Data access control method and device, computer equipment and storage medium
By initializing the storage of stored data and setting up RS encoding/decoding modules in the ORAM system, the data tampering and integrity problems in the ORAM system during data access are solved, and the effect of improving data access security and integrity is achieved.
Patent Information
- Application Number
- CN202510630845.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-16
- Publication Date
- 2025-06-20
- Estimated Expiration
- 2045-05-16
AI Technical Summary
Existing ORAM systems have data tampering and integrity problems during data access, and are vulnerable to network attacks, resulting in reduced data security and reliability.
Initialized storage of the data to be stored, including location mapping and RS encoding, and the encoded data block is stored in the ORAM binary tree. When receiving the data access request, a read and write request is sent to the ORAM binary tree, and the target data block is searched through the buffer Stash, and processed according to the search results. If the target data block does not exist, its real physical memory location is determined through the location mapping table and its path tag is remapped. Read the path of the target data block, and use all data blocks contained in the RS decode path to store the data to be stored in the buffer Stash. Finally, when the data access request is completed, all read data blocks are encrypted and RS-encoded, and they are expelled according to the original read path.
Through the powerful error correction capability of RS code, an RS encoding/decoding module is set up in the ORAM system. When data transmission or storage is tampered with and damaged, the original data can be restored through the remaining redundant information, ensuring the integrity of the data, and improving the security and integrity of the ORAM system in the data access process.
Smart Images

Figure CN120179873A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of data processing, and in particular, to a data access control method, apparatus, computer device, and medium. Background Art
[0002] With the booming development of the Internet, numerous mobile intelligent devices have been interconnected, thus generating a vast amount of data. To reduce data storage costs, many customers tend to store their private data on cloud servers. However, it is difficult to ensure the confidentiality of private data solely relying on encryption technologies such as AES, because there are still risks of leakage in the data access pattern. An attacker may infer some sensitive content based on information such as the number of queries and query paths of the customer. In response, the Oblivious Random Access Machine (ORAM) was proposed decades ago to effectively solve this security problem.
[0003] ORAM is a protocol that guarantees the security of the memory access pattern. It transforms the access to a single memory cell into a computationally indistinguishable sequence of a fixed number of accesses to hide the original access pattern. And as a relatively costly encryption method, it prevents the leakage of search and access patterns by continuously changing the data storage location and re-encrypting the accessed data. However, although the early ORAM schemes protected the security of the data access process, due to their low access efficiency, they brought a large amount of access overhead, resulting in poor performance of existing ORAM systems. Therefore, in recent years, research has proposed tree-based ORAM schemes to alleviate this situation. Among them, the most traditional and efficient tree-based ORAM scheme is Path ORAM. By determining the location of the target data block to be retrieved through the path, and then accessing and confusing the data blocks on the corresponding path, the overall access overhead can be greatly reduced.
[0004] In the process of implementing the present invention, it is realized that the prior art has at least the following technical problems: On the one hand, the application of the ORAM protocol may cause data to be maliciously tampered with during transmission. If these tampering behaviors cannot be detected and repaired in time, the data integrity will be seriously threatened. On the other hand, the construction of the ORAM scheme highly depends on encryption algorithms and randomization algorithms. If there are defects or misuses in the implementation of these algorithms, it is very easy to cause data integrity problems. Moreover, currently, network attackers can launch attacks on the ORAM scheme by means of various means such as DDoS attacks, man-in-the-middle attacks, and malware attacks, thereby destroying data integrity. Once the data integrity cannot be properly guaranteed, the effectiveness of the ORAM scheme will be greatly reduced, and the security and reliability of data privacy protection will also decrease accordingly. Therefore, how to avoid these problems that occur in the use of the ORAM protocol and improve the reliability of the ORAM system and data access security has become an urgent problem to be solved. Summary of the Invention
[0005] Embodiments of the present invention provide a data access control method, device, computer device, and storage medium to improve the data security and integrity when using an ORAM system for data access.
[0006] To solve the above technical problems, an embodiment of the present application provides a data access control method, including: Perform initialization storage on the data to be stored. The initialization storage includes location mapping and RS coding, and store the encoded data blocks into the ORAM binary tree; When receiving a data access request, send a read / write request to the ORAM binary tree, so that after the memory controller receives the request, it searches in the buffer Stash to see if there is a target data block, and receives the search result, where the target data block is the data block corresponding to the request address in the data access request; If the search result is that it exists, process the target data block according to the read / write request; If the search result is that it does not exist, determine the true physical memory location of the target data block through the location mapping table, and remap the path label of the target data block to a new random path; Read the path where the target data block is stored in the ORAM binary tree, and use RS decoding to decode all the data blocks included in the path, and store the data to be stored into the buffer Stash; Update the buffer Stash, and process the target data block according to the read / write request; After the data access request is completed, perform an encryption operation on all the read data blocks that have completed the operation, then perform RS coding on all the data blocks, and evict all the encrypted and encoded data blocks according to the path read originally.
[0007] Optionally, the initial storage of the data to be stored includes: When it is detected that data is first stored in the untrusted memory, the detected data is used as the data to be stored, and the data to be stored is used as the basic data block; Allocate path labels for the basic data block through the position mapping table PosMap and record the path where it is located; Perform an encryption operation on the basic data block, and perform RS encoding and introduce a security factor seed on the encrypted basic data block to obtain an encrypted encoded data block; Store the encrypted encoded data block into the ORAM binary tree.
[0008] Optionally, the performing RS encoding and introducing a security factor seed on the encrypted basic data block to obtain an encrypted encoded data block includes: Divide the encrypted basic data block into several small data blocks of a fixed size; Perform an exclusive OR operation on each small data block using the security seed coefficient S to generate a confused data block, where the security seed coefficient S is a random value generated by a dynamic generation algorithm based on the encryption key; Use the confused data block as a coefficient to construct a data polynomial , the data polynomial As the basis of the encoding process, it contains all the information of the confused data blocks, and based on the RS encoding method, for the data polynomial Generate check information to obtain a check polynomial; Combine the data polynomial and the check polynomial to construct a transmission polynomial, and use the transmission polynomial as the encrypted encoded data block.
[0009] Optionally, the storing the data to be stored into the buffer Stash by using all the data blocks included in the RS decoding path includes: Read all the data blocks on the path found from the position mapping table PosMap; Use all the data blocks included in the RS decoding path and decrypt all the data blocks to obtain the real data blocks, and store the real data blocks into Stash; If during the RS decoding process, there is a real data block that matches the target data block requested by the system, data integrity and error correction can be verified during the decoding process. If the data is error-free, the data block can enter the next step for normal processing. Otherwise, use RS error correction to restore the data.
[0010] Optionally, the using all the data blocks included in the RS decoding path and decrypting all the data blocks to obtain the real data blocks includes: Extract the transfer polynomial from the data blocks read from the ORAM tree; Reconstruct the secure seed coefficient S'; According to the transfer polynomial and the secure seed coefficient S', separate the transfer polynomial into a data polynomial and a parity polynomial; Use the parity checking mechanism of RS coding to verify the data integrity of the data polynomial and the parity polynomial. If the data is damaged or tampered with, use the error correction ability of RS to repair the data; Decode the data polynomial to restore the encrypted data block and obtain the real data block.
[0011] Optionally, the RS coding for all target paths and the eviction of all encrypted and encoded data blocks along the original read path include: Perform RS coding on all target paths and introduce the secure seed coefficient to obtain the secondarily encoded data blocks; Evict all the secondarily encoded data blocks along the original read path, traverse the data blocks in the buffer Stash, and according to the path labels of each data block, try to place all the data blocks into the buckets on the target paths until each bucket reaches the capacity limit. Finally, all the data blocks continue to be stored on the ORAM binary tree, waiting for the next access call of the system.
[0012] To solve the above technical problems, an embodiment of the present application further provides a data access control device, including: An initialization storage module for initializing the storage of the data to be stored. The initialization storage includes position mapping and RS coding, and stores the encoded data blocks into the ORAM binary tree; A request response module for sending a read / write request to the ORAM binary tree when receiving a data access request, so that the memory controller searches in the buffer Stash for the existence of the target data block after receiving the request and receives the search result, where the target data block is the data block corresponding to the request address in the data access request; A first processing module for processing the target data block according to the read / write request if the search result is existence; A second processing module for determining the real physical memory location of the target data block through the position mapping table and remapping the path label of the target data block to a new random path if the search result is non-existence; A read decoding module for reading the path where the target data block is stored in the ORAM binary tree and decoding all the data blocks included in the path by RS, and storing the data to be stored into the buffer Stash; A buffer update module for updating the buffer Stash and processing the target data block according to the read / write request; A re-encoding module, which is used to encrypt all the read data blocks after the data access request is completed, then perform RS encoding on all the data blocks, and evict all the encrypted and encoded data blocks along the original read path.
[0013] Optionally, the initialization storage module includes: A basic data block determination sub-module, which is used to, when detecting that data is first stored in the untrusted memory, regard the detected data as the data to be stored, and regard the data to be stored as the basic data block; A path generation sub-module, which is used to allocate path labels for the basic data blocks through the position mapping table PosMap and record the paths where they are located; An encryption and encoding sub-module, which is used to perform encryption operations on the basic data blocks, and perform RS encoding and introduce a security factor seed on the encrypted basic data blocks to obtain encrypted and encoded data blocks; A data storage sub-module, which is used to store the encrypted and encoded data blocks into the ORAM binary tree.
[0014] Optionally, the encryption and encoding sub-module includes: A data splitting unit, which is used to divide the encrypted basic data blocks into several small data blocks of a fixed size; A data scrambling unit, which is used to perform exclusive OR operations on each small data block using the security seed coefficient S to generate scrambled data blocks, where the security seed coefficient S is a random value generated by a dynamic generation algorithm based on the encryption key; A polynomial processing unit, which is used to construct a data polynomial using the scrambled data blocks as coefficients , the data polynomial serves as the basis for the encoding process, contains all the information of the scrambled data blocks, and based on the RS encoding method, generates check information for the data polynomial to obtain a check polynomial; An encoded data block generation unit, which is used to combine the data polynomial and the check polynomial to construct a transmission polynomial, and regard the transmission polynomial as the encrypted and encoded data block.
[0015] To solve the above technical problems, an embodiment of the present application further provides a computer device, including a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, it implements the steps of the above data access control method.
[0016] To solve the above technical problems, an embodiment of the present application further provides a computer-readable storage medium. The computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the steps of the above data access control method are implemented.
[0017] The data access control method, device, computer device, and storage medium provided by the embodiments of the present invention perform initialization storage on the data to be stored. The initialization storage includes position mapping and RS coding, and stores the encoded data blocks into the ORAM binary tree; when receiving a data access request, sends a read / write request to the ORAM binary tree, so that after the memory controller receives the request, it searches in the buffer Stash to check if there is a target data block and receives the search result; if the search result is that it exists, processes the target data block according to the read / write request; if the search result is that it does not exist, determines the true physical memory location of the target data block through the position mapping table, and remaps the path label of the target data block to a new random path; reads the path where the target data block is stored in the ORAM binary tree, and decodes all the data blocks included in the path using RS, stores the data to be stored into the buffer Stash; updates the buffer Stash, and processes the target data block according to the read / write request; when the data access request is completed, performs an encryption operation on all the read data blocks that have completed the operation, then performs RS coding on all the data blocks, and evicts all the encrypted and encoded data blocks according to the original read path. It realizes setting an RS encoding / decoding module in the ORAM system through the powerful error correction ability of the RS code. When the data is tampered with and damaged during transmission or storage, the RS encoding / decoding restores the original data through the remaining redundant information, ensuring the integrity of the data and improving the security and integrity of the ORAM system during the data access process. BRIEF DESCRIPTION OF THE DRAWINGS
[0018] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the following will briefly introduce the drawings required for the description of the embodiments of the present invention. Obviously, the following drawings are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained based on these drawings.
[0019] Figure 1 is an exemplary system architecture diagram to which the present application can be applied; Figure 2 is a flowchart of an embodiment of the data access control method of the present application; Figure 3 is a structural example diagram of a verifiable ORAM system based on the RS error correction code in the data access control method of the present application; Figure 4It is a schematic structural diagram of an embodiment of the data access control device according to the present application; Figure 5 It is a schematic structural diagram of an embodiment of the computer device according to the present application. Detailed implementation manners
[0020] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by those of ordinary skill in the technical field to which this application belongs; the terms used in the specification of this application are only for the purpose of describing specific embodiments and are not intended to limit this application; the terms "including" and "having" and any variations thereof in the specification and claims of this application and the above drawings are intended to cover non-exclusive inclusion. The terms "first", "second", etc. in the specification and claims of this application or the above drawings are used to distinguish different objects and are not used to describe a specific order.
[0021] In the existing method, the access protocol of the Path ORAM scheme is as follows: 1. When the ORAM receives a memory read / write request, first the ORAM checks whether the required target data block exists in the on-chip stash. If the target block exists, it means a hit and the block is taken out and transmitted to the processor.
[0022] 2. If there is a miss, that is, it does not exist in the buffer Stash, then the path label of the target data block in the tree is searched from the Position Map (PosMap) and the path label of the target block is re-randomized to map in order to confuse external attackers.
[0023] 3. The on-chip ORAM controller actively sends a request to the memory to read all data blocks on the path according to the path label found on the PosMap. In order to prevent the leakage of private data information, all data blocks (real blocks and virtual blocks) in the bucket nodes on the entire path are read into the stash for operation.
[0024] 4. After the system re-randomizes and maps the path label of the required target block, the latest path label and the latest target block value need to be updated.
[0025] 5. After the processor performs corresponding operations on the target block, the original read data blocks are evicted along the original path and stored in the memory. At this time, during the process of evicting the path, when the real data blocks are not enough to fill all the bucket nodes, the remaining data blocks on the original path are filled with randomly generated virtual data blocks to confuse external attackers and protect the memory access pattern.
[0026] Custom concepts in this embodiment: RS Error Correction Code: Leveraging the powerful error correction capabilities of Reed-Solomon (RS) codes, an RS encoding / decoding module is set up in the ORAM system. When data is tampered with or damaged during transmission or storage, the RS encoding / decoding restores the original data through the remaining redundant information, ensuring data integrity.
[0027] Security Factor Seed: The security seed factor is a randomly generated value that is generated by the client each time data is encoded and participates in polynomial calculations as part of the encoding process.
[0028] Reference to "embodiments" in this document means that the specific features, structures, or characteristics described in connection with the embodiments can be included in at least one embodiment of the present application. The phrase may not necessarily refer to the same embodiment at every occurrence in the specification, nor is it an independent or alternative embodiment mutually exclusive with other embodiments. Those skilled in the art will explicitly and implicitly understand that the embodiments described herein can be combined with other embodiments.
[0029] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are some, but not all, of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts fall within the scope of protection of the present invention.
[0030] Please refer to Figure 1 As shown in Figure 1 , the system architecture 100 may include terminal devices 101, 102, 103, a network 104, and a server 105. The network 104 serves as a medium for providing a communication link between the terminal devices 101, 102, 103 and the server 105. The network 104 may include various connection types, such as wired, wireless communication links, or fiber optic cables, etc.
[0031] Users can use the terminal devices 101, 102, 103 to interact with the server 105 through the network 104 to receive or send messages, etc.
[0032] The terminal devices 101, 102, and 103 can be various electronic devices with a display screen and supporting web browsing, including but not limited to smart phones, tablet computers, e-book readers, MP3 players (Moving Picture Experts Group Audio Layer III), MP4 (Moving Picture Experts Group Audio Layer IV) players, laptop computers, desktop computers, and so on.
[0033] The server 105 can be a server that provides various services, such as a background server that supports the pages displayed on the terminal devices 101, 102, and 103.
[0034] It should be noted that the data access control method provided by the embodiments of the present application is executed by the server. Correspondingly, the data access control device is set in the server.
[0035] It should be understood that Figure 1 the numbers of terminal devices, networks, and servers in
[0036] Please refer to Figure 2 , Figure 2 which shows a data access control method provided by an embodiment of the present invention. Taking the application of this method in the Figure 1 server side in S201: Initialize the storage of the data to be stored. The initialization storage includes location mapping and RS coding, and store the encoded data blocks into the ORAM binary tree.
[0037] Among them, RS coding is one of the most commonly used erasure codes, supporting arbitrary code rates, code lengths, and fault tolerance. Given two positive integers n and k, the RS(n, k) code can encode n data blocks into k parity check blocks, such that any one of the n + k blocks can be recovered from any other n blocks. All n + k data / parity check blocks form a stripe, and the stripe size is n + k. Therefore, an RS(n, k) code allows any k blocks to be lost in a stripe, achieving the maximum distance separable property (MDS). In addition, RS coding satisfies the linear property. That is, given an RS(n, k) code, a certain data block Bi in any n data blocks can be expressed as a linear combination of any other n different blocks B0, B1, …, Bn-1 in the same stripe, and Bi can be obtained through calculation, where Ci(0 ≤ i ≤ n ≤ 1) is the decoding coefficient specified by the given RS code.
[0038] This embodiment is applicable to the processes of data transmission and storage in a cloud environment (such as cloud storage, financial transactions, and medical data transmission) to protect private data, improve data security and integrity, and prevent external attackers from tampering with and damaging data. Considering that the application of traditional ORAM methods may cause data to be maliciously tampered with during transmission, if these tampering behaviors cannot be detected and repaired in a timely manner, data integrity will be seriously threatened. Therefore, the specific system structure diagram designed in this solution is as Figure 3 shown. Figure 3 is a structural example diagram of a verifiable ORAM system based on RS error correction code in the data access control method of this application. In an actual scenario, the upper part is an untrusted data storage area, and the lower part is a trusted memory controller. In the untrusted data storage, a tree structure (binary tree) is adopted to store data in order to prevent data privacy leakage and reduce ORAM access overhead. The memory controller in the lower part is located in the trusted area, and external attackers cannot infer the privacy of the data. Among them, a data encoding / decoding module is added to the memory controller in this solution to add RS error correction code to the data to prevent data from being tampered with and corrected in a timely manner to maintain data integrity.
[0039] In a specific optional implementation manner, in step S201, the initialization storage of the data to be stored includes: When it is detected that the data is first stored in the untrusted memory, the detected data is used as the data to be stored, and the data to be stored is used as the basic data block; The path label is allocated to the basic data block through the position mapping table PosMap and the path where it is located is recorded; The basic data block is encrypted, and RS coding is performed on the encrypted basic data block and a security coefficient seed is introduced to obtain an encrypted and encoded data block; Store the encrypted and encoded data block into the ORAM binary tree.
[0040] Specifically, when data is first stored in the untrusted memory, the memory controller of the ORAM system will first allocate a leaf label for the data block to be stored through the position mapping table PosMap (Position Map) and record it; For example, if there is a data block a to be stored in the memory, then the system will allocate a path label l corresponding to the physical address for it. The label l is one of any leaf nodes in the current binary tree. The data block a will finally be stored on the path connecting this leaf node and the root node, and then the data block a will be recorded in the position mapping table PosMap so that the system can find this data block when needed next time. Another example, Figure 3 The data block a in is marked on the path label l1 and recorded in the position mapping table PosMap, where Stash is the cache library for storing caches, data1, data2, are the stored data, addr1 and addr2 are the cache addresses corresponding to data1 and data2 respectively, l i is the path label corresponding to the i-th data block written from the position mapping table to the cache library, l i ’ is the path label corresponding to the i-th data block read from the cache library to the position mapping table, l1 and l4 are the path labels of the first and fourth data blocks in the position mapping table respectively, l1’ and l4’ are the path labels of the first and fourth data blocks in the cache library respectively, LLC is the last-level cache (LastLevel Cache), W is data writing, R is data reading, and the meaning of (W, addr2, data2) is to write the data data2 in the LLC to the cache address addr2 in the cache library, (R, addr1, ) means to read the data from the storage space address addr1 in the trusted area into the LLC.
[0041] Currently, the memory in a computer is only used to store data. In the cloud environment, there are still privacy and security issues such as data being tampered with and data being leaked. Therefore, if no processing is done to the data, we usually say that the memory is not trustworthy. So, generally, the memory is untrusted.
[0042] Secondly, in this embodiment, the data block is encrypted (using common encryption methods, such as AES symmetric encryption) to ensure the confidentiality of the data content; then RS coding is performed on the data block and a security factor seed is introduced to prevent the data from being tampered with and damaged, verifying and ensuring data integrity; finally, the encrypted and encoded data blocks are stored in the ORAM binary tree. It should be noted that the process of storing the encrypted and encoded data blocks in the ORAM binary tree is different from ordinary data. The ORAM binary tree is memory, but it stores data in the form of a binary tree. Ordinary data generally needs to read the corresponding data block according to the target data block required by the system and then store it back to the corresponding position. While ORAM reads all the data blocks on the entire path according to the path label for operation, and only one data block is needed by the processor, and then stores all the read data blocks into the memory binary tree.
[0043] In a specific optional implementation manner, performing RS coding on the encrypted basic data block and introducing a security factor seed to obtain an encrypted and encoded data block includes: Dividing the encrypted basic data block into several small data blocks of a fixed size; Performing an exclusive OR operation on each small data block using the security seed coefficient S to generate a confused data block, where the security seed coefficient S is a random value generated by a dynamic generation algorithm based on the encryption key; Using the confused data block as a coefficient to construct a data polynomial , the data polynomial As the basis of the coding process, it contains all the information of the confused data blocks, and based on the RS coding method, for the data polynomial Generate check information to obtain a check polynomial; Combine the data polynomial and the check polynomial to construct a transmission polynomial, and use the transmission polynomial as the encrypted and encoded data block.
[0044] Specifically, in the data coding stage, in order to ensure that the system can provide additional security in the face of replay attacks and at the same time achieve efficient verification of data integrity, the system preprocesses the data. The encrypted data is first divided into multiple small data blocks of a fixed size .
[0045] At the same time, in order to prevent replay attacks, this solution introduces a dynamically generated security seed coefficient S, and confuses each data block through an exclusive OR operation to generate a confused data block , where S is a random value generated by a dynamic generation algorithm based on the encryption key, ensuring the uniqueness of each coding operation.
[0046] The safety factor S is generated based on the specific conditions of the encoded data at that time and is not fixed. For example, in terms of time, if a data block a starts encoding at 6:30, then the coefficient S will obtain S1 according to the algorithm by incorporating the time factor. And if a data block b starts encoding at 9:30, then the algorithm incorporating the time factor will obtain a coefficient S2. These two coefficients are different, so it is dynamically generated according to the different characteristics of the data blocks. Specifically as follows: In the research on the dynamic generation of the coefficient seed S, the coefficient seed may be related to parameters such as data characteristics, encoding time, etc. For example, the encoding rate and encoding time are important indicators for measuring the dynamic generation of the coefficient seed.
[0047] In a specific example, the calculation formula for the coefficient seed is:
[0048] Among them, T i is the time from the start of data encoding to the i-th time interval, and N i is the number of characters in the data encoded within the i-th time interval.
[0049] Next, taking as the coefficient to construct the data polynomial . The data polynomial serves as the basis for the encoding process and contains all the information of the scrambled data blocks.
[0050] To achieve the verification of data integrity and the correction of potential errors, the system generates verification information based on the RS coding method. First, select a generating polynomial , and generate the verification polynomial by performing a modulo operation on the data polynomial Among them, is the remainder of the data polynomial with respect to the generating polynomial , which is used to detect whether the data is complete.
[0051] Among them, G(X) is the generating polynomial because G(X) is used for two purposes. One is to perform a modulo operation to generate the final verification polynomial R(X) to verify data integrity, and the other is to increase the complexity of data encoding to prevent it from being cracked and leaked. The specific generation of G(X) is to randomly generate a polynomial by the system. For example: G(X) = aX 2 +bX + c, where a, b, c are the polynomial coefficients.
[0052] Among them, R(X) is the verification polynomial, , and the mod algorithm is the idea of finding the remainder. For example, 5 mod 3 = 2. Similarly, polynomials can also be mutually modded to obtain a new remainder polynomial.
[0053] Finally, the system combines the data polynomial and the parity polynomial to construct the transmission polynomial , where 2t is the error correction capability of RS coding, indicating that this coding method can correct up to t symbol errors at most. By shifting by 2t powers and then combining it with , the data block and parity information can be effectively stored, and efficient decoding and error correction can be achieved.
[0054] In this embodiment, in order to enhance the defense ability of RS coding in security-sensitive environments, especially to cope with the challenge of replay attacks, a security seed coefficient is proposed to be introduced. By adding a randomly generated security seed coefficient during the RS coding process, it is ensured that each encoded data block is unique, thereby preventing attackers from deceiving the system through replay attacks and verifying data integrity. In addition, there is an encryption / decryption circuit in the controller to perform encryption / decryption operations on the data block to ensure the confidentiality of the data content.
[0055] It should be noted that by adding a randomly generated security seed coefficient during the RS coding process, even if the data blocks have the same content, the encoding results at different times will be different, ensuring that each encoded data block is unique, thereby verifying data integrity and preventing attackers from deceiving the system through replay attacks. Implement error correction and verifiable storage of data, thereby improving the overall performance and security of the system and ensuring the stability of data during transmission and storage.
[0056] S202: When receiving a data access request, send a read / write request to the ORAM binary tree, so that after the memory controller receives the request, it searches in the buffer Stash to check if there is a target data block, and receives the search result, where the target data block is the data block corresponding to the request address in the data access request.
[0057] Specifically, in the controller, the buffer Stash and the position mapping table Position Map (PosMap) are also key components in the ORAM system.
[0058] The buffer Stash buffer is mainly used to store the data blocks on the entire path read from the above-mentioned untrusted memory, and then find the target data block required by the system and return the data to the processor through the LLC for read / write operations. After the read / write is completed, the buffer Stash will return the just-read data block along the original path of the binary tree and store it again.
[0059] The PosMap is mainly used to mark the path labels of data blocks stored in the binary tree, and will re-map the path labels of the target data block just read and then update them. Usually, the processor issues a data read / write request Resquest=(op=Read / Write, addr, data) to the memory through the LLC, so as to access the data in the storage under the protection of the ORAM system.
[0060] S203: If the search result is existent, process the target data block according to the read / write request.
[0061] Specifically, if found (Stash hit), process the data block according to the operation and return it to the processor.
[0062] S204: If the search result is non-existent, determine the real physical memory location of the target data block through the position mapping table, and re-map the path label of the target data block to a new random path.
[0063] Specifically, if not found (Stash miss), access the position mapping table PosMap and look up the leaf label of the target data block required by the system to determine the actual physical memory location of the target block, access the memory, and load the target path. At the same time, the system re-maps the path label of the target data block to a new random path to confuse external attackers and updates it to the new path label on the PosMap.
[0064] S205: Read the path where the target data block is stored in the ORAM binary tree, and use RS to decode all the data blocks included in the path, and store the data to be stored into the buffer Stash.
[0065] Specifically, the system reads all the data blocks (real data blocks and virtual data blocks) on the path found from the PosMap in the ORAM tree in the memory to the Stash buffer. Since the data is stored after being encrypted and RS encoded in step 1, it is necessary to first RS decode all the data blocks included in the path, then decrypt all the data blocks, and finally store the real data blocks into the Stash. If during the RS decoding process, there is a real data block that matches the target data block requested by the system, data integrity and error correction can be verified during the decoding process. If the data is error-free, the data block can enter the next step for normal processing, otherwise use RS error correction to restore the data.
[0066] In a specific optional implementation manner, in step S205, using RS to decode all the data blocks included in the path and storing the data to be stored into the buffer Stash includes: Read all the data blocks on the path found from the position mapping table PosMap; Adopt all the data blocks included in the RS decoding path and decrypt all the data blocks to obtain the real data blocks, and store the real data blocks in the Stash; If, during the RS decoding process, there is a real data block that matches the target data block requested by the system, data integrity and error correction can be verified during the decoding process. If there is no error in the data, the data block can enter the next step for normal processing. Otherwise, use RS error correction to restore the data.
[0067] In a specific optional embodiment, adopting all the data blocks included in the RS decoding path and decrypting all the data blocks to obtain the real data blocks includes: Extract the transmission polynomial from the data blocks read from the ORAM tree; Reconstruct the secure seed coefficient S'; According to the transmission polynomial and the secure seed coefficient S', separate the transmission polynomial into a data polynomial and a parity polynomial; Use the parity checking mechanism of RS coding to verify the data integrity of the data polynomial and the parity polynomial. If the data is damaged or tampered with, use the RS error correction ability to repair the data; Decode the data polynomial to restore the encrypted data block to obtain the real data block.
[0068] Specifically, the RS decoding process is as follows: (1) During the decoding process, the system extracts the stored transmission polynomial from the data blocks read from the ORAM tree , which is composed of the data polynomial and the parity polynomial combined. .
[0069] (2) To correctly decode the data, the system first needs to reconstruct the secure seed coefficient S, which is a randomly generated random confusion parameter during encoding. The identification information of the secure seed is embedded in the transmission polynomial . During decoding, the corresponding secure seed S is found through the identification information. This process ensures that the decoding operation is consistent with the security parameters of the encoding process.
[0070] (3) After extracting the transmission polynomial , decompose it into the data polynomial and the parity polynomial through polynomial separation operation. First, obtain the data polynomial by extracting the high-order part of , and then separate the parity polynomial by calculating After separation, the polynomials respectively represent the data content and its integrity verification information, providing input for subsequent decoding and verification.
[0071] (4) Then, to ensure that the extracted data has not been tampered with or damaged, the check mechanism of RS coding is used to verify the data integrity.
[0072] (5) After the data integrity verification passes, the data polynomial is decoded to restore the encrypted data block. The security seed S used in the confusion process is restored to the original data through XOR operation during the decoding process: , where is the data block before decoding, is the restored encrypted data block. Since S is a dynamically generated and highly secure random number, the decoding operation can effectively reverse the confusion process of the data block, ensuring that the restored data block is consistent with the original data before encoding.
[0073] (6) The data block after integrity verification and data decoding is recombined into the complete ciphertext data required by the user, which can be decrypted subsequently and transmitted to Stash for processing. At this time, the decoding result has passed the check mechanism of RS coding and the protection of the security seed, ensuring the integrity and security of the data.
[0074] Further, the check mechanism of RS coding to verify the data integrity is executed in the following way: ① Through the reconstructed and the generating polynomial , calculate and verify the check polynomial .
[0075] ② Compare the calculated with the extracted . If the two are consistent, the data integrity verification passes; otherwise, the data is considered to be damaged or tampered with. In the case of verification failure, the error correction ability of the RS code can be used to attempt to repair the errors in the data.
[0076] Through the RS decoder, up to t symbol errors can be corrected, and the complete can be reconstructed. If the number of error symbols exceeds the error correction ability, the error handling mechanism is triggered to request the data from ORAM again for recovery.
[0077] S206: Update the buffer Stash and process the target data block according to the read and write requests.
[0078] Specifically, update the path label of the target data block read into the buffer Stash. In addition, if the system is processing a read request, return the target data to the processor; otherwise, if the system is processing a write operation, update the content of the data block. In this case, the target data block in the buffer Stash has the latest value and the latest path label.
[0079] S207: After the data access request is completed, encrypt all the read data blocks for which the operation is completed, then perform RS encoding on all the data blocks, and evict all the data blocks after encryption and encoding according to the original read path.
[0080] Specifically, after the operation of the target data block of this request is completed, the system first encrypts all the read data blocks for which the operation is completed, then performs RS encoding on all the target paths and introduces a security seed coefficient (for details, refer to the description of the above embodiments. To avoid repetition, it will not be elaborated here), and finally evicts all the data blocks after encryption and encoding according to the original read path. During the eviction process, traverse the data blocks in the Stash, and according to the path label of each data block, try to place all the data blocks into the buckets on the target path until each bucket reaches its capacity limit. Therefore, finally all the data blocks continue to be stored on the ORAM tree, waiting for the next access call from the system.
[0081] It should be noted that in this embodiment, by introducing a security seed coefficient, RS encoding not only retains its powerful error correction ability but also enhances the security and uniqueness of the data. This method shows significant advantages in applications facing security-sensitive scenarios, such as cloud storage, financial transactions, and medical data transmission. It can provide effective defense against replay attacks while ensuring data integrity, providing a more reliable guarantee for the secure transmission and storage of data.
[0082] In a specific optional implementation manner, performing position mapping and RS encoding on all the target paths and evicting all the data blocks after encryption and encoding according to the original read path includes: Performing RS encoding on all the target paths and introducing a security seed coefficient to obtain secondarily encoded data blocks; Evicting all the secondarily encoded data blocks according to the original read path, traversing the data blocks in the buffer Stash, and according to the path label of each data block, trying to place all the data blocks into the buckets on the target path until each bucket reaches its capacity limit. Finally, all the data blocks continue to be stored on the ORAM binary tree, waiting for the next access call from the system.
[0083] In this embodiment, the data to be stored is initialized for storage. The initialization storage includes position mapping and RS coding, and the encoded data blocks are stored in the ORAM binary tree. When a data access request is received, a read / write request is sent to the ORAM binary tree, so that after receiving the request, the memory controller searches in the buffer Stash to see if there is a target data block and receives the search result. If the search result is that it exists, the target data block is processed according to the read / write request. If the search result is that it does not exist, the true physical memory location of the target data block is determined through the position mapping table, and the path label of the target data block is remapped to a new random path. The path where the target data block is stored in the ORAM binary tree is read, and all the data blocks included in the path are decoded using RS. The data to be stored is stored in the buffer Stash. The buffer Stash is updated, and the target data block is processed according to the read / write request. After the data access request is completed, all the read data blocks that have completed the operation are encrypted, then all the data blocks are RS-encoded, and all the encrypted and encoded data blocks are evicted according to the original read path. By using the powerful error correction ability of RS codes, an RS encoding / decoding module is set in the ORAM system. When the data is tampered with and damaged during transmission or storage, the RS encoding / decoding restores the original data through the remaining redundant information, ensuring the integrity of the data and improving the security of the ORAM system during the data access process.
[0084] It should be understood that the magnitudes of the sequence numbers of the steps in the above embodiments do not imply the order of execution. The order of execution of each process should be determined according to its function and internal logic, and should not constitute any limitation to the implementation process of the embodiments of the present invention.
[0085] Figure 4 The principle block diagram of a data access control device corresponding one-to-one to the data access control method in the above embodiment is shown. As Figure 4 shown, the data access control device includes an initialization storage module 31, a request response module 32, a first processing module 33, a second processing module 34, a read decoding module 35, a buffer update module 36, and a re-encoding module 37. The detailed descriptions of each functional module are as follows: The initialization storage module 31 is used to initialize the storage of the data to be stored. The initialization storage includes position mapping and RS coding, and the encoded data blocks are stored in the ORAM binary tree; The request response module 32 is used to send a read / write request to the ORAM binary tree when a data access request is received, so that after the memory controller receives the request, it searches in the buffer Stash to see if there is a target data block and receives the search result, where the target data block is the data block corresponding to the request address in the data access request; The first processing module 33 is configured to process the target data block according to the read / write request if the search result is existent; The second processing module 34 is configured to determine the real physical memory location of the target data block through the location mapping table and remap the path label of the target data block to a new random path if the search result is non-existent; The read decoding module 35 is configured to read the path where the target data block is stored in the ORAM binary tree, decode all the data blocks included in the path by using RS, and store the data to be stored into the buffer Stash; The buffer update module 36 is configured to update the buffer Stash and process the target data block according to the read / write request; The re-encoding module 37 is configured to, after the data access request is completed, perform an encryption operation on all the read data blocks for which the operation is completed, then perform RS encoding on all the data blocks, and evict all the encrypted and encoded data blocks according to the path read originally.
[0086] Optionally, the initialization storage module 31 includes: The basic data block determination sub-module is configured to use the detected data as the data to be stored and use the data to be stored as the basic data block when it is detected that the data is first stored in the untrusted memory; The path generation sub-module is configured to allocate a path label for the basic data block through the location mapping table PosMap and record the path where it is located; The encryption and encoding sub-module is configured to perform an encryption operation on the basic data block, perform RS encoding on the encrypted basic data block, and introduce a security coefficient seed to obtain an encrypted and encoded data block; The data storage sub-module is configured to store the encrypted and encoded data block into the ORAM binary tree.
[0087] Optionally, the encryption and encoding sub-module includes: The data splitting unit is configured to divide the encrypted basic data block into several small data blocks of a fixed size; The data confusion unit is configured to perform an exclusive OR operation on each small data block by using the security seed coefficient S to generate a confused data block, where the security seed coefficient S is a random value generated by a dynamic generation algorithm based on the encryption key;
[0088] The polynomial processing unit is configured to construct a data polynomial by using the confused data block as a coefficient , the data polynomial serves as the basis for the encoding process, includes all the data block information after confusion, and generates check information based on the RS encoding method for the data polynomial to obtain a check polynomial; An encoded data block generation unit is configured to combine a data polynomial and a check polynomial to construct a transmission polynomial, and use the transmission polynomial as an encrypted encoded data block.
[0089] For the specific limitations of the data access control device, reference may be made to the limitations of the data access control method in the foregoing text, which will not be elaborated here. Each module in the above data access control device can be implemented in whole or in part by software, hardware, and their combination. Each of the above modules can be embedded in or independent of the processor in the computer device in the form of hardware, or stored in the memory in the computer device in the form of software, so as to facilitate the processor to call and execute the operations corresponding to each of the above modules.
[0090] To solve the above technical problems, an embodiment of the present application also provides a computer device. Specifically, please refer to Figure 5 , Figure 5 which is the basic structural block diagram of the computer device in this embodiment.
[0091] The computer device 4 includes a memory 41, a processor 42, and a network interface 43 that are communicatively connected to each other through a system bus. It should be noted that only the computer device 4 with components connected to the memory 41, the processor 42, and the network interface 43 is shown in the figure. However, it should be understood that it is not required to implement all the shown components, and more or fewer components can be alternatively implemented. Among them, those skilled in the art of the present technology can understand that the computer device here is a device that can automatically perform numerical calculations and / or information processing according to pre-set or stored instructions, and its hardware includes but is not limited to microprocessors, application specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), digital signal processors (DSPs), embedded devices, etc.
[0092] The computer device can be a computing device such as a desktop computer, a notebook, a palm computer, and a cloud server. The computer device can perform human-computer interaction with the user through means such as a keyboard, a mouse, a remote control, a touchpad, or a voice control device.
[0093] The memory 41 at least includes one type of readable storage medium, and the readable storage medium includes flash memory, hard disk, multimedia card, card-type memory (such as SD or D interface display memory, etc.), random access memory (RAM), static random access memory (SRAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), programmable read-only memory (PROM), magnetic memory, magnetic disk, optical disc, etc. In some embodiments, the memory 41 may be an internal storage unit of the computer device 4, such as the hard disk or memory of the computer device 4. In other embodiments, the memory 41 may also be an external storage device of the computer device 4, such as a plug-in hard disk, Smart Media Card (SMC), Secure Digital (SD) card, Flash Card, etc. equipped on the computer device 4. Of course, the memory 41 may also include both the internal storage unit and the external storage device of the computer device 4. In this embodiment, the memory 41 is generally used to store the operating system and various application software installed in the computer device 4, such as the program code of the data access control method. In addition, the memory 41 may also be used to temporarily store various data that have been output or will be output.
[0094] In some embodiments, the processor 42 may be a central processing unit (CPU), controller, microcontroller, microprocessor, or other data processing chip. The processor 42 is generally used to control the overall operation of the computer device 4. In this embodiment, the processor 42 is used to run the program code stored in the memory 41 or process data, such as running the program code of the data access control method.
[0095] The network interface 43 may include a wireless network interface or a wired network interface, and the network interface 43 is generally used to establish a communication connection between the computer device 4 and other electronic devices.
[0096] This application also provides another implementation manner, that is, to provide a computer-readable storage medium, and the computer-readable storage medium stores an interface display program, and the interface display program can be executed by at least one processor, so that the at least one processor executes the steps of the data access control method as described above.
[0097] Through the description of the above embodiments, those skilled in the art can clearly understand that the methods of the above embodiments can be implemented by means of software plus a necessary general hardware platform. Of course, they can also be implemented by hardware, but in many cases the former is a better implementation. Based on such an understanding, the technical solution of the present application, in essence, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk) and includes several instructions for causing a terminal device (which can be a mobile phone, computer, server, air conditioner, or network device, etc.) to execute the methods described in various embodiments of the present application.
[0098] Obviously, the above-described embodiments are only a part of the embodiments of the present application, rather than all embodiments. The preferred embodiments of the present application are given in the drawings, but they do not limit the patent scope of the present application. The present application can be implemented in many different forms. On the contrary, the purpose of providing these embodiments is to make the understanding of the disclosed content of the present application more thorough and comprehensive. Although the present application has been described in detail with reference to the foregoing embodiments, those skilled in the art can still modify the technical solutions described in the foregoing specific embodiments, or perform equivalent replacements on some of the technical features. Any equivalent structure directly or indirectly using the content of the specification and drawings of the present application in other related technical fields is equally within the scope of the patent protection of the present application.
Claims
1. A data access control method, characterized in that: include: Initialize the storage of the data to be stored, wherein the initialization storage includes position mapping and RS encoding, and store the encoded data blocks in the ORAM binary tree; When receiving a data access request, a read / write request is sent to the ORAM binary tree, so that the memory controller searches the buffer Stash for a target data block after receiving the request, and receives the search result, wherein the target data block is a data block corresponding to the request address in the data access request; If the search result is yes, processing the target data block according to the read / write request; If the search result is that the target data block does not exist, the real physical memory location of the target data block is determined through the location mapping table, and the path label of the target data block is remapped to a new random path; Read the path where the target data block is stored in the ORAM binary tree, and use RS to decode all the data blocks included in the path to store the data to be stored in the buffer Stash; Update the buffer Stash and process the target data block according to the read and write request; When the data access request is completed, all the read data blocks that have completed the operation are encrypted, and then all the data blocks are RS-encoded, and all the encrypted data blocks are expelled according to the original read path.
2. The data access control method according to claim 1, characterized in that: The initializing storage of the data to be stored includes: When it is detected that data is stored in the untrusted memory for the first time, the detected data is used as data to be stored, and the data to be stored is used as a basic data block; Assign path labels to the base data blocks and record the paths they are on through the position mapping table PosMap; Perform encryption operation on the basic data block, perform RS encoding on the encrypted basic data block and introduce a security factor seed to obtain an encrypted coded data block; The encrypted coded data block is stored in an ORAM binary tree.
3. The data access control method according to claim 2, characterized in that: The step of performing RS encoding on the encrypted basic data block and introducing a security factor seed to obtain an encrypted coded data block comprises: Divide the encrypted basic data block into several small data blocks of fixed size; Perform an XOR operation on each small data block using a security seed coefficient S to generate an obfuscated data block, wherein the security seed coefficient S is a random value generated by a dynamic generation algorithm based on an encryption key; Use the obfuscated data blocks as coefficients to construct a data polynomial , data polynomial As the basis of the encoding process, it contains all the obfuscated data block information and is based on the RS encoding method for the data polynomial Generate verification information and obtain a verification polynomial; The data polynomial and the check polynomial are combined to construct a transmission polynomial, and the transmission polynomial is used as the encrypted coded data block.
4. The data access control method according to claim 1, characterized in that: The method of using all data blocks included in the RS decoding path to store the data to be stored in the buffer Stash includes: Read all data blocks on the path found from the position mapping table PosMap; Use RS to decode all data blocks contained in the path and decrypt all data blocks to obtain the real data blocks, and store the real data blocks in Stash; If during the RS decoding process, there is a real data block that matches the target data block requested by the system, the data integrity and error correction can be verified during the decoding process. If there is no error in the data, the data block can proceed to the next step for normal processing. Otherwise, RS error correction is used to restore the data.
5. The data access control method according to claim 4, characterized in that: The method of using all data blocks included in the RS decoding path and decrypting all data blocks to obtain real data blocks includes: Extract the transfer polynomial from the data block read from the ORAM tree; Reconstruct the security seed coefficient S'; According to the transmission polynomial and the security seed coefficient S', separating the transmission polynomial into a data polynomial and a check polynomial; Use the RS-coded verification mechanism to verify the data polynomial and the check polynomial for data integrity. If the data is damaged or tampered with, use the RS error correction capability to repair the data. Decoding the data polynomial restores the encrypted data block to obtain the real data block.
6. The data access control method according to any one of claims 1 to 5, characterized in that: The position mapping and RS encoding of all target paths and the expulsion of all encrypted and encoded data blocks according to the originally read paths include: Perform RS encoding on all target paths and introduce security seed coefficients to obtain secondary encoded data blocks; All the secondary encoded data blocks are evicted according to the original read path, and the data blocks in the buffer Stash are traversed. According to the path label of each data block, all data blocks are tried to be placed in the storage bucket on the target path until each storage bucket reaches the capacity limit. Finally, all data blocks continue to be stored in the ORAM binary tree, waiting for the next access call of the system.
7. A data access control device, characterized in that: include: An initialization storage module is used to initialize the storage of the data to be stored, wherein the initialization storage includes position mapping and RS encoding, and the encoded data blocks are stored in an ORAM binary tree; A request response module, configured to send a read / write request to the ORAM binary tree upon receiving a data access request, so that the memory controller searches the buffer Stash for a target data block after receiving the request, and receives the search result, wherein the target data block is a data block corresponding to the request address in the data access request; A first processing module, configured to process the target data block according to a read / write request if the search result is yes; A second processing module is configured to determine the real physical memory location of the target data block through a location mapping table if the search result is non-existent, and remap the path label of the target data block to a new random path; A reading and decoding module is used to read the path where the target data block is stored in the ORAM binary tree, and use all the data blocks included in the RS decoding path to store the data to be stored in the buffer Stash; A buffer update module, used for updating the buffer Stash and processing the target data block according to the read and write request; The re-encoding module is used to encrypt all the read data blocks after the data access request is completed, then perform RS encoding on all the data blocks, and evict all the encrypted data blocks according to the original read path.
8. The data access control device according to claim 7, characterized in that: The initialization storage module comprises: A basic data block determination submodule, used to, when it is detected that data is stored in the untrusted memory for the first time, use the detected data as data to be stored, and use the data to be stored as a basic data block; The path generation submodule is used to assign path labels to the basic data blocks through the position mapping table PosMap and record the path; The encryption coding submodule is used to perform encryption operation on the basic data block, and perform RS encoding and introduce a security factor seed on the encrypted basic data block to obtain an encrypted coded data block; The data storage submodule is used to store the encrypted coded data block in the ORAM binary tree.
9. A computer device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that: When the processor executes the computer program, the data access control method according to any one of claims 1 to 6 is implemented.
10. A computer-readable storage medium storing a computer program, characterized in that: When the computer program is executed by a processor, the data access control method according to any one of claims 1 to 6 is implemented.
Citation Information
Patent Citations
Multi-path cache write-back method and device based on Path + ORAM (Optical Random Access Memory) and related equipment
CN117094037A
Data access control method and device, computer equipment and storage medium
CN118277628A
ORAM optimization strategy in multi-user shared storage scene
CN118627129A
Calculation method and system for information security
CN119691780A
Method and system for search pattern oblivious dynamic symmetric searchable encryption
WO2018122287A1
Cited By
Method and apparatus for indexing with constant height based on cache- crafty, disaggregated memory environment
KR102949667B1