Information leakage protection method and system

Through the information leakage protection method of hierarchical encryption and identity verification of protected files, the problem of high risk of information leakage in the existing technology is solved, and data security and operational efficiency are improved.

CN120263494AInactive Publication Date: 2025-07-04BEIJING MUXUE COMPUTER TECHNOLOGY CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510457078.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-13
Publication Date
2025-07-04
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

The existing information leakage protection methods and systems have technical complexity, risks of false alarms and underreporting, and dependence on professionals, resulting in a greater risk of leakage during information exchange.

Method used

By obtaining the number, size, number of accesses and number of modifications of files to be protected, it is divided into hot data, temperature data and cold data, and is encrypted by RSA algorithm, combined with SNN model for secondary encryption, using user identity information for verification, and periodically monitoring key changes to realize the secure distribution and management of data.

Benefits of technology

It significantly enhances data security, prevents sensitive information from being illegally obtained or abused, protects personal privacy and corporate confidentiality, reduces manual intervention, and improves operational efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120263494A_ABST
    Figure CN120263494A_ABST
Patent Text Reader

Abstract

The invention provides an information leakage protection method and system, and belongs to the field of information protection. The problem of relatively high leakage risk in an information exchange process is solved; the method specifically comprises the following steps: S1, dividing a to-be-protected file into hot data, temperature data and cold data; s2, encrypting the hot data, the temperature data and the cold data to generate a primary key, and obtaining and storing a hot data ciphertext, a temperature data ciphertext and a cold data ciphertext; s3, obtaining verification information, and constructing a secondary encryption model; obtaining to-be-verified information; comparing the to-be-verified information with the verification information; if the comparison is successful, the hot data, the temperature data and the cold data are sent to the visitor; if the comparison fails, performing secondary encryption by using a secondary encryption model; and S4, periodically monitoring the number of the to-be-protected files, and changing the key once. The user information is acquired, analyzed and processed, and the information is encrypted for multiple times, so that the information security is guaranteed.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention discloses an information leakage protection method and system, which relates to the field of information protection. Background Art

[0002] The existing methods or systems for information leakage protection have the following deficiencies: Technical complexity: Information leakage protection involves the comprehensive application of multiple technologies, such as encryption technology, intrusion detection systems, data leakage protection systems, etc., which increases the complexity of technology implementation.

[0003] False positive and false negative risks: The protection system may produce false positives or false negatives, which may lead to unnecessary tension or neglect of real threats.

[0004] Dependence on professionals: Effective information leakage protection requires professional technical personnel for configuration and management. The lack of professional talents may affect the effectiveness of the system. Summary of the Invention

[0005] Aiming at the deficiencies of the existing technology, the purpose of the present invention is to provide an information leakage protection method and system, aiming to solve the problem of a relatively large leakage risk during the information exchange process.

[0006] To achieve the above purpose, the present invention is realized through the following technical solutions: An information leakage protection method includes: Step S1: Obtain the number of files to be protected, obtain the size, access times, and modification times corresponding to each protected file, and obtain allocation parameters; according to the allocation parameters, divide the files to be protected into hot data, warm data, and cold data; Step S2: Obtain the network interface number of the user's PC and initialize the cloud platform; use the RSA algorithm to encrypt the hot data, warm data, and cold data once to generate a primary key, and obtain the hot data ciphertext, warm data ciphertext, and cold data ciphertext; determine whether the local server can accommodate all the hot data ciphertext and warm data ciphertext; If it can accommodate, save the hot data ciphertext and warm data ciphertext in the local server, and restore and save the cold data ciphertext in the cloud platform; If it cannot accommodate, save some of the hot data ciphertext and warm data ciphertext in the local server; summarize the unsaved hot data ciphertext, warm data ciphertext, and cold data ciphertext, and save them in the cloud platform; Step S3: Obtain the user's identity information as verification information; use the SNN model to construct a secondary encryption model; obtain the visitor identity information for accessing the local server and the cloud platform to obtain the information to be verified; compare the information to be verified with the verification information; If the comparison is successful, use the key once to decrypt the hot data ciphertext and the warm data ciphertext to obtain the hot data and the warm data; aggregate the hot data, the warm data, and the cold data, and send them to the visitor; If the comparison fails, use the secondary encryption model to perform secondary encryption on the hot data ciphertext, the warm data ciphertext, and the cold data to obtain the secondary ciphertext, and feedback it to the visitor; Step S4: Periodically monitor the size of the number of files to be protected, and change the key once.

[0007] Furthermore, the specific steps of the said step S1 are as follows: Step S11: Load the os library; use the path.listdir() method and the path.isfile() method in the os library to obtain the number of files to be protected, denoted as fn; use the path.getsize() method in the os library to obtain the size of each file to be protected, denoted as b1, b2 ~ b fn ; Among them, b1 represents the size of the first file to be protected; b2 represents the size of the second file to be protected; and so on, b fn represents the size of the fnth file to be protected; Step S12: Load the io library; use the IOException module in the io library to construct a read-write access counter; use the read-write access counter to obtain the access times and modification times of the files to be scanned; Aggregate the access times and modification times of the first to the fnth files to be scanned and protected, denoted as r1, r2 ~ r fn and w1, w2 ~ w fn ; Step S14: Aggregate the data obtained in steps S11 to S13 as the allocation parameters; according to the allocation parameters, divide the files to be scanned into hot data, warm data, and cold data; Step S15: Aggregate the hot data, the warm data, and the cold data, and enter step S2.

[0008] Furthermore, the specific steps of the said step S14 are as follows: Step S141: Calculate the average values corresponding to r1 ~ r fn and w1 ~ w fn , denoted as ar and aw; Define relation 11: r i + w i ≥ (ar * aw) 1 / 2 ; where i is a positive integer representing 1 to fn; r i and w i , respectively represent the access times and modification times corresponding to the ith file to be scanned; Step S142: Substitute r1 to r fn and w1 to w fn into Equation 11; Screen out the files to be protected that do not satisfy Equation 11 as cold data; count the number of cold data, denoted as cmn; Mark the files to be protected that satisfy Equation 1 as non-cold data; Step S143: Define Equation 12: w j −r j ≥0; where j represents the subscript corresponding to the non-cold data, and the value range of j is: 1 to (fn − cmn); w j and r j respectively represent the access times and modification times corresponding to the i-th non-cold data; Substitute the access times and modification times corresponding to the non-cold data into Equation 12; Summarize the data that satisfy Equation 12 as Data 1; count the number of Data 1, denoted as nn; Summarize the data that do not satisfy Equation 12 as Data 2; count the number of Data 1, denoted as ny; Step S144: Calculate the average value of b1 to bfn, denoted as ab; Define Equation 13: ; Define Equation 14: ; where i represents the subscript of the access times or modification times corresponding to Data 1, and the value range of j is: 1 to nn; b i , w i and r i respectively represent the file size, access times or modification times corresponding to the i-th Data 1; j represents the subscript of the access times or modification times corresponding to Data 2, and the value range of j is: 1 to ny; b j , w j and r j respectively represent the file size, access times or modification times corresponding to the j-th Data 2; Step S145: Substitute the file size, access times and modification times corresponding to Hot Data 1 into Equation 13 respectively; substitute the file size, access times and modification times corresponding to Hot Data 2 into Equation 14 respectively; Summarize the Hot Data 1 that satisfy Equation 13 as hot data; summarize the Hot Data 2 that satisfy Equation 14 as warm data; Count the number of hot data and warm data, denoted as wmn and smn respectively; the relationship between wmn and smn and cmn and fn satisfies: wmn + smn ≤ fn − cmn; Step S146: In the hot data 1, summarize the hot data 1 that does not satisfy relation 13 as warm data, and count the number, denoted as Δsmn; In the hot data 2, summarize the hot data 2 that does not satisfy relation 14 as cold data, and count the number, denoted as Δcmn; On the basis of the original smn, modify smn to smn'; smn' = smn + Δsmn; On the basis of the original cmn, modify cmn to cmn'; cmn' = cmn + Δcmn; The relationship among wmn, smn', cmn', and fn satisfies: wmn + smn' + cmn' = fn.

[0009] Furthermore, the specific steps of step S2 are as follows: Step S21: Obtain the network interface number of the user's PC and initialize the (data storage) cloud platform; Step S211: Obtain the network interface number of the user's PC (such as static IP address, subnet mask, default gateway), and configure the network interface number into the server; Obtain the operating system version number of the user's PC; according to the operating system version number, load the corresponding private cloud operating system image; and install the private cloud operating system image on the local server; Step S212: Denote wmn, smn', and cmn' as wn, sn, and cn respectively; Use the docker container run <image name> command to create wn A containers, sn B containers, and sn C containers in sequence in the (data storage) cloud platform; Set the initial size of the A containers, B containers, and C containers to 1 bit; Step S22: Use the RSA algorithm to encrypt the hot data, warm data, and cold data once to obtain the hot data ciphertext, warm data ciphertext, and cold data ciphertext; Step S23: Obtain the remaining storage space size of the user's local server, denoted as cbb; Use the path.getsize() method in the os library to obtain the sizes of each hot data ciphertext, warm data ciphertext, and cold data ciphertext, denoted as wb1 to wb wn 、sb1 to sb sn and cb1 to cb cn ; Step S24: Judge whether less than or equal to cbb holds; If it holds, it indicates that the local server has sufficient memory. Save the hot data ciphertext and warm data ciphertext on the local server, restore and save the cold data ciphertext on the cloud platform, and proceed to step S25; If it does not hold, it indicates that the local server does not have sufficient memory. Save some of the hot data ciphertext and warm data ciphertext on the local server, and proceed to step S26.

[0010] Furthermore, the subsequent steps of step S24 are as follows: Step S25: The local server has sufficient memory, save the data ciphertext, warm data ciphertext, and cold data ciphertext; Step S251: In the cloud platform, use the docker rm <container_id_or_name> command to delete all A containers and B containers; Step S252: Save the wn hot data ciphertexts and sn warm data ciphertexts on the local server; use the private key decryption exponent d1 to decrypt the cold data ciphertext to obtain cn cold data; Step S253: Set the sizes of the sn C containers to cb1 to cb cn , to obtain sn C containers'; in the order of cb1 to cb cn , sequentially store the cn cold data (original text) into the sn C containers'; Step S26: The local server does not have sufficient memory, save the data ciphertext, warm data ciphertext, and cold data ciphertext.

[0011] Furthermore, the specific steps of step S22 are as follows: Step S221: Generate a one-time key for the RSA algorithm based on the network interface number; Step S222: Use a hash function to obtain the hash value of the network interface number, denoted as hn; Use the Mersenne Twister algorithm to randomly generate two positive prime numbers, denoted as p1 and q1; p1, q1, and hn satisfy: p1 + q1 = hn; Step S223: Define calculation formula 21: p i *q i = on i ; where i is a natural number, and the initial value of i is 1; p i and q i , respectively represent the two positive prime numbers generated in the i-th execution of step S222; on i , represents the common modulus corresponding to o i and q i ; Substitute o1 and q1 into calculation formula 21 in sequence to calculate the common modulus on1; Step S224: Define calculation formula 22: ; where i is a natural number and its initial value is 1; , representing the Euler value obtained from the i-th execution of step S225; p and k respectively represent the calculation parameters of calculation formula 22; Compare the magnitudes of o1 and q1; in calculation formula 22, if o1 ≥ q1, substitute o1 into p, substitute q1 into k, and calculate the Euler value of o1 relative to q1 ; If o1 < q1, substitute q1 into p, substitute o1 into k, and calculate the Euler value of q1 relative to o1 .

[0012] Furthermore, the subsequent steps of step S224 are as follows: Step S225: Define an integer of BigInteger type as the public key encryption key exponent, denoted as e i ; where i is a natural number and its initial value is 1; e i represents the integer generated from the i-th execution of step S225; Define the constraint conditions 23 and 24 for e i : Constraint condition 23: e i and satisfy the relationship: ; Constraint condition 24: e i is mutually exclusive with , and the greatest common divisor of e i and must be 1; where i is a natural number and its initial value is 1; , representing the Euler value obtained from the i-th execution of step S225; Substitute into constraint conditions 23 and 24, and use the Mersenne Twister algorithm to generate a smallest integer e1 that simultaneously satisfies constraint conditions 23 and 24; use e1 as the public key encryption key exponent for the first execution of step S225; Step S226: Define an integer of BigInteger type as the private key decryption exponent, denoted as d i ; where i is a natural number and its initial value is 1; Define congruence equation 25: ; d i represents the private key decryption exponent obtained from the i-th execution of step S226; , representing the Euler value obtained by the i-th execution of step S225; ≡ represents the symbol of identical equality; Substitute into the congruence equation 25 to calculate the private key decryption exponent d1 corresponding to e1; Step S227: Define the encapsulation structure 26 of the one-time key: (d i , e i ); where i is a natural number and its initial value is 1; d i and e i respectively represent the private key decryption exponent (d i ) and the public key encryption exponent (e i ) obtained by the i-th execution of steps S2211 to S2215; Substitute d1 and e1 into the encapsulation structure 26 to obtain the one-time key (d1, e1); where d1 is used for decryption and e1 is used for encryption; Use the public key encryption key exponent e1 to perform one-time encryption on the hot data, warm data, and cold data, and obtain wn hot data ciphertexts, sn warm data ciphertexts, and cn cold data ciphertexts; Step S228: Create a singly linked list data structure, denoted as the standard linked list; store the two positive prime numbers p i and q i generated by the i-th execution of step S222 into the standard linked list; destroy p i and q i .

[0013] Furthermore, the specific steps of step S26 are as follows: Step S261: Define the judgment formula 27: ; where ZW(1→i) represents the cumulative value of the sizes of the 1st to the i-th hot data ciphertexts, and wb i represents the size of the i-th hot data ciphertext; ZS(1→m) represents the cumulative value of the sizes of the 1st to the m-th warm data ciphertexts, and sb m represents the size of the m-th warm data ciphertext; Step S262: Substitute wb1 to wb wn corresponding to the wn hot data ciphertexts into formula A, and judge whether formula A holds when i = wn; If it holds, then judge formula B and enter step S263; If it does not hold, then obtain the maximum value of i for which formula A holds, denoted as mi; save the 1st to the mi-th hot data ciphertexts in the local server; In the cloud platform, use the "docker rm <container_id_or_name>" command to delete mi A containers; use the private key decryption exponent d1 to decrypt the (mi + 1)-th to wn-th hot data ciphertexts, all warm data ciphertexts, and all cold data ciphertexts, and store them in the cloud platform; Step S263: Substitute the sb1 to sb corresponding to sn warm data ciphertexts sn into Equation B, and determine whether Equation B holds when m = sn; If it holds, repeat Steps S251 to S253; save the hot data ciphertexts and warm data ciphertexts in the local server, and restore and save the cold data ciphertexts in the cloud platform; If it does not hold, obtain the maximum value of m for which Equation B holds, denoted as mm; save all the hot data and the 1st to mm-th warm data ciphertexts in the local server; In the cloud platform, use the "docker rm <container_id_or_name>" command to delete all A containers and mm B containers; use the private key decryption exponent d1 to decrypt the (mm + 1)-th to sn-th warm data ciphertexts and all cold data ciphertexts, and store them in the cloud platform.

[0014] An information leakage protection system includes: Data acquisition module: used to acquire the number of files to be protected, acquire the size, access times, and modification times corresponding to each protected file, and obtain allocation parameters; according to the allocation parameters, divide the files to be protected into hot data, warm data, and cold data; Primary encryption module: used to acquire the network interface number of the user's PC and initialize the cloud platform; use the RSA algorithm to perform primary encryption on hot data, warm data, and cold data, generate primary keys, and obtain hot data ciphertexts, warm data ciphertexts, and cold data ciphertexts; determine whether the local server can accommodate all the hot data ciphertexts and warm data ciphertexts; If it can accommodate, save the hot data ciphertexts and warm data ciphertexts in the local server, and restore and save the cold data ciphertexts in the cloud platform; If it cannot accommodate, save some of the hot data ciphertexts and warm data ciphertexts in the local server; aggregate the un-saved hot data ciphertexts, warm data ciphertexts, and cold data ciphertexts, and save them in the cloud platform; Secondary encryption module: used to acquire the user's identity information as verification information; use the SNN model to construct a secondary encryption model; acquire the identity information of the visitors accessing the local server and the cloud platform to obtain the information to be verified; compare the information to be verified with the verification information; If the comparison is successful, use the key once to decrypt the hot data ciphertext and the warm data ciphertext to obtain the hot data and the warm data; summarize the hot data, the warm data, and the cold data and send them to the visitor. If the comparison fails, do not process. Periodic inspection module: used to periodically monitor the size of the number of files to be protected and change the key once.

[0015] Compared with the prior art, the beneficial effects of the present invention are as follows: Enhance data security: Through information mining and information encryption methods, the present invention can significantly enhance data security, effectively prevent sensitive information from being illegally obtained or misused, and protect personal privacy and corporate secrets.

[0016] Maintain customer trust: Protecting the security of customer data is to maintain customer trust; through access control and monitoring mechanisms, internal leakage incidents can be effectively prevented. Improve operational efficiency: Through the automated information leakage protection system of the present invention, the need for manual monitoring and intervention can be reduced, thereby improving the operational efficiency of enterprises. Description of the drawings

[0017] By reading the detailed description of the non-limiting embodiments with reference to the following drawings, other features, purposes, and advantages of the present invention will become more obvious: Figure 1 It is a schematic diagram of the method of the present invention; Figure 2 It is a schematic diagram of the system of the present invention; Figure 3 It is a schematic diagram of the CNN model of the present invention. Detailed implementation manners

[0018] To make the above objects, features, and advantages of the present invention more obvious and understandable, the present invention will be further described in detail below with reference to the drawings and specific implementation manners.

[0019] Embodiment 1 Please refer to Figure 1 and Figure 3 , an information leakage protection method includes: It should be noted that since the method of "directly scanning the user's PC to obtain data" will violate user privacy; therefore, the present invention adopts the method of "user authorized scanning" to obtain data; The implementation steps of the "user authorized scanning" method are as follows: Step Ⅰ: The user creates a folder named "files to be scanned" on the PC and configures the absolute path of the "files to be scanned" (folder) in the "an information leakage protection system"; Step II: The user stores the data or files protected by the present invention into the "file to be scanned" (folder) as the files to be protected. Step III: The present invention automatically locates the "file to be scanned" (folder) through the absolute path, and then reads the data or files in the "file to be scanned" (folder) to obtain the files to be protected. Step S1: Obtain the number of files to be protected, obtain the size, access times, and modification times corresponding to each protected file to obtain the allocation parameters; divide the files to be protected into hot data, warm data, and cold data according to the allocation parameters. The specific steps of Step S1 are as follows: Step S11: Load the os library; use the path.listdir() method and path.isfile() method in the os library to (scan the "file to be scanned" (folder)) to obtain the number of files to be protected, denoted as fn; use the path.getsize() method in the os library to obtain the size of each file to be protected, denoted as b1, b2 ~ b fn ; where, b1 represents the size of the first file to be protected; b2 represents the size of the second file to be protected; and so on, b fn represents the size of the fnth file to be protected; Step S12: Load the io library; use the IOException module in the io library to construct a read-write access counter; configure the absolute path of the "file to be scanned" (folder) to the read-write access counter; use the read-write access counter to obtain the access times and modification times of the file to be scanned. Summarize the access times and modification times of the first to fnth files to be scanned and protected, denoted as r1, r2 ~ r fn and w1, w2 ~ w fn ; where, r1 and w1 respectively represent the access times and modification times of the first file to be protected; r2 and w2 respectively represent the access times and modification times of the second file to be protected; and so on, r fn and w fn respectively represent the access times and modification times of the fnth file to be protected; Step S14: Summarize the data obtained in Steps S11 to S13 as the allocation parameters; divide the files to be scanned into hot data, warm data, and cold data according to the allocation parameters. Step S141: Calculate the average values corresponding to r1 ~ r fn and w1 ~ w fn denoted as ar and aw; Define relationship 11: r i +w i≥ (ar * aw) 1 / 2 ; where i is a positive integer, representing 1 to fn; r i and w i , respectively represent the access times and modification times corresponding to the i-th file to be scanned; Step S142: Substitute r1 to r fn and w1 to w fn into relation 11; Screen out the files to be protected that do not satisfy relation 11 as cold data; count the number of cold data, denoted as cmn; Mark the files to be protected that satisfy relation 1 as non-cold data; Step S143: Define relation 12: w j - r j ≥ 0; where j represents the subscript corresponding to the non-cold data, and the value range of j is: 1 to (fn - cmn); w j and r j , respectively represent the access times and modification times corresponding to the i-th non-cold data; Substitute the access times and modification times corresponding to the non-cold data into relation 12; Summarize the (non-cold) data that satisfy relation 12 as data 1; count the number of data 1, denoted as nn; Summarize the (non-cold) data that do not satisfy relation 12 as data 2; count the number of data 1, denoted as ny; Step S144: Calculate the average value of b1 to bfn, denoted as ab; Define relation 13: ; Define relation 14: ; where i represents the subscript of the access times or modification times corresponding to data 1, and the value range of j is: 1 to nn; b i , w i and r i , respectively represent the file size, access times or modification times corresponding to the i-th data 1; j represents the subscript of the access times or modification times corresponding to data 2, and the value range of j is: 1 to ny; b j , w j and r j , respectively represent the file size, access times or modification times corresponding to the j-th data 2; Step S145: Substitute the file size, access times and modification times corresponding to the hot data 1 into relation 13 respectively; substitute the file size, access times and modification times corresponding to the hot data 2 into relation 14 respectively; Summarize the hot data 1 that satisfies relation 13 as hot data; summarize the hot data 2 that satisfies relation 14 as warm data; Count the number of hot data and warm data, denoted as wmn and smn respectively; the relationship between wmn and smn and cmn and fn satisfies: wmn + smn ≤ fn - cmn; Step S146: In the hot data 1, summarize the hot data 1 that does not satisfy relation 13 as warm data, and count the number, denoted as Δsmn; In the hot data 2, summarize the hot data 2 that does not satisfy relation 14 as cold data, and count the number, denoted as Δcmn; On the basis of the original smn, modify smn to smn'; smn' = smn + Δsmn; On the basis of the original cmn, modify cmn to cmn'; cmn' = cmn + Δcmn; The relationship between wmn, smn', cmn' and fn satisfies: wmn + smn' + cmn' = fn.

[0020] Step S15: Summarize the hot data, warm data and cold data, and enter step S2.

[0021] Step S2: Obtain the network interface number of the user's PC, and initialize the (data storage) cloud platform; use the RSA algorithm to encrypt the hot data, warm data and cold data once to generate a primary key, and obtain the encrypted hot data, encrypted warm data and encrypted cold data; determine whether the local server can accommodate all the encrypted hot data and encrypted warm data; If it can accommodate, save the encrypted hot data and encrypted warm data in the local server, and restore and save the encrypted cold data in the (data storage) cloud platform; If it cannot accommodate, save some of the encrypted hot data and encrypted warm data in the local server; summarize the encrypted hot data, encrypted warm data and encrypted cold data that are not saved (in the local server) and save them in the (data storage) cloud platform; The specific steps of step S2 are as follows: Step S21: Obtain the network interface number of the user's PC, and initialize the (data storage) cloud platform; Step S211: Obtain the network interface number of the user's PC (such as static IP address, subnet mask, default gateway), and configure the network interface number into the server; Obtain the operating system version number of the user's PC; according to the operating system version number, load the corresponding private cloud operating system image (such as CentOS, Ubuntu); and install the private cloud operating system image on the local server; Step S212: Denote wmn, smn’, and cmn’ as wn, sn, and cn respectively; Use the docker container run <image name> command to successively create wn A containers, sn B containers, and sn C containers in the (data storage) cloud platform; Set the initial size of the A containers, B containers, and C containers to 1 bit; Step S22: Use the RSA algorithm to encrypt the hot data, warm data, and cold data once to obtain the hot data ciphertext, warm data ciphertext, and cold data ciphertext; Step S221: Generate the first key (private key) of the RSA algorithm according to the network interface number; Step S222: Use the hash function to obtain the hash value of the network interface number, denoted as hn; Use the Mersenne Twister algorithm to randomly generate two positive prime numbers, denoted as p1 and q1; p1, q1, and hn satisfy: p1 + q1 = hn; Step S223: Define calculation formula 21: p i *q i = on i ; where i is a natural number and its initial value is 1; p i and q i respectively represent the two positive prime numbers generated in the i-th execution of Step S222; on i represents the common modulus corresponding to o i and q i ; Substitute o1 and q1 into calculation formula 21 in sequence to calculate the common modulus on1; Step S224: Define calculation formula 22: ; where i is a natural number and its initial value is 1; , represents the Euler (function) value obtained in the i-th execution of Step S225; p and k respectively represent the calculation parameters of calculation formula 22; Compare the magnitudes of o1 and q1; in calculation formula 22, if o1 ≥ q1, then substitute o1 into p and q1 into k to calculate the Euler (function) value of o1 relative to q1 ; If o1 < q1, then substitute q1 into p and o1 into k to calculate the Euler (function) value of q1 relative to o1 ; Step S225: Define an integer of BigInteger type as the public key encryption key exponent, denoted as e i ; where i is a natural number and its initial value is 1; ei represents the integer generated by the i-th execution of step S225; Define e i Constraint conditions 23 and 24 for Constraint condition 23: e i and The relationship satisfies: ; Constraint condition 24: e i and are mutually exclusive, and the greatest common divisor of e i and must be 1; where i is a natural number and the initial value of i is 1; , represents the Euler's totient function value obtained from the i-th execution of step S225; Substitute into constraint conditions 23 and 24, and use the Mersenne Twister algorithm to generate the smallest integer e1 that simultaneously satisfies constraint conditions 23 and 24; Take e1 as the public key encryption key exponent for the first execution of step S225; Step S226: Define an integer of type BigInteger as the private key decryption exponent, denoted as d i ; where i is a natural number and the initial value of i is 1; Define congruence equation 25: ; d i represents the private key decryption exponent obtained from the i-th execution of step S226; , represents the Euler's totient function value obtained from the i-th execution of step S225; ≡ represents the symbol of identical equality; Substitute into congruence equation 25 to calculate the private key decryption exponent d1 corresponding to e1; Step S227: Define the encapsulation structure 26 of the session key: (d i , e i ); where i is a natural number and the initial value of i is 1; d i and e i , respectively represent the private key decryption exponent (d i ) and the public key encryption exponent (e i ) obtained from the i-th execution of steps S2211 to S2215; Substitute d1 and e1 into the encapsulation structure 26 to obtain the session key (d1, e1); where d1 is used for decryption and e1 is used for encryption; Use the public key encryption key exponent e1 to perform one-time encryption on the hot data, warm data, and cold data, and obtain wn hot data ciphertexts, sn warm data ciphertexts, and cn cold data ciphertexts; Step S228: Create a singly linked list data structure, denoted as the standard linked list; store the two positive prime numbers p i and q i , generated in the i-th execution of Step S222, into the standard linked list; destroy p i and q i ; Step S23: Obtain the remaining storage space size of the user's local server, denoted as cbb; Use the path.getsize() method in the os library to obtain the sizes of each hot data ciphertext, warm data ciphertext, and cold data ciphertext, denoted as wb1 to wb wn , sb1 to sb sn and cb1 to cb cn ; Step S24: Judge whether less than or equal to cbb holds; If it holds, it means the local server has sufficient memory. Save the hot data ciphertext and warm data ciphertext on the local server, restore and save the cold data ciphertext on the (data storage) cloud platform, and enter Step S25; If it does not hold, it means the local server does not have sufficient memory. Save some of the hot data ciphertext and warm data ciphertext on the local server, and enter Step S26; Step S25: The local server has sufficient memory. Save the data ciphertext, warm data ciphertext, and cold data ciphertext; Step S251: In the (data storage) cloud platform, use the docker rm <container_id_or_name> command to delete all A containers and B containers; Step S252: Save wn hot data ciphertexts and sn warm data ciphertexts on the local server; use the private key decryption exponent d1 to decrypt the cold data ciphertext to obtain cn cold data (original texts); Step S253: Set the sizes of sn C containers to cb1 to cb cn in sequence to obtain sn C containers'; in the order of cb1 to cb cn , store the cn cold data (original texts) into the sn C containers' in sequence; Step S26: The local server does not have sufficient memory. Save the data ciphertext, warm data ciphertext, and cold data ciphertext; Step S261: Define judgment formula 27: ; where ZW(1→i) represents the cumulative value of the sizes of the 1st to the i-th hot data ciphertexts, wb iRepresents the size of the i-th hot data ciphertext; ZS(1→m) represents the cumulative value of the sizes of the 1st to the m-th warm data ciphertexts, sb m Represents the size of the m-th warm data ciphertext; Step S262: Substitute wb1 to wb corresponding to wn hot data ciphertexts wn Into formula A, and determine whether formula A holds when i = wn; If it holds, then judge formula B and enter step S263; If it does not hold, then obtain the maximum value of i for which formula A holds, denoted as mi; Save the 1st to the mi-th hot data ciphertexts in the local server; In the (data storage) cloud platform, use the docker rm <container_id_or_name> command to delete mi A containers; Use the private key decryption exponent d1 to decrypt the (mi + 1)-th to the wn-th hot data ciphertexts, all warm data ciphertexts, and all cold data ciphertexts, and store them in the (data storage) cloud platform; (Steps S252 to S253) Step S263: Substitute sb1 to sb corresponding to sn warm data ciphertexts sn Into formula B, and determine whether formula B holds when m = sn; If it holds, then repeat steps S251 to S253; Save the hot data ciphertexts and warm data ciphertexts in the local server, and restore and save the cold data ciphertexts in the (data storage) cloud platform; If it does not hold, then obtain the maximum value of m for which formula B holds, denoted as mm; Save all the hot data and the 1st to the mm-th warm data ciphertexts in the local server; In the (data storage) cloud platform, use the docker rm <container_id_or_name> command to delete all A containers and mm B containers; Use the private key decryption exponent d1 to decrypt the (mm + 1)-th to the sn-th warm data ciphertexts and all cold data ciphertexts, and store them in the (data storage) cloud platform. (Steps S252 to S253) Step S3: Obtain the user's identity information as the verification information; Use the SNN model to construct a secondary encryption model; Obtain the visitor identity information for accessing the local server and the (data storage) cloud platform to get the information to be verified; Compare the information to be verified with the verification information; If the comparison is successful, then use the primary key to decrypt the hot data ciphertexts and warm data ciphertexts to obtain the hot data and warm data; Aggregate the hot data, warm data, and cold data and send them to the visitor; If the comparison fails, then use the secondary encryption model to perform secondary encryption on the hot data ciphertexts, warm data ciphertexts, and cold data to obtain the secondary ciphertexts and feedback them to the visitor.

[0022] Step S4: Periodically monitor the size of the number of files to be protected and change the key once.

[0023] Embodiment 2 Please refer to Figure 2 , an information leakage protection system includes: a data acquisition module, a primary encryption module, a secondary encryption module, a periodic inspection module, a database, and a server; wherein, the data acquisition module, the primary encryption module, the secondary encryption module, and the periodic inspection module are respectively connected to the database and the server.

[0024] Data acquisition module: used to obtain the number of files to be protected, obtain the size, access times, and modification times corresponding to each protected file, and obtain allocation parameters; according to the allocation parameters, divide the files to be protected into hot data, warm data, and cold data; Primary encryption module: used to obtain the network interface number of the user's PC and initialize the (data storage) cloud platform; use the RSA algorithm to perform primary encryption on hot data, warm data, and cold data to generate a primary key, and obtain hot data ciphertext, warm data ciphertext, and cold data ciphertext; determine whether the local server can accommodate all the hot data ciphertext and warm data ciphertext; If it can accommodate, save the hot data ciphertext and warm data ciphertext in the local server, and restore and save the cold data ciphertext in the (data storage) cloud platform; If it cannot accommodate, save some of the hot data ciphertext and warm data ciphertext in the local server; summarize the hot data ciphertext, warm data ciphertext, and cold data ciphertext that are not saved (in the local server) and save them in the (data storage) cloud platform; Secondary encryption module: used to obtain the user's identity information as verification information; use the SNN model to construct a secondary encryption model; obtain the visitor identity information for accessing the local server and the (data storage) cloud platform to obtain the information to be verified; compare the information to be verified with the verification information; If the comparison is successful, use the primary key to decrypt the hot data ciphertext and warm data ciphertext to obtain hot data and warm data; summarize the hot data, warm data, and cold data and send them to the visitor; If the comparison fails, do not process; Periodic inspection module: used to periodically monitor the size of the number of files to be protected and change the key once.

[0025] The above formulas are all dimensionless and only take their numerical values for calculation. The formulas are obtained by collecting a large amount of data for software simulation to get a formula closest to the actual situation. The preset parameters in the formulas are set by those skilled in the art according to the actual situation. For example, there are weight coefficients and proportionality coefficients, and the values set for them are specific numerical values obtained by quantifying each parameter, which is convenient for subsequent comparison. Regarding the magnitudes of the weight coefficients and proportionality coefficients, as long as they do not affect the proportional relationship between the parameters and the quantified values, it is acceptable.

[0026] Finally, it should be noted that the above-described embodiments are only specific implementation manners of the present invention, which are used to illustrate the technical solutions of the present invention, rather than limiting it. The protection scope of the present invention is not limited thereto. Although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that: any person skilled in the art within the technical scope disclosed by the present invention can still modify the technical solutions recorded in the foregoing embodiments, or can easily think of changes, or perform equivalent replacements on some of the technical features; and these modifications, changes or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of the present invention, and should all be covered within the protection scope of the present invention. Therefore, the protection scope of the present invention shall be subject to the protection scope of the claims.

Claims

1. An information leakage protection method, characterized in that, The protection method includes: Step S1: Obtain the number of files to be protected, obtain the size, access times, and modification times corresponding to each protected file to get allocation parameters; divide the files to be protected into hot data, warm data, and cold data according to the allocation parameters; Step S2: Obtain the network interface number of the user's PC and initialize the cloud platform; use the RSA algorithm to encrypt the hot data, warm data, and cold data once to generate a primary key, and obtain the hot data ciphertext, warm data ciphertext, and cold data ciphertext; determine whether the local server can accommodate all the hot data ciphertext and warm data ciphertext; If it can accommodate, save the hot data ciphertext and warm data ciphertext in the local server, and restore and save the cold data ciphertext in the cloud platform; If it cannot accommodate, save some of the hot data ciphertext and warm data ciphertext in the local server; summarize the unsaved hot data ciphertext, warm data ciphertext, and cold data ciphertext, and save them in the cloud platform; Step S3: Obtain the user's identity information as verification information; use the SNN model to construct a secondary encryption model; obtain the identity information of the visitors accessing the local server and the cloud platform to get the information to be verified; compare the information to be verified with the verification information; If the comparison is successful, use the primary key to decrypt the hot data ciphertext and warm data ciphertext to obtain the hot data and warm data; summarize the hot data, warm data, and cold data and send them to the visitors; If the comparison fails, use the secondary encryption model to encrypt the hot data ciphertext, warm data ciphertext, and cold data a second time to obtain the secondary ciphertext and feedback it to the visitors; Step S4: Periodically monitor the size of the number of files to be protected and change the primary key.

2. The information leakage protection method according to claim 1, characterized in that, The specific steps of step S1 are as follows: Step S11: Load the os library; use the path.listdir() method and path.isfile() method in the os library to obtain the number of files to be protected, denoted as fn; use the path.getsize() method in the os library to obtain the size of each file to be protected, denoted as b1, b2 ~ b fn ; Among them, b1 represents the size of the first file to be protected; b2 represents the size of the second file to be protected; and so on, b fn represents the size of the fn-th file to be protected; Step S12: Load the io library; use the IOException module in the io library to construct a read-write access counter; use the read-write access counter to obtain the access times and modification times of the files to be scanned; Summarize the access times and modification times of the protected files of the 1st to the fnth files to be scanned, denoted as r1, r2 ~ r fn and w1, w2 ~ w fn ; Step S14: Summarize the data obtained in steps S11 to S13 as allocation parameters; divide the files to be scanned into hot data, warm data, and cold data according to the allocation parameters; Step S15: Summarize the hot data, warm data, and cold data and enter step S2.

3. An information leakage prevention method according to claim 2, characterized in that, The specific steps of step S14 are as follows: Step S141: Calculate the average values corresponding to r1 to r fn and w1 to w fn and denote them as ar and aw; Define relationship 11: r i + w i ≥ (ar * aw) 1 / 2 ; where i is a positive integer representing 1 to fn; r i and w i , respectively represent the access times and modification times corresponding to the i-th file to be scanned; Step S142: Substitute r1 to r fn and w1 to w fn into Equation 11; Screen out the files to be protected that do not satisfy relation 11 as cold data; count the number of cold data, denoted as cmn; Mark the files to be protected that satisfy relation 1 as non-cold data; Step S143: Define relationship 12: w j −r j ≥0; where j represents the subscript corresponding to non-cold data, and the value range of j is 1 to (fn − cmn); w j and r j , respectively represent the access times and modification times corresponding to the i-th non-cold data; Substitute the access times and modification times corresponding to the non-cold data into relation 12; Summarize the data that satisfy relation 12 as data 1; count the number of data 1, denoted as nn; Summarize the data that do not satisfy relation 12 as data 2; count the number of data 1, denoted as ny; Step S144: Calculate the average value corresponding to b1 to bfn, denoted as ab; Define relational expression 13: ; Define relational expression 14: ; Among them, i represents the subscript of the access or modification times corresponding to Data 1, and the value range of j is 1 to nn; b i , w i and r i , respectively represent the file size, access times or modification times corresponding to the i-th Data 1; j represents the subscript of the access or modification count corresponding to data 2, and the value range of j is 1 to ny; b j , w j and r j , respectively representing the file size, access count, or modification count corresponding to the j-th data 2; Step S145: Substitute the file size, access times, and modification times corresponding to hot data 1 into relation 13 respectively; substitute the file size, access times, and modification times corresponding to hot data 2 into relation 14 respectively; Summarize the thermal data 1 that satisfies relation 13 as thermal data; summarize the thermal data 2 that satisfies relation 14 as warm data; Count the number of thermal data and warm data, denoted as wmn and smn respectively; the relationship between wmn and smn and cmn and fn satisfies: wmn + smn ≤ fn - cmn; Step S146: In the thermal data 1, summarize the thermal data 1 that does not satisfy relation 13 as warm data, and count the number, denoted as Δsmn; In the thermal data 2, summarize the thermal data 2 that does not satisfy relation 14 as cold data, and count the number, denoted as Δcmn; On the basis of the original smn, modify smn to smn'; smn' = smn + Δsmn; On the basis of the original cmn, modify cmn to cmn'; cmn' = cmn + Δcmn; The relationship between wmn, smn', cmn' and fn satisfies: wmn + smn' + cmn' = fn.

4. The information leakage protection method according to claim 2, wherein The specific steps of step S2 are as follows: Step S21: Obtain the network interface number of the user's PC and initialize the cloud platform; Step S211: Obtain the network interface number of the user's PC and configure the network interface number into the server; Obtain the operating system version number of the user's PC; according to the operating system version number, load the corresponding private cloud operating system image; And install the private cloud operating system image on the local server; Step S212: Denote wmn, smn' and cmn' as wn, sn and cn respectively; Use the docker container run <image name> command to create wn A containers, sn B containers and sn C containers in the cloud platform in sequence; Set the initial size of the A containers, B containers and C containers to 1 bit; Step S22: Use the RSA algorithm to encrypt the thermal data, warm data and cold data once to obtain the encrypted thermal data ciphertext, encrypted warm data ciphertext and encrypted cold data ciphertext; Step S23: Obtain the remaining storage space size of the user's local server, denoted as cbb; Use the path.getsize() method in the os library to obtain the sizes of each hot data ciphertext, warm data ciphertext, and cold data ciphertext, denoted as wb1 to wb wn , sb1 to sb sn and cb1 to cb cn ; Step S24: Determine whether it is less than or equal to cbb; If it holds, it means that the memory of the local server is sufficient. Save the encrypted thermal data ciphertext and encrypted warm data ciphertext on the local server, restore and save the encrypted cold data ciphertext on the cloud platform, and enter step S25; If it does not hold, it means that the memory of the local server is not sufficient. Save some of the encrypted thermal data ciphertext and encrypted warm data ciphertext on the local server, and enter step S26.

5. The information leakage prevention method according to claim 4, wherein The subsequent steps of step S24 are as follows: Step S25: The memory of the local server is sufficient, save the encrypted data ciphertext, encrypted warm data ciphertext and encrypted cold data ciphertext; Step S251: In the cloud platform, use the docker rm <container_id_or_name> command to delete all A containers and B containers; Step S252: Save wn encrypted thermal data ciphertexts and sn encrypted warm data ciphertexts in the local server; Use the private key decryption exponent d1 to decrypt the encrypted cold data ciphertext to obtain cn cold data; Step S253: Set the sizes of the sn C containers to cb1 to cb in sequence, obtaining sn C containers; sequentially store the cn cold data into the sn C containers in the order of cb1 to cb; cn , obtaining sn C containers; in the order of cb1 to cb cn , sequentially store the cn cold data into the sn C containers; Step S26: The memory of the local server is not sufficient, save the encrypted data ciphertext, encrypted warm data ciphertext and encrypted cold data ciphertext.

6. A method for protecting against information leakage according to claim 4, characterized in that, The specific steps of step S22 are as follows: Step S221: Generate a primary key for the RSA algorithm according to the network interface number; Step S222: Use a hash function to obtain the hash value of the network interface number, denoted as hn; Use the Mersenne Twister algorithm to randomly generate two positive prime numbers, denoted as p1 and q1; p1, q1, and hn satisfy: p1 + q1 = hn; Step S223: Define calculation formula 21: p i *q i = on i ; where i is a natural number, and the initial value of i is 1; p i and q i , respectively representing two positive prime numbers generated in the i-th execution of step S222; on i represents o i and q i corresponding common modulus; Substitute o1 and q1 into the calculation formula 21 in sequence to calculate the common modulus on1; Step S224: Define calculation formula 22: where i is a natural number and its initial value is 1; represents the Euler value obtained by executing step S225 for the i-th time; p and k respectively represent the calculation parameters of calculation formula 22; Compare the magnitudes of o1 and q1; in Equation 22, if o1 ≥ q1, substitute o1 into p and q1 into k, and calculate the Euler value of o1 relative to q1 ; If o1 < q1, then substitute q1 into p, substitute o1 into k, and calculate the Euler value of q1 relative to o1 .

7. An information leakage prevention method according to claim 6, characterized in that, The subsequent steps of step S224 are as follows: Step S225: Define an integer of BigInteger type as the public key encryption key exponent, denoted as e i ; where i is a natural number and the initial value of i is 1; e i represents the integer generated by executing Step S225 for the i-th time; Define e i Constraint conditions 23 and 24: Constraint 23: e i and satisfy the relationship: ; Constraint 24: e i is mutually exclusive with ; the greatest common divisor of e i and must be 1; where i is a natural number and its initial value is 1; , representing the Euler value obtained by executing step S225 for the i-th time; Substitute into Constraint 23 and Constraint 24, and use the Mersenne Twister algorithm to generate a smallest integer e1 that simultaneously satisfies Constraint 23 and Constraint 24; use e1 as the public key encryption key exponent for the first execution of step S225. Step S226: Define an integer of BigInteger type as the private key decryption exponent, denoted as d i ; where i is a natural number and the initial value of i is 1; Define the congruence equation 25: ; d i represents the private key decryption exponent obtained by the i-th execution of step S226; , represents the Euler value obtained by the i-th execution of step S225; ≡ represents the symbol of identical equality; Substitute into the congruence equation 25 to calculate the private key decryption exponent d1 corresponding to e1; Step S227: Define the encapsulation structure 26 of the one-time key: (d i , e i ); where i is a natural number and the initial value of i is 1; d i and e i , respectively represent the private key decryption exponent (d i ) and the public key encryption exponent (e i ) obtained by executing steps S2211 to S2215 for the i-th time; Substitute d1 and e1 into the encapsulation structure 26 to obtain the primary key (d1, e1); where, d1 is used for decryption and e1 is used for encryption; Use the public key encryption key exponent e1 to perform primary encryption on the hot data, warm data, and cold data, and obtain wn hot data ciphertexts, sn warm data ciphertexts, and cn cold data ciphertexts; Step S228: Create a singly linked list data structure, denoted as the standard linked list; store the two positive prime numbers p i and q i generated in the i-th execution of step S222 into the standard linked list; destroy p i and q i .

8. An information leakage prevention method according to claim 5, characterized in that, The specific steps of step S26 are as follows: Step S261: Define the judgment formula 27: ; Among them, ZW(1→i) represents the cumulative value of the sizes of the first to the i-th hot data ciphertexts, and wb i represents the size of the i-th hot data ciphertext; ZS(1→m) represents the cumulative value of the sizes of the first to the m-th warm data ciphertexts, and sb m represents the size of the m-th warm data ciphertext; Step S262: Substitute the ciphertexts of wn hot data corresponding to wb1 to wb wn into formula A, and determine whether formula A holds when i = wn; If it holds, then judge formula B and enter step S263; If it does not hold, then obtain the maximum value of i that makes formula A hold, denoted as mi; save the 1st to the mi-th hot data ciphertexts in the local server; In the cloud platform, use the docker rm <container_id_or_name> command to delete mi A containers; use the private key decryption exponent d1 to decrypt the (mi + 1)-th to the wn-th hot data ciphertexts, all warm data ciphertexts, and all cold data ciphertexts, and store them in the cloud platform; Step S263: Substitute the sb1 to sb corresponding to the sn temperature data ciphertexts sn into Equation B, and determine whether Equation B holds when m = sn; If it holds, then repeat steps S251 to S253; save the hot data ciphertexts and warm data ciphertexts in the local server, and restore and save the cold data ciphertexts in the cloud platform; If it does not hold, then obtain the maximum value of m that makes formula B hold, denoted as mm; save all the hot data and the 1st to the mm-th warm data ciphertexts in the local server; In the cloud platform, use the docker rm <container_id_or_name> command to delete all A containers and mm B containers; use the private key decryption exponent d1 to decrypt the (mm + 1)-th to the sn-th warm data ciphertexts and all cold data ciphertexts, and store them in the cloud platform.

9. An information leakage protection system, applicable to any one of the information leakage protection methods of claims 1-8, characterized in that The protection system includes: Data acquisition module: used to acquire the number of files to be protected, acquire the size, access times, and modification times corresponding to each protected file to obtain allocation parameters; divide the files to be protected into hot data, warm data, and cold data according to the allocation parameters; Primary encryption module: used to acquire the network interface number of the user's PC side and initialize the cloud platform; perform primary encryption on the hot data, warm data, and cold data using the RSA algorithm, generate a primary key, and obtain hot data ciphertexts, warm data ciphertexts, and cold data ciphertexts; judge whether the local server can accommodate all the hot data ciphertexts and warm data ciphertexts; If it can accommodate, then save the hot data ciphertexts and warm data ciphertexts in the local server, and restore and save the cold data ciphertexts in the cloud platform; If it cannot be accommodated, part of the hot data ciphertext and warm data ciphertext are saved in the local server; the unsaved hot data ciphertext, warm data ciphertext, and cold data ciphertext are aggregated and saved in the cloud platform; Secondary encryption module: used to obtain the user's identity information as verification information; use the SNN model to construct a secondary encryption model; obtain the visitor identity information accessing the local server and the cloud platform to get the information to be verified; compare the information to be verified with the verification information; If the comparison is successful, use the primary key to decrypt the hot data ciphertext and warm data ciphertext to obtain the hot data and warm data; aggregate the hot data, warm data, and cold data and send them to the visitor; If the comparison fails, do not process; Periodic inspection module: used to periodically monitor the quantity and size of the files to be protected and change the primary key.