology is adopted to disperse the data storage in multiple cold storage devices. The Ceph distributed file system is used to manage these cold storage devices. Through the consistent hashing algorithm, the data is evenly distributed on each storage node. Each data block is split into multiple sub-blocks during storage, and these sub-blocks are stored in different cold storage devices according to the hash value. At the same time, redundant copies of the data are stored on different cold storage devices, and the number of copies is determined according to the importance of the data. When a cold storage device fails, the data can be quickly restored from other devices storing the copies. A heartbeat detection mechanism is established between the storage nodes, and heartbeat signals are sent to each other every 10 seconds. If a node fails to receive a heartbeat signal for 3 consecutive times, it is determined that the node has failed, and the data recovery and load balancing mechanisms are automatically activated.
[0019] Furthermore, in the access control step, blockchain technology is introduced to store the user access records in an immutable manner. The detailed information of each user access is used as a transaction record. Using the hash chain structure of the blockchain, each transaction record is linked. Each block contains multiple transaction records, and the integrity of the block is ensured by calculating the hash value of the block header. The Proof of Work (PoW) or Proof of Stake (PoS) consensus mechanism is adopted to ensure the consistency confirmation of the transaction records by the nodes in the blockchain network. By storing the access records on the blockchain, any tampering with the access records requires modifying the subsequent blocks of the entire blockchain. At the same time, using the smart contract function of the blockchain, the access control policy is automatically executed, including automatically restricting the access rights when a user attempts illegal access multiple times continuously.
[0020] Further, in the data integrity check step, when a data integrity problem is found, an intelligent repair is performed by using a data recovery algorithm in combination with redundant data. The data recovery algorithm adopts an error correction technique based on Reed-Solomon code, which can correct errors in data blocks within a certain range. For each data block, the parameters of the error correction code are determined according to its importance and storage method. When a data integrity problem is detected, the error type and degree are first analyzed. If it is a bit error, the error is directly corrected by using the error correction code; if a data block is lost, the data is restored through a data reconstruction algorithm according to the association relationship between the copy stored in the redundant area and the data block. During the data reconstruction process, the original content of the data block is gradually restored by combining the index information in the storage layout, the logical order of the data blocks, and the relevance of the hash values, improving the repair efficiency.
[0021] Further, in the data migration step, during the data migration process, a combination of incremental backup and differential backup is adopted to reduce the data transmission volume and migration time. After marking the data to be migrated, a full backup is first performed as the base version; then, for subsequent data changes, the newly added data blocks and the changed data blocks are identified through the log records of the file system and the timestamp information of the data blocks. These data blocks constitute the incremental backup. At the same time, by comparing the hash values of the same data blocks in the original cold storage device and the new cold storage device, the data blocks with differences are found, and these data blocks are used as the content of the differential backup; during migration, only the data blocks of the incremental backup and the differential backup are transmitted.
[0022] Further, a system for implementing the cold storage management method with data protection function is characterized by comprising:
[0023] Environmental assessment module: used to implement the functions of the storage environment assessment step, including sensors, a data acquisition system, and an analysis and alarm unit. The sensors have self-calibration functions. Through the built-in calibration circuit and standard reference source, the measurement accuracy of the sensors is calibrated regularly. During the calibration process, the temperature sensor is compared with a high-precision standard thermometer, the humidity sensor is calibrated with a standard humidity generator, and the Hall effect sensor and the acceleration sensor are calibrated through calibration equipment;
[0024] Data encryption module: performs the data encryption step, encrypts the data by using a multi-layer encryption algorithm and a key management mechanism, and has an encryption algorithm update function. By connecting to an external security update server, it regularly checks whether there is a new encryption algorithm vulnerability released. If there is a new security threat, it automatically downloads and updates the encryption algorithm. During the update process, a dual-key mechanism is adopted, that is, both the old encryption key and the new encryption key are retained for a period of time, and the new encryption algorithm is used for newly stored data at the same time;
[0025] Storage layout planning module: Responsible for the data storage layout planning step, planning the storage area and setting redundancy according to data characteristics, supporting dynamic adjustment of the storage layout. By real-time monitoring the access frequency, importance changes of data, and performance indicators of storage devices, using a machine learning-based clustering algorithm to reclassify data and plan storage locations;
[0026] Access control module: According to the access control step, establish a user authorization and access record mechanism, integrate with an external identity management system, and achieve docking with the enterprise's existing user management system through standard LDAP and OAuth interface protocols;
[0027] Data integrity check module: Complete the data integrity check step, regularly check data and recover in case of problems, parallel process the integrity checks of multiple data blocks. Through multi-threading technology, allocate the number of threads according to the system's hardware resources. For a system with an 8-core CPU, start 8 threads simultaneously to perform hash calculation and checksum comparison on data blocks. During the data recovery process, use efficient memory management and data caching technologies to reduce the time for data reading and writing;
[0028] Data migration module: According to the data migration step, implement the migration of data between cold storage devices, support resume from breakpoint during the migration process. By recording the transfer progress information of each data block during the migration process, store this information in a local temporary file or database. When the migration process is interrupted due to network failure or device restart, the system resumes and continues the transfer from the position where it was interrupted according to the recorded progress information.
[0029] Compared with the existing technologies, the beneficial effects of the present invention are:
[0030] In terms of storage environment monitoring, by comprehensively deploying high-precision sensors and reasonable data acquisition frequencies, the cold storage environment parameters can be accurately grasped. Combining with an advanced environment assessment mechanism, abnormal situations of temperature, humidity, magnetic field, and vibration can be detected in a timely manner, with early warnings issued, effectively avoiding storage medium damage and data loss caused by environmental problems, and ensuring the physical security of data storage.
[0031] In terms of data encryption, multi-layer encryption algorithms and a perfect key management are adopted. Multi-layer encryption greatly improves the confidentiality of data. Even if one layer of encryption is cracked, there are other encryption protections. Strict key management ensures the security of keys, prevents data leakage, and protects sensitive information.
[0032] For the data storage layout, planned according to data characteristics, the access efficiency is optimized. Important and low-frequency accessed data is stored in high-security areas, and high-frequency accessed data is easy to obtain. At the same time, redundancy settings ensure data integrity and improve the overall storage performance.
[0033] In the access control process, multi-factor authentication and fine-grained permission management prevent unauthorized access. Reliable access records and auditing mechanisms, combined with blockchain technology, ensure that the records cannot be tampered with, effectively track anomalies, and enhance data security.
[0034] Data integrity checks can promptly and accurately detect problems. The intelligent repair algorithm, combined with redundant data, quickly repairs the problems, reducing the impact of data corruption. When migrating data, the combination of incremental and differential backups significantly reduces the transmission volume and time, ensures stable migration, and improves the flexibility and reliability of cold storage management. Brief Description of the Drawings
[0035] Figure 1 It is a schematic block diagram of a cold storage management method with a data protection function proposed by the present invention. Detailed Embodiment
[0036] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.
[0037] In the description of the present invention, it should be understood that the terms "center", "longitudinal", "transverse", "length", "width", "thickness", "upper", "lower", "front", "rear", "left", "right", "vertical", "horizontal", "top", "bottom", "inner", "outer", "clockwise", "counterclockwise" indicate the orientation or positional relationship based on the orientation or positional relationship shown in the drawings. It is only for the convenience of describing the present invention and simplifying the description, rather than indicating or implying that the device or element referred to must have a specific orientation, be constructed and operated in a specific orientation, and therefore should not be construed as a limitation to the present invention.
[0038] In addition, the terms "first" and "second" are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the quantity of the indicated technical features. Thus, features defined with "first" and "second" may explicitly or implicitly include one or more of the said features. In the description of the present invention, the meaning of "a plurality of" is two or more unless otherwise specifically defined. In addition, the terms "installed", "connected", and "coupled" should be understood in a broad sense. For example, it may be a fixed connection, a detachable connection, or an integral connection; it may be a mechanical connection or an electrical connection; it may be directly connected or indirectly connected through an intermediate medium, and it may be the communication inside two components. For those of ordinary skill in the art, the specific meanings of the above terms in the present invention can be understood according to specific circumstances. The present invention will be further described in detail below with reference to the accompanying drawings.
[0039] Refer to Figure 1 : A cold storage management method with a data protection function, comprising the following steps:
[0040] Storage environment assessment step: comprehensively evaluate the physical environment where the cold storage device is located, including parameters such as temperature, humidity, magnetic field strength, and vibration conditions. Reasonably distribute high-precision temperature sensors, humidity sensors, Hall effect sensors, and acceleration sensors in the cold storage area to form a sensor network. The accuracy of the temperature sensor can reach ±0.1 °C, and the accuracy of the humidity sensor is ±2% RH to ensure the accuracy of environmental data collection. The data acquisition system collects sensor data at a preset frequency. For large cold storage warehouses with relatively stable temperatures, the acquisition frequency is set to once every 2 hours; for environments with slightly faster humidity changes, it is collected once every 30 minutes; abnormal vibration and magnetic field strength can trigger acquisition immediately. The collected data is transmitted to the data analysis unit, which makes judgments based on preset environmental parameter thresholds. For example, the temperature threshold is set between -20 °C and 5 °C, the humidity threshold is 30%-50% RH, the magnetic field strength does not exceed a specific Gaussian value, and the vibration acceleration is less than a certain standard value. Once the threshold is exceeded, the system immediately sends an alarm to the management personnel through an audible and visual alarm and a remote notification system.
[0041] Data Encryption Steps: Before the data is stored in the cold storage device, a multi-layer encryption algorithm is used to encrypt the data. First, the AES-256 symmetric encryption algorithm is applied to initially encrypt the data, and its key is generated through a key generation algorithm based on a hash function and a pseudo-random number generator. The data is divided into data blocks of a fixed size, and each data block is encrypted separately. During the encryption process, multiple rounds of transformations are performed on the data block, and each round includes byte substitution, row shift, column mixing, and round key addition operations. Then, the 2048-bit RSA asymmetric encryption algorithm is used to encrypt the AES key. When generating the public and private key pair for the RSA algorithm, the randomness and security of the prime numbers are ensured through a large prime number generation algorithm. The public key is distributed within the system for encrypting the AES key, while the private key is stored in a key management center with multiple physical protections and access controls, and only authorized personnel can access it through strict authentication.
[0042] Data Storage Layout Planning Steps: The data is classified according to its type, access frequency, and importance. The data types can be divided into structured data (such as database files), semi-structured data (such as XML files), and unstructured data (such as images and videos). For data with a low access frequency but extremely high importance, such as the backup of the enterprise's core financial database, it is stored in the inner layer area of the cold storage device. This area is equipped with an independent power supply and a redundant cooling system, and a highly reliable storage medium, such as an enterprise-level solid-state drive, is used to reduce access latency and improve data security. For data with a slightly higher access frequency, such as the backup of recent business records, it is stored in the relatively outer layer area, using a large-capacity mechanical hard disk. At the same time, a redundant area is set up, and its size is divided according to a certain proportion based on the total amount and importance of the data. For example, the redundancy of important data is 30%. The SHA-256 hash algorithm is used to calculate the checksum of the data, and each data block corresponds to a checksum. The checksum is stored in the redundant area together with the data to ensure the integrity and recoverability of the data.
[0043] Access Control Steps: Establish a strict user access authorization mechanism. Users need to pass multi-factor authentication, including username and strong password (the password should contain uppercase and lowercase letters, numbers, and special characters, with a length of at least 8 digits), fingerprint recognition (using a high-resolution fingerprint sensor with a recognition accuracy of 99.9%), and smart card recognition (the smart card has an embedded encryption chip that stores a unique identity identifier and encryption key). After the user enters the authentication information, the information is sent to the authentication server through a secure transmission protocol (such as the TLS protocol). The authentication server verifies based on the pre-stored user information (including user basic information, permission levels, and historical access records) and permission settings. For ordinary users, only the permission to read public data is granted; for intermediate users, they can read and write some business-related data; senior administrators have full read, write, and management permissions for all data. Each access operation is recorded in the audit log, which includes detailed information about the accessing user, the access time accurate to milliseconds, the data content identifier (represented by a data hash value or unique identifier), and the operation type (read, write, delete) for subsequent detailed auditing and abnormal behavior tracking.
[0044] Data Integrity Check Steps: Regularly check the integrity of the data in cold storage. Based on the checksum copies set in the storage layout plan, calculate the SHA-256 hash value of the data again in parallel in units of data blocks and compare it with the stored checksum. For important data, the check period is set to be carried out during the low system load period from 2 to 4 am every day; for general data, the check period is once a week. If a data integrity problem is found, start the data recovery operation. Through the data recovery algorithm, combine the copies stored in the redundant area and the association information between data blocks (such as the logical order of data blocks and index information) for intelligent repair. At the same time, analyze the cause of data corruption. If there are bad sectors on the storage medium, mark the bad sector area and migrate the data to other available areas; if it is suspected to be a software error, check through system logs and error reports and update or repair the relevant software in a timely manner.
[0045] Data migration steps: When the storage capacity utilization rate of the cold storage device reaches 80% or the storage technology is updated (such as the emergence of a new storage medium with higher cost performance), data migration is performed. First, the data to be migrated is marked by adding a migration flag bit to the data metadata, and access operations to these data are suspended. Then, the data is read out from the original cold storage device, and a high-speed network channel based on SSL / TLS encryption is used during the transmission process, with a transmission speed of over 10 Gbps. At the same time, the integrity of the data is checked again, and a hash check is performed every 100 MB of data transmitted. After the new cold storage device receives the data, it stores the data again according to the new storage layout plan, and the new layout is determined based on the latest classification and importance assessment results of the current data. The access permissions are updated according to the latest settings in the user permission management system, and relevant metadata information such as the data storage location and access path is updated. After the migration is completed, the data in the original cold storage device is deleted or marked as migrated, and all relevant modules within the system are notified through the broadcast mechanism to resume normal access operations to the data.
[0046] In the present invention, in the storage environment assessment step, machine learning algorithms are used to perform predictive analysis on environmental data. The long short-term memory network (LSTM) algorithm is adopted, which can learn the sequential patterns of environmental parameters changing over time. Using the temperature, humidity, magnetic field intensity, and vibration data of the past year as the training set, the training model learns the characteristics of seasonal changes, periodic fluctuations, and sudden abnormal situations. By continuously adjusting the number of neurons, the number of layers, and the learning rate parameters of the model, the prediction performance of the model is optimized. During actual operation, the model can predict abnormal increases or decreases in temperature, sharp changes in humidity, abnormal fluctuations in magnetic field intensity, and possible vibration events 1-2 hours in advance, so as to timely initiate preventive measures such as adjusting the parameters of the cooling system, starting the dehumidification equipment, or strengthening the physical fixation of the equipment.
[0047] In the present invention, in the data encryption step, the encrypted data is obfuscated. After the data encryption is completed, random padding data of a specific length is generated according to the size of the data block and the output result of the encryption algorithm. The generation of the padding data is based on a cryptographically secure pseudo-random number generator, and its seed value is jointly determined by various factors such as the system time and the hardware identifier to ensure randomness. The padding data is inserted into the encrypted data in a specific pattern, such as inserting a certain length of padding data every fixed byte, and the content and insertion position of the padding data change dynamically during each encryption process, further improving the security of the data and making it difficult for attackers to crack the encryption by analyzing the data pattern.
[0048] In the present invention, in the data storage layout planning step, the distributed storage technology is adopted to disperse and store data in multiple cold storage devices. A distributed file system (such as Ceph) is used to manage these cold storage devices, and the data is evenly distributed on each storage node through the consistent hashing algorithm. Each data block is split into multiple sub-blocks during storage, and these sub-blocks are stored in different cold storage devices according to the hash value. At the same time, redundant copies of the data are stored on different cold storage devices, and the number of copies is determined according to the importance of the data. Generally, the number of copies of important data is 3, and the number of copies of critical data can be set to 5. In this way, when a certain cold storage device fails, the data can be quickly restored from other devices storing the copies, improving the availability and fault tolerance of the data. A heartbeat detection mechanism is established between the storage nodes, and heartbeat signals are sent to each other every 10 seconds. If a certain node does not receive a heartbeat signal for 3 consecutive times, it is determined that the node has failed, and the data recovery and load balancing mechanisms are automatically started.
[0049] In the present invention, in the access control step, the blockchain technology is introduced to store the user access records in an immutable manner. The detailed information of each user access (including the accessing user, access time, accessed data content, and operation type) is used as a transaction record, and each transaction record is linked using the hash chain structure of the blockchain. Each block contains multiple transaction records, and the integrity of the block is ensured by calculating the hash value of the block header. The proof-of-work (PoW) or proof-of-stake (PoS) consensus mechanism is adopted to ensure the consistency confirmation of the transaction records by the nodes in the blockchain network. By storing the access records on the blockchain, any tampering with the access records requires modifying the subsequent blocks of the entire blockchain, which is extremely costly in terms of computing, thus ensuring the reliability of the audit. At the same time, using the smart contract function of the blockchain, some access control policies can be automatically executed. For example, when a user attempts illegal access multiple times continuously, their access rights can be automatically restricted.
[0050] In the present invention, in the data integrity check step, when a data integrity problem is detected, an intelligent repair is performed by using a data recovery algorithm in combination with redundant data. The data recovery algorithm adopts an error correction technique based on Reed-Solomon code, which can correct errors in data blocks within a certain range. For each data block, the parameters of the error correction code are determined according to its importance and storage method. For example, for important data blocks, higher error correction capability parameters are used. When a data integrity problem is detected, the type and degree of the error are first analyzed. If there are a small number of bit errors, the error correction code is directly used for correction. If a data block is lost or severely damaged, the data is restored through a data reconstruction algorithm according to the association relationship between the copy stored in the redundant area and the data block. During the data reconstruction process, the original content of the data block is gradually restored by combining the index information in the storage layout, the logical order of the data blocks, and the relevance of the hash values, improving the repair efficiency.
[0051] In the present invention, in the data migration step, during the data migration process, a combination of incremental backup and differential backup is adopted to reduce the data transmission volume and migration time. After marking the data to be migrated, a full backup is first performed as the base version. Then, for subsequent data changes, the newly added data blocks and the changed data blocks are identified through the log records of the file system and the timestamp information of the data blocks, and these data blocks constitute the incremental backup. At the same time, by comparing the hash values of the same data blocks in the original cold storage device and the new cold storage device, the data blocks with differences are found, and these data blocks are used as the content of the differential backup. During migration, only the data blocks of the incremental backup and the differential backup are transmitted, greatly reducing the data transmission volume. For a large-scale cold storage system, this method can shorten the migration time from several days of traditional full migration to several hours, improving the migration efficiency.
[0052] The present invention also discloses a cold storage management system with a data protection function, including:
[0053] An environment evaluation module: used to implement the functions of the storage environment evaluation step in claim 1, including sensors, a data acquisition system, and an analysis and alarm unit. The sensors have a self-calibration function. Through the built-in calibration circuit and standard reference source, the measurement accuracy of the sensors is calibrated regularly (such as once a week). During the calibration process, the temperature sensor is compared with a high-precision standard thermometer, the humidity sensor is calibrated with a standard humidity generator, and the Hall effect sensor and the acceleration sensor are calibrated through dedicated calibration equipment to ensure that the accuracy of the environmental data acquisition is within the allowable error range, guaranteeing the reliability of the subsequent environmental evaluation.
[0054] Data Encryption Module: It executes the data encryption step in Claim 1 and encrypts data using a multi-layer encryption algorithm and a key management mechanism. This module has an encryption algorithm update function. By connecting to an external security update server, it regularly (e.g., once a month) checks whether there are new encryption algorithm vulnerabilities released. If there are new security threats, it automatically downloads and updates the encryption algorithm. During the update process, a dual-key mechanism is adopted, that is, both the old encryption key and the new encryption key are retained for a period of time to ensure that ongoing read and write operations are not affected, and at the same time, the new encryption algorithm is used for newly stored data to achieve a smooth transition.
[0055] Storage Layout Planning Module: It is responsible for the data storage layout planning step in Claim 1, and plans the storage area and sets redundancy according to data characteristics. This module supports dynamic adjustment of the storage layout. By real-time monitoring of the access frequency, importance changes of data, and performance indicators of storage devices (such as storage capacity, read and write speed), it uses intelligent algorithms (such as machine learning-based clustering algorithms) to reclassify data and plan storage locations. For example, when the access frequency of a certain type of data suddenly increases, it migrates the data from the inner-layer low-temperature storage area to the outer-layer area with relatively high access speed; when the performance of a certain area of the storage device deteriorates, it automatically migrates the data to other areas with good performance.
[0056] Access Control Module: According to the access control step in Claim 1, it establishes a user authorization and access record mechanism. This module can be integrated with an external identity management system and achieve seamless docking with the enterprise's existing user management system through standard interface protocols (such as LDAP, OAuth). In this way, the identity information and permission settings of users in the cold storage system can be consistent with the enterprise's overall user management strategy, facilitating unified management and maintenance. At the same time, during the integration with external systems, secure data transmission methods and encryption authentication mechanisms are adopted to prevent the leakage of user information.
[0057] Data Integrity Check Module: It completes the data integrity check step in Claim 1, regularly checks data and recovers in case of problems. This module can parallelly process the integrity checks of multiple data blocks. Through multi-threading technology, it reasonably allocates the number of threads according to the hardware resources of the system (such as the number of CPU cores). For example, for a system with an 8-core CPU, 8 threads can be started simultaneously to perform hash calculations and checksum comparisons on data blocks, greatly improving the check speed. During the data recovery process, efficient memory management and data caching technologies are used to reduce the time for data reading and writing and accelerate the repair process.
[0058] Data Migration Module: Implement the data migration between cold storage devices according to the data migration steps in Claim 1. Resume interrupted transfers is supported during the migration process. By recording the transfer progress information of each data block (such as the number of bytes transferred and the transfer status) during the migration process, and storing this information in a local temporary file or database. When the migration process is interrupted due to network failures or device restarts, the system can continue the transfer from the last interrupted position based on the recorded progress information after recovery, ensuring the stability of the migration, avoiding re-transmitting the completed parts, and improving the migration efficiency.
[0059] The above are only the preferred specific embodiments of the present invention, but the protection scope of the present invention is not limited thereto. Any person skilled in the art within the technical scope disclosed by the present invention, according to the technical solution and inventive concept of the present invention, with equivalent replacement or change, should be covered within the protection scope of the present invention.
Claims
1. A cold storage management method with data protection function, characterized in that: The following steps are involved: Storage environment assessment steps: conduct a comprehensive assessment of the physical environment of the cold storage equipment, distribute temperature sensors, humidity sensors, Hall effect sensors and acceleration sensors in the cold storage area to form a sensor network; The data acquisition system collects sensor data at a preset frequency; Abnormal vibration and magnetic field strength can trigger collection immediately, and the collected data is transmitted to the data analysis unit. The data analysis unit makes a judgment based on the preset environmental parameter threshold. If the magnetic field strength does not exceed the set Gauss value, if it exceeds the threshold, an alarm will be immediately issued to the management personnel through the sound and light alarm and remote notification system; Data encryption steps: Before the data is stored in the cold storage device, a multi-layer encryption algorithm is used to encrypt the data. First, the AES-256 symmetric encryption algorithm is used to encrypt the data initially. The key is generated by a key generation algorithm based on a hash function and a pseudo-random number generator. The data is divided into fixed-size data blocks, and each data block is encrypted separately. During the encryption process, the data blocks are transformed multiple times. Each round includes byte substitution, row shift, column confusion, and round key addition operations. After that, the AES key is encrypted using the 2048-bit RSA asymmetric encryption algorithm. When the RSA algorithm generates a public-private key pair, it uses a large prime number generation algorithm to ensure the randomness and security of the prime number. The public key is distributed within the system to encrypt the AES key, and the private key is stored in a key management center that uses multiple physical protections and access controls. Only authorized personnel can access it through identity authentication. Data storage layout planning steps: Classify data according to data type, access frequency and importance. Data types are divided into structured data, semi-structured data and unstructured data. For enterprise financial database backup data, store it in the inner area of the cold storage device. This area is equipped with an independent power supply and redundant cooling system, and uses enterprise-level solid-state hard disk storage media to reduce access latency and improve data security. For recent business record backup data, store it in a relatively outer area using mechanical hard disks. At the same time, set up redundant areas, the size of which is divided according to the total amount of data and the importance ratio. The SHA-256 hash algorithm is used to calculate the checksum of the data. Each data block corresponds to a checksum, and the checksum is stored in the redundant area together with the data. Access control steps: Establish a user access authorization mechanism. Users must pass multi-factor authentication, including username and strong password, fingerprint recognition, and smart card recognition. After the user enters the authentication information, the information is sent to the authentication server via the secure transmission TLS protocol. The authentication server performs verification based on pre-stored user information and permission settings; Data integrity check steps: Regularly perform integrity checks on the data in cold storage. Based on the checksum replicas set in the storage layout plan, recalculate the SHA-256 hash value of the data in units of data blocks through parallel computing, and compare it with the stored checksum. If data integrity problems are found, start the data recovery operation, and use the data recovery algorithm to perform intelligent repairs in combination with the replicas stored in the redundant area and the association information between the data blocks. At the same time, analyze the causes of data corruption. If bad sectors appear on the storage medium, mark the bad sector area and migrate the data to other available areas. If it is a software error, check it through system logs and error reports; Data migration steps: When the storage capacity utilization rate of the cold storage device reaches 80% or the storage technology is updated, the data is migrated. First, the data to be migrated is marked by adding a migration mark bit in the data metadata, and the access to these data is suspended; then, the data is read out from the original cold storage device, and a high-speed network channel based on SSL / TLS encryption is used during the transmission process. At the same time, the data integrity is checked again, and a hash check is performed every 100MB of data transmitted; after receiving the data, the new cold storage device re-stores the data according to the new storage layout plan. The new layout is determined based on the latest classification and importance assessment results of the current data; Update access permissions based on the latest settings in the user rights management system and update related metadata information; After the migration is completed, the data in the original cold storage device is deleted or marked as migrated, and all modules in the system are notified through the broadcast mechanism to resume normal access to the data.
2. A cold storage management method with data protection function according to claim 1, characterized in that: In the storage environment assessment step, machine learning algorithms are used to predict and analyze environmental data. The long short-term memory network (LSTM) algorithm is adopted, and the temperature, humidity, magnetic field strength and vibration data of the past year are used as the training set. The model is trained to learn the characteristics of seasonal changes, periodic fluctuations and sudden abnormal situations. The model's prediction performance is optimized by continuously adjusting the number of neurons, the number of layers and the learning rate parameters of the model. In actual operation, the model predicts abnormal temperature increases or decreases, sharp changes in humidity, abnormal fluctuations in magnetic field strength and vibration events 1-2 hours in advance, and promptly initiates preventive measures, including adjusting cooling system parameters, starting dehumidification equipment or strengthening the physical fixation of equipment.
3. The cold storage management method with data protection function according to claim 1, characterized in that: In the data encryption step, the encrypted data is obfuscated. After the data encryption is completed, random padding data of a specific length is generated based on the size of the data block and the output result of the encryption algorithm. The generation of the padding data is based on a cryptographically secure pseudo-random number generator, and its seed value is determined by multiple factors such as system time and hardware identifier to ensure randomness. The padding data is inserted into the encrypted data in a specific pattern.
4. The cold storage management method with data protection function according to claim 1, characterized in that: In the data storage layout planning step, distributed storage technology is used to disperse the data and store it in multiple cold storage devices. The Ceph distributed file system is used to manage these cold storage devices. The data is evenly distributed on each storage node through the consistent hashing algorithm. Each data block is divided into multiple sub-blocks during storage. These sub-blocks are stored in different cold storage devices according to the hash value. At the same time, redundant copies of the data are stored on different cold storage devices. The number of copies is determined according to the importance of the data. When a cold storage device fails, the data is quickly restored from other devices that store copies. A heartbeat detection mechanism is established between storage nodes, and heartbeat signals are sent to each other every 10 seconds. If a node does not receive a heartbeat signal for three consecutive times, it is determined that the node is faulty, and the data recovery and load balancing mechanism are automatically started.
5. The cold storage management method with data protection function according to claim 1, characterized in that: In the access control step, blockchain technology is introduced to store user access records in an unalterable manner, and the detailed information of each user access is used as a transaction record. The hash chain structure of the blockchain is used to link each transaction record. Each block contains multiple transaction records, and the integrity of the block is guaranteed by calculating the hash value of the block header. The PoW proof-of-work or PoS proof-of-stake consensus mechanism is used to ensure the consistency of transaction records by nodes in the blockchain network. By storing access records on the blockchain, any tampering with the access records requires modifying subsequent blocks of the entire blockchain. At the same time, the smart contract function of the blockchain is used to automatically execute access control policies, including automatically restricting the access rights of users when they attempt illegal access multiple times in a row.
6. The cold storage management method with data protection function according to claim 1, characterized in that: In the data integrity check step, when a data integrity problem is found, a data recovery algorithm is used in combination with redundant data for intelligent repair. The data recovery algorithm adopts an error correction technology based on Reed-Solomon code, which can correct errors in data blocks within a certain range. For each data block, the parameters of the error correction code are determined according to its importance and storage method. When a data integrity problem is detected, the error type and degree are first analyzed. If it is a bit error, the error correction code is directly used to correct it; if the data block is lost, the data is restored through a data reconstruction algorithm based on the association between the copy stored in the redundant area and the data block. During the data reconstruction process, the index information in the storage layout, the logical order of the data block, and the correlation of the hash value are combined to gradually restore the original content of the data block to improve the repair efficiency.
7. The cold storage management method with data protection function according to claim 1, characterized in that: In the data migration step, during the data migration process, a combination of incremental backup and differential backup is used to reduce the amount of data transmission and migration time. After marking the data to be migrated, a full backup is first performed as the basic version; then, for subsequent data changes, the newly added data blocks and the changed data blocks are identified through the log records of the file system and the timestamp information of the data blocks. These data blocks constitute the incremental backup. At the same time, the hash values of the same data blocks in the original cold storage device and the new cold storage device are compared to find the data blocks with differences. These data blocks are used as the content of the differential backup; During migration, only the data blocks of incremental and differential backups are transferred.
8. A system for implementing the cold storage management method with data protection function according to any one of claims 1 to 7, characterized in that: include: Environmental assessment module: used to implement the functions of the storage environment assessment steps, including sensors, data acquisition systems and analysis and alarm units. The sensors have self-calibration functions. Through the built-in calibration circuit and standard reference source, the measurement accuracy of the sensors is calibrated regularly. During the calibration process, the temperature sensor is compared with a high-precision standard thermometer, the humidity sensor is calibrated with a standard humidity generator, and the Hall effect sensor and the acceleration sensor are calibrated through the calibration equipment; Data encryption module: executes data encryption steps, uses multi-layer encryption algorithms and key management mechanisms to encrypt data, has encryption algorithm update function, connects to external security update servers, regularly checks whether new encryption algorithm vulnerabilities are released, and automatically downloads and updates encryption algorithms if there are new security threats. During the update process, a dual-key mechanism is used, that is, the old encryption key and the new encryption key are retained for a period of time, and the new encryption algorithm is used for the newly stored data; Storage layout planning module: responsible for the steps of data storage layout planning, planning storage areas and setting redundancy according to data characteristics, supporting dynamic adjustment of storage layout, and using machine learning-based clustering algorithms to reclassify data and plan storage locations by real-time monitoring of data access frequency, importance changes, and storage device performance indicators; Access control module: Establish user authorization and access record mechanism according to access control steps, integrate with external identity management system, and connect with the enterprise's existing user management system through standard LDAP and OAuth interface protocols; Data integrity check module: completes the data integrity check steps, periodically checks data and recovers when problems occur, and processes integrity checks on multiple data blocks in parallel. Through multi-threading technology, the number of threads is allocated according to the hardware resources of the system. For a system with an 8-core CPU, 8 threads are started at the same time to perform hash calculations and checksum comparisons on data blocks. During the data recovery process, efficient memory management and data caching technology are used to reduce the time for data reading and writing. Data migration module: According to the data migration steps, data migration between cold storage devices is realized, and breakpoint resumption is supported during the migration process. The transmission progress information of each data block is recorded during the migration process and stored in a local temporary file or database. When the migration process is interrupted due to network failure or device restart, the system will continue the transmission from the last interrupted position according to the recorded progress information after recovery.
Citation Information
Cited By
Digital archive management vulnerability assessment method and system based on multi-dimensional influence factors
CN120611881A
Building intelligent operation and maintenance control system and method based on intelligent encryption algorithm
CN120785921A
Data backup management method and system for automobile data recorder
CN121144112A
Mobile terminal off-line storage method and system based on mountainous area
CN121418941A