Cache data security protection system based on cloud computing
By designing a cloud-based cached data security protection system, the problem of neglected cached data security in the cloud computing environment is solved, and effective security management of cached data is achieved, preventing attacks, and ensuring the security and availability of data.
Patent Information
- Application Number
- CN202510303375.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-14
- Publication Date
- 2025-06-27
AI Technical Summary
In cloud computing environments, the security of cached data is often ignored and may become a potential target of attacks, resulting in unauthorized access, cache poisoning, data tampering and other problems, which in turn causes serious financial losses and reputation damage.
Design a cached data security protection system based on cloud computing, including data acquisition module, cloud storage module, verification execution module, security processing module and protection early warning module. By collecting and preprocessing cached data in real time, the system uses a distributed storage architecture and a variety of encryption algorithms to identify and classify secure signals, generate signaling that allows or prohibits cache, and conducts real-time analysis and early warning to ensure the confidentiality, integrity and availability of data.
By enhancing control over cached data, a variety of encryption algorithms and access control policies are adopted to ensure data security, prevent unauthorized access and data tampering, and reduce the risk of financial losses and reputation damage.
Smart Images

Figure CN120217413A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of security protection, and more specifically, to a security protection system for cached data based on cloud computing. Background Art
[0002] With the rapid development and wide application of cloud computing technology, enterprises and individuals are increasingly relying on cloud computing services to process and store data; cloud computing, as a computing model based on the Internet, allows users to access and share computing resources, such as computing power, storage space, and applications, over the network without having to own or maintain the actual hardware and software infrastructure; this model brings many advantages, including cost-effectiveness, scalability, convenience, and innovation, greatly promoting the progress of information technology.
[0003] However, in actual use, there are still some drawbacks. For example, users often rely on third-party service providers for data storage and management, which reduces the user's control over the data; cached data, as an important means to improve system performance and response speed, is often frequently used in high-concurrency scenarios; however, the security of cached data is often overlooked and may become a potential target for attacks; attack behaviors such as unauthorized access, cache poisoning, and data tampering can all lead to serious financial losses and damage to reputation. Summary of the Invention
[0004] In order to overcome the above-mentioned defects of the prior art, an embodiment of the present invention provides a security protection system for cached data based on cloud computing to solve the problems raised in the above background art.
[0005] To achieve the above object, the present invention provides the following technical solutions:
[0006] Data acquisition module: used to collect cached data within the platform and transmit the collected data to be approved and IP data to the cloud storage module;
[0007] Cloud storage module: used to store the input information, data to be approved, and IP data;
[0008] Verification and execution module: used to identify security exception signals, security stability signals, and security deviation signals, and generate an allow execution signaling or a prohibit caching signaling;
[0009] Security processing module: used to perform security processing on the sorted input information and the record information in the cloud storage module, thereby converting the cached data into calculation processing data, and transmitting the conversion value to the protection and warning module;
[0010] Protection and warning module: used to perform warning analysis on the calculated and processed data, the data to be approved, and the IP data, so as to perform security comparison on the cached data, and generate security exception signals, security stability signals, and security deviation signals.
[0011] Preferably, the specific process of the data acquisition module for acquiring data is as follows: acquire the login verification information input by the user in the cache protection platform, and perform account verification on the login verification information and the entered information; according to the operation data used in the browsing and downloading interface after successful account verification, acquire the data name that the user is about to cache and the IP address of the computer, and mark them as the data to be approved and the IP data respectively;
[0012] The data acquisition module acquires the cached data in the platform through two methods: real-time acquisition and batch acquisition; in real-time acquisition, the system captures data operation records in real time through the API interface or log file of the cache node, including the read and write operations of the cached data, access timestamps, access source IP addresses, and user identity identifiers, and the identity identifiers include SessionID or Token; at the same time, the system also regularly scans the cache database through a timed task scheduler to extract unsynchronized incremental data to achieve batch acquisition; the specific method of data acquisition is as follows: deploy a lightweight proxy program on the cache node to monitor data operation events; secondly, filter out invalid and low-value data according to preset rules; then, encapsulate the acquired data into a unified format and attach metadata; finally, send the data to the cloud storage module through an encrypted channel.
[0013] Preferably, in the cloud storage module, the cloud storage module adopts a distributed storage architecture to store the entered information, the data to be approved, the IP data, and the relevant record information efficiently and securely. First, the data is classified and preprocessed before storage: the entered information is encrypted by the AES-256 algorithm and attached with a timestamp and a version number; the data to be approved is sharded, and the metadata is associated with the shard information for storage; the IP data is desensitized, and only the necessary fields are retained; the record information includes fields such as timestamps, operation types, and results for subsequent auditing and analysis; the data storage is based on a distributed file system, and a multi-copy mechanism is adopted to ensure reliability, and the data is stored in layers according to the data type and access frequency - hot data is stored on high-performance SSD nodes, and cold data is stored on high-capacity HDD nodes. When the data is sharded and stored, it is evenly distributed to multiple nodes through the consistent hashing algorithm to avoid single-point performance bottlenecks.
[0014] Preferably, in the verification execution module, three types of signals are identified and classified: For security exception signals, by real-time monitoring of cache operation behaviors and network traffic characteristics, combined with the Isolation Forest algorithm, the behavior patterns deviating from the normal baseline are identified; for security stable signals, a dynamic trust scoring model is constructed based on historical operation data. By analyzing user permission compliance, device fingerprint stability, and operation path coherence, the security confidence level is quantified; for security deviation signals, a rule engine and a Bayesian network are used for fusion analysis to detect data integrity deviation, permission overstep behavior, and protocol compliance deviation; subsequently, the three types of signals are input into the risk assessment model, and the comprehensive risk value is calculated through a weighted algorithm, and a signaling is generated based on the result: when the comprehensive risk value is lower than the security threshold, an allow execution signaling is generated, including an encryption token and an access permission label, authorizing the cache operation; when a high-risk signal is detected or the comprehensive risk value exceeds the threshold, a prohibit cache signaling is triggered to block data transmission and initiate an alarm notification; the generated signaling is transmitted to the cache execution node through a digital signature and a TLS1.3 encrypted channel to prevent signaling tampering or theft.
[0015] Preferably, in the security management module, the input information is standardized and cleaned to remove redundant fields and invalid data, and at the same time, the recorded information is de-duplicated and outlier corrected; subsequently, the sensitive fields are masked or hashed for desensitization processing to ensure privacy compliance, and are classified by tagging according to data types and uses; in the data conversion stage, a hybrid encryption algorithm is used to encrypt the data, the large-capacity data is sharded and a shard index is generated, and at the same time, the conversion value is calculated based on preset rules to generate calculation processing data including a risk score, a data heat value, and a security confidence level. The converted data is transmitted to the protection and warning module through a TLS1.3 encrypted channel, and an ECDSA digital signature and a SHA-256 hash value are added to ensure integrity, and role-based access control and attribute-based access control policies are used to restrict access permissions; to improve performance, data compression technology is used to reduce the occupied transmission bandwidth, and Redis cache is used to accelerate the access to high-frequency data; the full-link operation logs are stored in the blockchain node to achieve tamper-proof audit traceability, and at the same time, the execution results of the protection and warning module are fed back to the security processing module to dynamically optimize the data conversion rules and calculation models.
[0016] Preferably, in the protection and warning module, three types of data sources are integrated: computed data, data to be approved, and IP data. The data is associated through a unique identifier to construct a multi-dimensional analysis data set, and the data is normalized to eliminate the dimension difference. In the real-time analysis engine, the module uses the isolation forest algorithm to detect abnormal behaviors in the user operation sequence, combines the rule engine to match known attack patterns, and evaluates the risk level based on the IP reputation library. When the real-time risk score exceeds the preset threshold, a security anomaly signal is generated; a dynamic trust score model is constructed based on the user's historical operation data, and the operation path coherence score is calculated through the sliding window algorithm. When the score is higher than the benchmark value, a security and stability signal is generated; by detecting the deviation between the data to be approved and the preset security policies, including the file type blacklist and hash value mismatch; verifying the compliance of the data transmission protocol and judging the permission overstep based on the attribute-based access control model, a security deviation signal is generated.
[0017] The technical effects and advantages of the present invention:
[0018] In the present invention, the data acquisition module is responsible for collecting and preprocessing the cached data and sending it to the cloud storage module through an encrypted channel. The cloud storage module adopts a distributed architecture to classify, preprocess, and store the data to ensure the reliability and security of the data. The verification and execution module identifies and classifies security signals and generates signals to allow or prohibit caching. The security processing module performs security processing on the input information and recorded information, converts it into computed data, and transmits it to the protection and warning module. The protection and warning module integrates multi-dimensional data sources, performs real-time analysis, generates security signals, and automatically triggers signals according to the risk score threshold; the present invention enhances the user's control over the data and adopts a variety of encryption algorithms, access control policies, and log audit measures to ensure the confidentiality, integrity, and availability of the data. Description of the Drawings
[0019] Figure 1 It is a schematic diagram of the module connection of the present invention. Detailed Embodiments
[0020] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.
[0021] Please refer to Figure 1 As shown, the present invention provides a cloud computing-based cached data security protection system, which includes a data acquisition module, a cloud storage module, a verification and execution module, a security processing module, and a protection and warning module.
[0022] Data collection module: It is used to collect the cached data in the platform and transmit the collected data to be approved and IP data to the cloud storage module;
[0023] The specific process of the data collection module collecting data is as follows: collect the login verification information input by the user in the cache protection platform, and perform account verification on the login verification information and the entered information; based on the operation data in the browsing and downloading interface after successful account verification, collect the data name that the user is about to cache and the IP address of the computer, and mark them as data to be approved and IP data respectively;
[0024] The data collection module collects the cached data in the platform in two ways: real-time collection and batch collection; in real-time collection, the system captures data operation records in real time through the API interface or log file of the cache node, including read and write operations of cached data, access timestamps, access source IP addresses, and user identity identifiers, and the identity identifiers include SessionID or Token; at the same time, the system also regularly scans the cache database through a timed task scheduler to extract unsynchronized incremental data to achieve batch collection; the specific method of data collection is as follows: deploy a lightweight proxy program on the cache node to monitor data operation events; secondly, filter out invalid and low-value data according to preset rules; then, encapsulate the collected data into a unified format and attach metadata; finally, send the data to the cloud storage module through an encrypted channel.
[0025] Among them, the preset rules include sensitive fields and access frequency thresholds, and the metadata includes data sources and collection times;
[0026] The sensitive data of the data collection module is collected in real time with a delay of less than 100ms, while ordinary data is collected in a batch mode with an interval configured to be five minutes; for large-capacity data, the system performs sharded transmission, with the single transmission size not exceeding 1MB, and supports the resume function of interrupted transmission, and can resume transmission from the breakpoint after the network is interrupted to ensure data integrity; the system uses the zero-copy technology to reduce memory occupancy, uses compression algorithms to reduce network bandwidth consumption, and deploys distributed collection nodes to avoid single-point performance bottlenecks.
[0027] Cloud storage module: It is used to store the entered information, data to be approved, and IP data;
[0028] In the cloud storage module, a distributed storage architecture is adopted to store the input information, data to be approved, IP data, and related record information efficiently and securely. First, the data is classified and preprocessed before storage: the input information is encrypted by the AES-256 algorithm and appended with a timestamp and version number; the data to be approved is sharded, and the metadata is stored in association with the shard information; the IP data is desensitized, and only necessary fields are retained; the record information includes fields such as timestamp, operation type, and result, which are used for subsequent auditing and analysis; the data is stored based on a distributed file system, and a multi-copy mechanism is adopted to ensure reliability, and it is stored in layers according to the data type and access frequency - hot data is stored on high-performance SSD nodes, and cold data is stored on high-capacity HDD nodes. When the data is sharded and stored, it is evenly distributed to multiple nodes through the consistent hashing algorithm to avoid a single-point performance bottleneck;
[0029] The input information includes the user name, password hash value, and dynamic verification code configuration. The data to be approved includes the data name, file hash value, and file type cached by the user request. The IP data includes the IP address and geographical location information of the user device. The record information includes the user operation log and system audit log. The hot data is the data to be approved and IP data, and the cold data is the historical record information;
[0030] In the storage process, the cloud storage module first receives the data packet through an encrypted channel and verifies the data integrity; then, classifies the data according to the data type and encrypts the sensitive information; next, shards and stores the large-capacity data, and generates a metadata index for fast retrieval at the same time; finally, associates the input information, data to be approved, IP data, and record information through a unique identifier to build a global index to support multi-dimensional queries; all stored data is encrypted by AES-256, and the access permissions are restricted based on the RBAC and ABAC mechanisms; at the same time, the storage space occupancy is reduced through data compression, the cache mechanism is used to accelerate the access to high-frequency data, and elastic expansion is supported to dynamically adjust the storage resources; in addition, the cloud storage module records the logs of all data storage operations and stores them in an independent audit database for easy post-event traceability and security analysis.
[0031] Among them, RBAC stands for role-based access control, and ABAC stands for attribute-based access control. The logs of all data storage operations include the data reception time, storage location, and access record;
[0032] The verification execution module: is used to identify security exception signals, security stability signals, and security deviation signals, and generate an allow execution signaling or a prohibit caching signaling;
[0033] In the verification execution module, three types of signals are identified and classified: For security exception signals, by real-time monitoring of cache operation behaviors and network traffic characteristics, and combining with the isolation forest algorithm to identify behavior patterns deviating from the normal baseline; for security stable signals, a dynamic trust scoring model is constructed based on historical operation data, and by analyzing user permission compliance, device fingerprint stability, and operation path coherence, the security confidence level is quantified; for security deviation signals, a rule engine and a Bayesian network are used for fusion analysis to detect data integrity deviation, permission overstep behavior, and protocol compliance deviation; Subsequently, the three types of signals are input into the risk assessment model, and the comprehensive risk value is calculated through a weighted algorithm, and a signaling is generated based on the result: when the comprehensive risk value is lower than the security threshold, an allow execution signaling is generated, including an encryption token and an access permission label, authorizing the cache operation; when a high-risk signal is detected or the comprehensive risk value exceeds the threshold, a prohibit cache signaling is triggered, blocking data transmission and initiating an alarm notification; the generated signaling is transmitted to the cache execution node through a digital signature and a TLS1.3 encrypted channel to prevent signaling tampering or theft;
[0034] Among them, cache operation behaviors include high-frequency access and operation at unconventional times, and network traffic characteristics include abnormal IP requests and packet replay attacks; high-risk signals include data tampering and identity forgery,
[0035] The execution result of the signaling is recorded in real time. The execution result includes successful authorization and failed authorization, and is fed back to the machine learning model for online training to optimize the signal recognition accuracy; at the same time, a signaling life cycle management mechanism is established, the signaling validity period is set, and it will automatically expire and trigger re-verification after timeout; in terms of security protection, the module uses a hardware security module to protect the signaling generation key to ensure that the private key cannot be exported, and integrates role-based access control and attribute-based access control policies to limit the signaling operation permissions; The full-link operation logs are stored in the blockchain node to achieve tamper-proof audit traceability;
[0036] Among them, the full-link operation logs include the signaling generation time, execution result, and associated user information.
[0037] Security processing module: Used to perform security processing on the sorted input information and the record information in the cloud storage module, so as to convert the cache data into calculation processing data, and transmit the converted value to the protection and warning module;
[0038] In the security management module, the input information is standardized and cleaned to remove redundant fields and invalid data. At the same time, the recorded information is de-duplicated and outlier values are corrected. Subsequently, the sensitive fields are masked or hashed for desensitization to ensure privacy compliance, and are classified by tagging according to the data type and usage. In the data transformation stage, a hybrid encryption algorithm is used to encrypt the data. The large-capacity data is fragmented and a fragment index is generated. At the same time, the transformation value is calculated based on preset rules to generate calculation processing data including risk scores, data heat values, and security confidence levels. The transformed data is transmitted to the protection and warning module through a TLS1.3 encrypted channel, and an ECDSA digital signature and a SHA-256 hash value are added to ensure integrity. Role-based access control and attribute-based access control policies are used to restrict access permissions. To improve performance, data compression technology is used to reduce the occupancy of the transmission bandwidth, and Redis caching is used to accelerate the access to high-frequency data. The full-link operation logs are stored in the blockchain node to achieve anti-tampering audit traceability. At the same time, the execution results of the protection and warning module are fed back to the security processing module to dynamically optimize the data transformation rules and calculation models.
[0039] The input information includes user account data and permission configurations. The recorded information includes operation logs and audit logs. The sensitive fields include IP addresses and user identity information. The data types are divided into structured and unstructured. The hybrid encryption algorithm adopts the experimental method of combining AES-256 with the national secret SM4. The preset rules include access frequency and risk scores.
[0040] Protection and warning module: used to perform warning analysis on the calculation processing data, the data to be approved, and the IP data, so as to perform a security comparison on the cached data and generate security anomaly signals, security stability signals, and security deviation signals.
[0041] In the protection and warning module, three types of data sources are integrated: calculation processing data, data to be approved, and IP data. The data is associated through a unique identifier to construct a multi-dimensional analysis data set. At the same time, the data is normalized to eliminate the dimension difference. In the real-time analysis engine, the module uses the isolation forest algorithm to detect abnormal behaviors in the user operation sequence, combines the rule engine to match known attack patterns, and evaluates the risk level based on the IP reputation library. When the real-time risk score exceeds the preset threshold, a security anomaly signal is generated. A dynamic trust score model is constructed based on the user's historical operation data, and the coherence score of the operation path is calculated through the sliding window algorithm. When the score is higher than the benchmark value, a security stability signal is generated. By detecting the deviation between the data to be approved and the preset security policies, including the file type blacklist and hash value mismatch; verifying the compliance of the data transmission protocol and judging the permission overstep based on the attribute-based access control model, a security deviation signal is generated.
[0042] Processed data includes risk scores, data heat values and security confidence levels. Data to be approved includes data names, file hash values and metadata requested by users for caching. IP data includes user device IP addresses, geographic locations and historical behavior tags. Known attack patterns include DDoS features and SQL injection features. User operation sequences include high-frequency downloads and access at unusual times. User historical operation data includes device fingerprint consistency and permission usage compliance. Data transmission protocol compliance includes verification of TLS versions and encryption algorithms.
[0043] During the security comparison stage, the module compares the hash value of the data to be approved with the original record in the cloud storage in real time to detect data tampering, checks whether the user's current permissions match the cache operation request to prevent unauthorized access, and comprehensively evaluates the operational risks in combination with the IP geographic location, device type and network environment; the generated signal classification output: the security anomaly signal contains the attack type mark, risk level and recommended disposal measures; the security stability signal outputs the trust score, operation stability index and authorization suggestion; the security deviation signal generates deviation class, correction suggestion and associated log index; the module also supports dynamic feedback and optimization, feeds back the warning results to the machine learning model for online learning, dynamically adjusts the risk score threshold, and links with the verification execution module to automatically trigger signaling according to the signal type; in terms of security protection, the signal data is transmitted through the quantum key distribution channel and end-to-end encrypted using the national secret SM9 algorithm. At the same time, the full-link warning log is stored in the blockchain network to ensure that it cannot be tampered with, and supports multi-dimensional audit tracing by time, user or event type;
[0044] Attack type tags include brute force cracking and data tampering. Risk levels are divided into high, medium and low. Recommended disposal measures include blocking access and triggering secondary authentication. Deviation types include protocol violations and authority violations. Correction suggestions include upgrading encryption algorithms. Warning results include false alarm rate and missed alarm rate. Automatic triggering of signaling includes allowing execution of signaling and prohibiting caching of signaling. Warning logs include signal generation time, analysis basis and disposal results.
[0045] Finally: The above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of the present invention should be included in the protection scope of the present invention.
Claims
1. A cache data security protection system based on cloud computing, characterized in that: include: Data collection module: used to collect cache data in the platform and transmit the collected data to be approved and IP data to the cloud storage module; Cloud storage module: used to store input information, data to be approved, and IP data; Verification execution module: used to identify safety abnormality signals, safety stability signals and safety deviation signals, and generate execution permission signaling or cache prohibition signaling; Security processing module: used to perform security processing on the divided and organized input information and the recorded information in the cloud storage module, so as to convert the cached data into calculated and processed data, and transmit the converted values to the protection and early warning module; Protection warning module: used to perform early warning analysis on computing and processing data, data to be approved, and IP data, so as to perform security comparison on cached data and generate security anomaly signals, security stability signals, and security deviation signals.
2. The cache data security protection system based on cloud computing according to claim 1, characterized in that: The specific process of data collection by the data collection module is as follows: collecting the login verification information entered by the user in the cache protection platform, and performing account verification on the login verification information and the input information; collecting the operation data used in the browsing and downloading interface after the account verification is successful, collecting the name of the data that the user is about to cache and the IP address of the computer, and marking them as data to be approved and IP data respectively.
3. The cache data security protection system based on cloud computing according to claim 2 is characterized in that: The data collection module collects cache data in the platform through real-time collection and batch collection. In real-time collection, the system captures data operation records in real time through the API interface or log file of the cache node, including the read and write operations of the cache data, access timestamps, access source IP addresses, and user identities. The identities include Session ID or Token. At the same time, the system also regularly scans the cache database through the scheduled task scheduler to extract unsynchronized incremental data and realize batch collection. The specific method of data collection is as follows: deploy a lightweight agent program on the cache node to listen to data operation events; secondly, filter invalid and low-value data according to preset rules; then, encapsulate the collected data into a unified format and attach metadata; finally, send the data to the cloud storage module through an encrypted channel.
4. The cache data security protection system based on cloud computing according to claim 1, characterized in that: In the cloud storage module, the cloud storage module adopts a distributed storage architecture to efficiently and securely store input information, data to be approved, IP data and related record information; the data is classified and pre-processed before storage: the input information is encrypted using the AES-256 algorithm and a timestamp and version number are attached; The data to be approved is processed in pieces, and the metadata is stored in association with the piece information; the IP data is desensitized, and only the necessary fields are retained; The recorded information includes fields such as timestamp, operation type and result, which are used for subsequent audit and analysis. The data storage is based on a distributed file system, with a multi-copy mechanism to ensure reliability, and tiered storage based on data type and access frequency - hot data is stored in high-performance SSD nodes, and cold data is stored in high-capacity HDD nodes. When data is stored in shards, it is evenly distributed to multiple nodes through the consistent hashing algorithm to avoid single-point performance bottlenecks.
5. The cache data security protection system based on cloud computing according to claim 4, characterized in that: In the storage process, the cloud storage module first receives the data packet through the encrypted channel and verifies the data integrity; Subsequently, the data is classified according to the data type, and sensitive information is encrypted. Next, large-capacity data is stored in shards, and metadata indexes are generated for quick retrieval. Finally, the input information, data to be approved, IP data, and record information are associated through unique identifiers to build a global index to support multi-dimensional queries. All stored data is encrypted using AES-256, and access rights are restricted based on RBAC and ABAC mechanisms. At the same time, data compression is used to reduce storage space usage, and a cache mechanism is used to accelerate high-frequency data access. Elastic expansion is supported to dynamically adjust storage resources. In addition, the cloud storage module records logs of all data storage operations and stores them in an independent audit database to facilitate subsequent tracing and security analysis.
6. The cache data security protection system based on cloud computing according to claim 1, characterized in that: In the verification execution module, three types of signals are identified and classified: security anomaly signals are identified by real-time monitoring of cache operation behavior and network traffic characteristics, combined with the isolation forest algorithm to identify behavior patterns that deviate from the normal baseline; Security and stability signals build a dynamic trust scoring model based on historical operation data, and quantify security confidence by analyzing user permission compliance, device fingerprint stability, and operation path consistency; Security deviation signals are analyzed by combining rule engines and Bayesian networks to detect data integrity deviations, permission violations, and protocol compliance deviations. Subsequently, the three types of signals are input into the risk assessment model, the comprehensive risk value is calculated through a weighted algorithm, and a signal is generated based on the result: when the comprehensive risk value is lower than the security threshold, an execution permission signal is generated, which contains an encrypted token and an access permission tag to authorize the cache operation; when a high-risk signal is detected or the comprehensive risk value exceeds the threshold, a cache prohibition signal is triggered, data transmission is blocked, and an alarm notification is initiated; the generated signal is transmitted to the cache execution node through a digital signature and a TLS1.3 encrypted channel to prevent signal tampering or theft.
7. The cache data security protection system based on cloud computing according to claim 1, characterized in that: In the security management module, the input information is cleaned in a standardized manner to remove redundant fields and invalid data, and the recorded information is deduplicated and outliers are corrected; then, sensitive fields are masked or hashed to ensure privacy compliance, and are labeled and classified according to data type and purpose; In the data conversion stage, a hybrid encryption algorithm is used to encrypt data, shard large-capacity data and generate shard indexes. At the same time, the conversion value is calculated based on preset rules to generate calculated processing data including risk scores, data heat values and security confidence levels. The converted data is transmitted to the protection and early warning module through the TLS1.3 encrypted channel, with ECDSA digital signatures and SHA-256 hash values attached to ensure integrity, and access rights are restricted by role-based access control and attribute-based access control policies. To improve performance, data compression technology is used to reduce transmission bandwidth occupancy, and high-frequency data access is accelerated through Redis cache. The full-link operation log is stored in the blockchain node to achieve tamper-proof audit traceability, and the execution results of the protection and early warning module are fed back to the security processing module to dynamically optimize data conversion rules and calculation models.
8. The cache data security protection system based on cloud computing according to claim 1, characterized in that: In the protection warning module, three types of data sources are integrated: calculation and processing data, data to be approved, and IP data. The data are associated through unique identifiers to construct a multi-dimensional analysis data set, and the data is normalized to eliminate dimensional differences. In the real-time analysis engine, the module uses the isolation forest algorithm to detect abnormal behaviors in user operation sequences, combines the rule engine to match known attack patterns and the IP reputation database to assess risk levels, and generates a security anomaly signal when the real-time risk score exceeds the preset threshold; A dynamic trust scoring model is built based on the user's historical operation data, and the operation path consistency score is calculated through a sliding window algorithm. A security and stability signal is generated when the score is higher than the benchmark value. The deviation between the data to be approved and the preset security policy is detected, including file type blacklist and hash value mismatch. The compliance of the data transmission protocol and the attribute-based access control model are verified to determine the violation of permissions and generate a security deviation signal.
Citation Information
Cited By
Block chain-driven data exchange full-process monitoring system and method
CN120825496A
Blockchain-driven end-to-end monitoring system and method for data exchange
CN120825496B
Data security management method and device based on dynamic encryption and real-time anomaly detection
CN121530694A
Data security management method and device based on dynamic encryption and real-time anomaly detection
CN121530694B