Dynamic application data online transparent encryption replacement method
By deploying the file system transparent encryption and decryption module in the operating system, online transparent encryption and substitution of dynamic application data is realized, and the complexity and time-consuming problem of plain text replacement to cipher text in large data scenarios is solved, ensuring the continuity and security of the business system.
Patent Information
- Application Number
- CN202510333284.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-20
- Publication Date
- 2025-07-08
AI Technical Summary
The prior art is complex and time-consuming, and it is difficult to implement in large data scenarios without affecting the operation continuity of the business system.
Deploy the file system transparent encryption and decryption module in the operating system of the business system, and encrypt the dynamic application data plaintext through the file system transparent encryption and decryption module to realize the online transparent encryption replacement of dynamic application data from plaintext to ciphertext, and complete the encryption and decryption operations in the kernel layer or user space to avoid the transformation of the business system.
It realizes that dynamic application data is replaced from plain text to cipher text without affecting the normal operation of business applications of the business system, enhances data security, maintains business continuity, and reduces the impact on system performance.
Smart Images

Figure CN120277688A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of encryption technology, and in particular to an online transparent encryption replacement method for dynamic application data. Background Art
[0002] With the rapid development of the information age, data has become the core focus of enterprise operations. During the operation of the business system, a large amount of dynamic application data will continue to be generated. These dynamic application data are stored in the storage devices connected to the business system and are frequently called in business read and write operations to support various business applications. While dynamic application data has become a key component of the business system, its security is particularly important. Once the dynamic application data is leaked or tampered with, it will bring serious risks to the business system and its operators.
[0003] In order to improve the security of the system and data, it is an effective means to apply cryptographic technology to encrypt and decrypt dynamic application data during its storage and writing and reading. However, before the application of cryptographic technology, dynamic application data is stored in the storage device in plain text; the corresponding business system also reads and writes it in plain text. To achieve the storage of dynamic application data in the form of ciphertext in the storage device, as well as encryption and decryption during its writing and reading, one method is to adaptively upgrade the application logic of the corresponding business system, introduce the corresponding API, and call the encryption machine or encryption and decryption components. This method often involves multiple modules, or even the adjustment of the entire application ecosystem. The scope of transformation is wide and the complexity is high. It usually requires customized development for different business systems, and has poor compatibility and scalability. In addition, each encryption and decryption operation of the business system needs to be called through the API, which invisibly increases the overhead of system calls and may greatly reduce the performance of the business system.
[0004] Another method is to introduce a file system transparent encryption and decryption module into the operating system of the computing execution environment. When the business system writes dynamic application data, the introduced file system transparent encryption and decryption module first intercepts the data to be written, then encrypts the intercepted data, and finally stores the encrypted data in the storage device. Similarly, when the business system reads dynamic application data, the introduced file system transparent encryption and decryption module first intercepts the encrypted data to be read, then decrypts the encrypted data, and finally provides the decrypted data to the business system for use. The advantage of this method is that it does not require any modification to the application logic of the business system, has stronger compatibility, and lower implementation costs. However, since dynamic application data is stored in plain text in the storage device before the application of cryptographic technology, it is a difficult problem to replace the existing dynamic application data stored in plain text with encrypted data without affecting the continuity of the business system operation.
[0005] The common approach to address the above problems is to suspend the modification of existing dynamic application data in the business system, and then perform encryption and replacement on the static dynamic application data. In this way, the downtime of the business system depends on the duration of the encryption and replacement, which in turn depends on the size of the existing dynamic application data. In many application scenarios, the existing dynamic application data in the business system is extremely large, resulting in an overly long encryption and replacement process. For example, the encryption and replacement of 2TB of dynamic application data takes several hours, and the actual amount of dynamic application data is even larger. A long downtime of the business system is unacceptable in many scenarios. Therefore, it has become an urgent need to develop an online encryption and replacement method that can replace dynamic application data from plaintext to ciphertext without affecting the continuity of the business system operation. Summary of the Invention
[0006] In response to the above problems and technical requirements, this application proposes an online transparent encryption and replacement method for dynamic application data. The technical solution of this application is as follows:
[0007] An online transparent encryption and replacement method for dynamic application data, the online transparent encryption and replacement method for dynamic application data includes:
[0008] Deploy a file system transparent encryption and decryption module in the operating system of the business system, and apply the file system transparent encryption and decryption module to the target data directory in the storage device connected to the operating system;
[0009] During the process that the business system accesses the dynamic application data plaintext under the original data directory via the file system of the operating system to run the business application, call the file system transparent encryption and decryption module to encrypt the dynamic application data plaintext under the original data directory, so as to realize the encryption and replacement of the dynamic application data plaintext under the original data directory to the dynamic application data ciphertext under the target data directory;
[0010] After the encryption and replacement are completed and it is determined that the dynamic application data ciphertext under the target data directory is consistent with the dynamic application data plaintext under the original data directory, the business system accesses the dynamic application data ciphertext under the target data directory via the file system transparent encryption and decryption module of the operating system.
[0011] A further technical solution thereof is that the business system accessing the dynamic application data ciphertext under the target data directory via the file system transparent encryption and decryption module of the operating system includes:
[0012] When the operating system receives a write access request from the business system, call the file system transparent encryption and decryption module to encrypt the dynamic application data plaintext carried in the write access request to obtain the dynamic application data ciphertext and write it into the target data directory of the storage device;
[0013] When the operating system receives a read access request from the business system, it reads the dynamic application data ciphertext from the target data directory of the storage device according to the read access request, and calls the file system transparent encryption and decryption module to decrypt the read dynamic application data ciphertext to obtain the dynamic application data plaintext and return it to the business system.
[0014] A further technical solution thereof is that when the business system supports the modification operation of the existing dynamic application data plaintext file in the original data directory, the target data directory and the original data directory are two different directories; when the business system only supports the read operation of the existing dynamic application data plaintext file in the original data directory, the target data directory and the original data directory are the same directory.
[0015] A further technical solution thereof is that when the business system supports the modification operation of the existing dynamic application data plaintext file in the original data directory, encrypting the dynamic application data plaintext in the original data directory by calling the file system transparent encryption and decryption module includes: calling a synchronization tool to synchronize the dynamic application data plaintext in the original data directory, and calling the file system transparent encryption and decryption module to encrypt the synchronized dynamic application data plaintext during the synchronization process.
[0016] A further technical solution thereof is that when the business system supports the modification operation of the existing dynamic application data plaintext file in the original data directory, the dynamic application data online transparent encryption replacement method further includes:
[0017] When it is detected that the encryption replacement ratio reaches the ratio threshold, pause the business system and then complete the encryption replacement of the newly added dynamic application data plaintext in the original data directory to the dynamic application data ciphertext in the target data directory; after completing the encryption replacement and determining that the dynamic application data ciphertext in the target data directory meets the consistency requirement with the dynamic application data plaintext in the original data directory, use the target data directory to replace the original data directory.
[0018] A further technical solution thereof is that detecting whether the encryption replacement ratio reaches the ratio threshold includes determining that the encryption replacement ratio reaches the ratio threshold when at least one of the following conditions is detected:
[0019] When it is determined by the synchronization tool that the synchronization incremental data of the dynamic application data plaintext in the original data directory is less than the data volume threshold;
[0020] Or, when the estimated synchronization encryption duration calculated according to the data volume of the dynamic application data plaintext in the original data directory and the synchronization encryption speed is less than the duration threshold;
[0021] Or, determining that the data volume difference between the dynamic application data plaintext in the original data directory and the dynamic application data ciphertext in the target data directory is within the difference threshold range.
[0022] A further technical solution is that detecting whether the dynamic application data ciphertext in the target data directory and the dynamic application data plaintext in the original data directory meet the consistency requirements includes:
[0023] When it is determined that both the data content and data attributes of the dynamic application data ciphertext in the target data directory and the dynamic application data plaintext in the original data directory are consistent, it is determined that the consistency requirements are met; otherwise, it is determined that the consistency requirements are not met and encryption replacement is performed again.
[0024] A further technical solution is that detecting the data content and data attributes of the dynamic application data ciphertext in the target data directory and the dynamic application data plaintext in the original data directory includes:
[0025] List all the file directories in the target data directory and all the file directories in the original data directory respectively, compare the file directories in the target data directory and the file directories in the original data directory line by line. When the file directories in the target data directory are the same as those in the original data directory, it is determined that the data content of the dynamic application data ciphertext in the target data directory and the dynamic application data plaintext in the original data directory is consistent;
[0026] View the hidden permissions of the dynamic application data ciphertext in the target data directory and the hidden permissions of the dynamic application data plaintext in the original data directory respectively, and compare the hidden permissions of the dynamic application data ciphertext and the hidden permissions of the dynamic application data plaintext line by line. When the hidden permissions of the dynamic application data ciphertext and the dynamic application data plaintext are the same, it is determined that the data attributes of the dynamic application data ciphertext in the target data directory and the dynamic application data plaintext in the original data directory are consistent.
[0027] A further technical solution is that the data operated by the business system is stored based on files, and the operating system of the business system is an operating system based on the Linux kernel, Windows kernel, XNU kernel, or microkernel.
[0028] A further technical solution is that the synchronization tool used is a multi-threaded synchronization tool, and the multi-threaded synchronization tool performs the encryption replacement of the dynamic application data plaintext in the original data directory to the dynamic application data ciphertext in the target data directory through multi-threaded parallel execution.
[0029] A further technical solution is that using the target data directory to replace the original data directory includes:
[0030] Perform a data backup on the dynamic application data plaintext in the original data directory and rename the original directory name of the original data directory, and then update the directory name of the target data directory to the original directory name of the original data directory.
[0031] A further technical solution is that the target data directory is a newly created empty directory, and before starting the encryption replacement, the file system transparent encryption and decryption module is configured to monitor the target data directory, so that the file system transparent encryption and decryption module automatically encrypts the clear text of the dynamic application data synchronized to the target data directory.
[0032] A further technical solution is that the file system transparent encryption and decryption module is deployed in the kernel of the operating system.
[0033] A further technical solution is that the file system transparent encryption and decryption module is deployed in the user space of the operating system.
[0034] The beneficial technical effects of this application are:
[0035] This application discloses a method for online transparent encryption and replacement of dynamic application data. After deploying the file system transparent encryption and decryption module in the operating system, during the process of the business system continuously accessing the clear text of the dynamic application data, without affecting the normal operation of the business application of the business system, the file system transparent encryption and decryption module is used to encrypt the clear text of the dynamic application data under the original data directory. And after completing the encryption replacement of the dynamic application data from clear text to cipher text, the business system can run on the cipher text of the dynamic application data via the file system transparent encryption and decryption module. Through real-time encryption and replacement, it effectively prevents the leakage risk of the dynamic application data of the business system during storage, and on the basis of realizing a truly seamless switch from clear text to cipher text to enhance security, it maintains the business continuity of the business system and is exempt from the transformation of the business system.
[0036] This method does not require the business system that only supports reading operations on the existing clear text files of the dynamic application data under the original data directory to suspend service. For the business system that supports modifying operations on the existing clear text files of the dynamic application data under the original data directory, only a short-term suspension of the business system is required to complete the encryption replacement of the existing dynamic application data. The requirement of short-term suspension of the business system can be met during the operation and maintenance window time of the business system, thus not affecting the service continuity. Moreover, by optimizing the encryption algorithm and replacement strategy, and using technical means such as hardware acceleration, it ensures that the impact of the encryption process on the system performance is minimized.
[0037] In an embodiment of the method, a file system transparent encryption and decryption module is added to the kernel layer of the operating system, and the transparent encryption replacement operation and subsequent encryption and decryption operations of dynamic application data are completed. This method does not involve modifying the application layer business system, and the application logic of the business system remains unchanged. Therefore, the scope of transformation is more concentrated and the impact is smaller. Moreover, the encryption and decryption operations can be directly completed in the kernel layer without API calls every time, thus reducing the frequent interaction between the application layer and the kernel layer and improving the system performance. In addition, the transformation of the kernel layer is relatively independent, which not only has better compatibility and scalability for different business systems, but also only needs to focus on the file system transparent encryption and decryption module for subsequent maintenance and upgrade, without affecting other business modules, thus reducing the maintenance cost.
[0038] In another embodiment of the method, a file system transparent encryption and decryption module is added to the user space of the operating system, and the transparent encryption replacement operation and subsequent encryption and decryption operations of dynamic application data are completed. This method also does not involve modifying the application layer business system, and the application logic of the business system remains unchanged. However, since the encryption and decryption are performed in the user space and involve frequent context switching, this method will have some negative impacts on the performance of the business system.
[0039] The operating system involved in this method can be the operating system on a single computing device or a collection of operating systems on multiple computing devices. BRIEF DESCRIPTION OF THE DRAWINGS
[0040] Figure 1 is a flowchart of the method for online transparent encryption and replacement of dynamic application data according to an embodiment of the present application.
[0041] Figure 2 is a schematic diagram of the reading and writing of dynamic application data by a business system in the traditional method.
[0042] Figure 3 is a schematic diagram of the reading and writing of dynamic application data by a business system in an embodiment of the method for online transparent encryption and replacement of dynamic application data of the present application.
[0043] Figure 4 is Figure 3 the improved framework diagram of the reading and writing of dynamic application data by a business system in the embodiment.
[0044] Figure 5 is a schematic diagram of the reading and writing of dynamic application data by a business system in another embodiment of the method for online transparent encryption and replacement of dynamic application data of the present application.
[0045] Figure 6 is Figure 5 the improved framework diagram of the reading and writing of dynamic application data by a business system in the embodiment. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0046] The following further describes the specific implementation manners of the present application with reference to the accompanying drawings.
[0047] The present application discloses a method for online transparent encryption replacement of dynamic application data. Please refer to Figure 1 the flowchart shown below. The method for online transparent encryption replacement of dynamic application data includes:
[0048] Step S1: Deploy a file system transparent encryption / decryption module in the operating system of the service system, and apply the file system transparent encryption / decryption module to the target data directory in the storage device connected to the operating system.
[0049] The data run by the service system targeted by the present application is based on file storage, and the operating system of the service system is an operating system based on the Linux kernel, Windows kernel, XNU kernel, or microkernel. For example, commonly, the service system is a database system or a Hadoop system. During the operation of the service application, such service systems access the plaintext of dynamic application data in the storage device of the storage layer through the file system in the operating system kernel. Figure 2 Taking the read / write process of the plaintext of dynamic application data by the database system as an example, a framework diagram is shown.
[0050] The present application is directed to an application scenario where the plaintext of dynamic application data of the service system has been stored in the original data directory of the storage device. On this basis, first, the Figure 2 software and hardware framework shown below is improved and optimized. The main improvement lies in deploying a file system transparent encryption / decryption module in the operating system. In one embodiment, the file system transparent encryption / decryption module is deployed in the kernel of the operating system, as shown in Figure 3 and Figure 4 shown below. Or in another embodiment, the file system transparent encryption / decryption module is deployed in the user space of the operating system, as shown in Figure 5 and Figure 6 shown below.
[0051] Depending on its own performance, the service system has two main types of access to the plaintext of dynamic application data in the storage device:
[0052] (1) The service system supports modifying the plaintext files of dynamic application data existing in the original data directory. For example, Figure 2 the database system shown below. This type of service system generates new plaintext of dynamic application data during the operation of the service application and writes it into the storage device of the storage layer through the file system of the operating system kernel. The service system can also read the plaintext of dynamic application data that has been stored in the storage device through the file system of the operating system kernel.
[0053] In this case, the target data directory in this step and the original data directory are two different directories. The target data directory is a newly created target data directory in the storage device. Figure 1 The flowchart of Figure 1 takes this case as an example. And in order not to affect the existing dynamic application data of the business system, the newly created target data directory is initially an empty directory.
[0054] (2) The business system only supports reading operations on the existing dynamic application data plaintext files under the original data directory. For example, the Hadoop system belongs to this category. During the operation of the business application, for the existing dynamic application data plaintext files, this type of business system will only read them through the file system of the operating system kernel, but will not modify them.
[0055] In this case, the target data directory and the original data directory in this step refer to the same directory.
[0056] Regardless of which of the above situations, after determining the target data directory, it is necessary to apply the newly added file system transparent encryption and decryption module to this target data directory. Applying to this target data directory here means configuring the file system transparent encryption and decryption module to monitor the target data directory so that all accesses to and from this target data directory will pass through this file system transparent encryption and decryption module.
[0057] Step S2, during the process that the business system accesses the dynamic application data plaintext under the original data directory through the file system of the operating system to run the business application, call the file system transparent encryption and decryption module to encrypt the dynamic application data plaintext under the original data directory, so as to realize the encryption replacement of the dynamic application data plaintext under the original data directory to the dynamic application data ciphertext under the target data directory.
[0058] That is to say, this application can perform online transparent encryption replacement on the existing dynamic application data plaintext under the original data directory in the storage device during the normal service provision of the business system. And during the process of online transparent encryption replacement, the business system can still dynamically read and write the original data directory, that is, it will not affect the normal operation of the business system. Moreover, this online transparent encryption replacement process occurs automatically at the operating system layer, so it is transparent to the business system at the application layer, and the application logic of the business system remains unchanged.
[0059] However, since the business system is still dynamically accessing the dynamic application data plaintext under the original data directory during the process of online transparent encryption replacement, there are two different situations here:
[0060] In the first case, the business system only supports reading the existing plaintext files of dynamic application data in the original data directory. In this case, during the encryption replacement process executed by the operating system, the business system reads the existing plaintext files of dynamic application data in the original data directory via the file system of the operating system, but does not modify the existing plaintext files of dynamic application data in the original data directory. In this case, since the business system does not modify the existing plaintext files of dynamic application data in the original data directory during the transparent encryption replacement process, during the continuous operation of the business system to provide services, the file system transparent encryption and decryption module can be directly called to encrypt the existing plaintext of dynamic application data in the original data directory without generating data conflicts. Moreover, in this case, the business system does not need to stop the service. After encrypting all the plaintext of dynamic application data in the original data directory, the ciphertext of dynamic application data in the original data directory (which is also the target data directory) is obtained. This is why the target data directory and the original data directory can directly use the same data directory in this case.
[0061] In the second case, during the encryption replacement process executed by the operating system, the business system modifies the existing plaintext files of dynamic application data in the original data directory via the file system of the operating system. For example, this is often the case when the business system is a database system. In this case, since the business system modifies the plaintext of dynamic application data in the original data directory during the transparent encryption replacement process, new plaintext of dynamic application data will be generated during the transparent encryption replacement process. Therefore, to avoid data conflicts, encryption is not directly performed in the original data directory, so the target data directory and the original data directory are not the same data directory. Then the encryption replacement from the plaintext of dynamic application data in the original data directory to the ciphertext of dynamic application data in the target data directory includes: calling a synchronization tool to synchronize the plaintext of dynamic application data in the original data directory, and calling the file system transparent encryption and decryption module to encrypt the synchronized plaintext of dynamic application data during the synchronization process. Since the file system transparent encryption and decryption module has been configured to be applied to the target data directory, when the plaintext of dynamic application data is synchronized to the target data directory, the file system transparent encryption and decryption module can automatically encrypt the plaintext of dynamic application data synchronized to the target data directory to obtain the ciphertext of dynamic application data and write it into the target data directory.
[0062] In this case, it is also necessary to pause the business system to complete the transparent encryption replacement of the newly generated dynamic application data plaintext during the transparent encryption replacement process, including: when it is detected that the encryption replacement ratio reaches the ratio threshold, after pausing the business system, complete the encryption replacement of the dynamic application data plaintext newly added under the original data directory to the dynamic application data ciphertext under the target data directory, so as to replace all the dynamic application data plaintext encryption under the original data directory with the dynamic application data ciphertext under the target data directory. In this case, although the business system needs to be paused, most of the dynamic application data plaintext is transparently encrypted and replaced during the normal operation of the business system. Only a small part of the newly added dynamic application data plaintext needs to be transparently encrypted and replaced during the pause of the business system, and the data volume of the newly generated dynamic application data plaintext during the transparent encryption replacement process is very limited and the time consumption is very short. Therefore, the pause duration of the business system is also very short, and the impact on the business system is small.
[0063] Detecting whether the encryption replacement ratio reaches the ratio threshold includes the following three different detection methods: (1) In one implementation, when it is determined through the synchronization tool that the synchronization increment data of the dynamic application data plaintext under the original data directory is less than the data volume threshold, it is determined that the encryption replacement ratio reaches the ratio threshold. The synchronization increment data can be directly given by the synchronization tool, and the data volume threshold is a small user-defined value. (2) In another implementation, when the estimated synchronization encryption duration calculated based on the data volume of the dynamic application data plaintext under the original data directory and the synchronization encryption speed is less than the duration threshold, it is determined that the encryption replacement ratio reaches the ratio threshold. The duration threshold is a small user-defined value. (3) In another implementation, when it is determined that the data volume difference between the dynamic application data plaintext under the original data directory and the dynamic application data ciphertext under the target data directory is within the difference threshold range, it is determined that the encryption replacement ratio reaches the ratio threshold. The difference threshold range is a small user-defined value. No matter which implementation method is adopted, when it is determined that the encryption replacement ratio reaches the ratio threshold, it means that the encryption replacement of the remaining dynamic application data plaintext takes a short time, that is, it means that the pause duration of the business system is short and within an acceptable range.
[0064] For example, in an example, the clear text of the dynamic application data in the original data directory is 2TB. When encrypting and replacing it according to the traditional method, the business system needs to be suspended and all 2TB of the clear text of the dynamic application data needs to be encrypted and replaced. The encryption and replacement of 2TB of the clear text of the dynamic application data often takes several hours or more, so the business system also needs to be suspended for several hours or more. When using the method of the present application, first, the existing 2TB of the clear text of the dynamic application data is transparently encrypted and replaced during the normal service operation of the business system. During this process, new clear text of the dynamic application data will also be generated. Continuously perform transparent encryption and replacement until it is detected that the data volume difference between the clear text of the dynamic application data in the original data directory and the ciphertext of the dynamic application data in the target data directory is 20GB. Then, suspend the business system and perform transparent encryption and replacement on the remaining 20GB of the clear text of the dynamic application data. The encryption and replacement of 20GB of the clear text of the dynamic application data often only takes a few minutes. Therefore, the business system also only needs to be suspended for a few minutes. Therefore, although the business system also needs to be suspended in the second case, the suspension duration is very limited and has little impact on the business system.
[0065] The synchronization tool used in the second case can adopt the corresponding synchronization tool under the existing operating system, such as the rsync tool under the common Linux operating system and the bvckup2 tool under the Windows operating system. Further, in another embodiment, the synchronization tool used is a multi-threaded synchronization tool. The multi-threaded synchronization tool encrypts and replaces the clear text of the dynamic application data in the original data directory to the ciphertext of the dynamic application data in the target data directory through multi-threaded parallel execution, thereby improving the efficiency of encryption and replacement.
[0066] Step S3, after completing the encryption and replacement and determining that the ciphertext of the dynamic application data in the target data directory meets the consistency requirement with the clear text of the dynamic application data in the original data directory, the business system accesses the ciphertext of the dynamic application data in the target data directory through the transparent encryption and decryption module of the operating system's file system.
[0067] To ensure the accuracy of the encryption and replacement and also ensure the accuracy of the ciphertext of the dynamic application data after encryption and replacement, consistency detection needs to be performed first after completing the encryption and replacement. In one embodiment, the consistency detection includes: when it is determined that the data content and data attributes of the ciphertext of the dynamic application data in the target data directory are both consistent with the clear text of the dynamic application data in the original data directory, it is determined that the consistency requirement is met; otherwise, it is determined that the consistency requirement is not met and the encryption and replacement are performed again. It includes:
[0068] (1) Data content consistency detection: List all file directories in the target data directory and all file directories in the original data directory respectively. Compare the file directories in the target data directory and the file directories in the original data directory line by line. When the file directories in the target data directory are the same as those in the original data directory, it is determined that the data content of the dynamic application data ciphertext in the target data directory is consistent with the dynamic application data plaintext in the original data directory.
[0069] (2) Data attribute consistency detection: View the hidden permissions of the dynamic application data ciphertext in the target data directory and the hidden permissions of the dynamic application data plaintext in the original data directory respectively. Compare the hidden permissions of the dynamic application data ciphertext and the hidden permissions of the dynamic application data plaintext line by line. When the hidden permissions of the dynamic application data ciphertext and the dynamic application data plaintext are the same, it is determined that the data attributes of the dynamic application data ciphertext in the target data directory are consistent with the dynamic application data plaintext in the original data directory.
[0070] That is, in this embodiment, consistency detection is performed on both data content and data attributes. Only when both aspects meet the consistency requirements, it is determined that the dynamic application data plaintext and the dynamic application data ciphertext meet the consistency requirements, and finally it is determined that the encryption replacement has been accurately completed. Otherwise, the transparent encryption replacement is performed again until the consistency requirements are met.
[0071] After determining that the dynamic application data ciphertext and the dynamic application data plaintext meet the consistency requirements, the dynamic application data ciphertext in the target data directory can be enabled. When the business system only supports reading operations on the existing dynamic application data plaintext files in the original data directory, since the target data directory and the original data directory are the same directory, there is no need to modify the application logic of the business system to achieve the switch from dynamic application data plaintext to dynamic application data ciphertext.
[0072] When the business system supports modifying operations on the existing dynamic application data plaintext files in the original data directory, first, the target data directory is used to replace the original data directory, including: backing up the dynamic application data plaintext in the original data directory and renaming the original directory name of the original data directory, and then updating the directory name of the target data directory to the original directory name of the original data directory. After restarting the business system, although the business logic of the business system still keeps the original directory name of the original data directory for reading and writing unchanged, it actually switches to reading and writing the dynamic application data ciphertext in the target data directory, thus achieving the switch from dynamic application data plaintext to dynamic application data ciphertext without modifying the application logic of the business system.
[0073] Taking the case where the business system supports the modification operation of the existing dynamic application data plaintext files in the original data directory as an example, during the process of converting the dynamic application data of the business system from the plaintext state to the ciphertext state in the first stage, the business system still runs on the dynamic application data plaintext, that is, as Figure 3 and Figure 5 shown, the business system still reads and writes the dynamic application data plaintext in the original data directory via the file system. During this process, the file system reads the dynamic application data plaintext in the original data directory and transmits it to the synchronization tool. The synchronization tool performs data synchronization via the file system. While synchronizing the data, the synchronized plaintext data is processed into ciphertext data by the transparent encryption and decryption module of the file system, and finally the ciphertext data is synchronously written into the target data directory.
[0074] After seamlessly converting the dynamic application data of the business system from the plaintext state to the ciphertext state, the subsequent business system will run on the dynamic application data ciphertext, and the newly generated dynamic application data will also be encrypted and written into the storage device, as Figure 4 and Figure 6 shown, including the following processes:
[0075] (1) For the data writing process, when the operating system receives a write access request from the business system, it calls the transparent encryption and decryption module of the file system to encrypt the dynamic application data plaintext carried in the write access request to obtain the dynamic application data ciphertext and write it into the target data directory of the storage device.
[0076] (2) For the data reading process, when the operating system receives a read access request from the business system, it reads the dynamic application data ciphertext from the target data directory of the storage device according to the read access request, and calls the transparent encryption and decryption module of the file system to decrypt the read dynamic application data ciphertext to obtain the dynamic application data plaintext and return it to the business system.
[0077] Moreover, in this process, the transparent encryption and decryption module of the file system directly completes the encryption and decryption operations of the dynamic application data, and the application logic of the business system remains unchanged, thus realizing seamless encryption and decryption. Moreover, there is no need to perform API calls for each encryption and decryption, so the frequent interaction between the application layer and the kernel layer is reduced, which is beneficial to reducing the system call overhead and improving the system performance, thereby realizing a truly seamless switch from the dynamic application data plaintext to the dynamic application data ciphertext.
[0078] The file system transparent encryption and decryption module implements encryption and decryption operations according to its own business logic. In one embodiment, the encryption and decryption method implemented by the file system transparent encryption and decryption module includes: when encrypting dynamic application data, first obtain random information from the hardware root key generator, receive confidential materials from the centralized control server by establishing a secure transmission channel, and these information and modules are loaded into the kernel of the operating system. The unique key processing module uses the customer's unique random information to generate a key seed and put it in the kernel module. After selecting the data file that needs to be encrypted and protected, the encryption module will generate a different, irregular, and random key index for each selected file. The key index does not contain any information related to the key, that is, the "mutual information" between the two is zero. This key index is passed to the kernel module and added to the previous key seed for processing and generates a key for any single file. After the key is encrypted, it is passed to the file encryption and decryption module and the corresponding file is encrypted. At the same time, the key index will also be stored together with the corresponding encrypted file. When decrypting dynamic application data, the key index will be read to the kernel module, and the key will be generated again using the same logic as when encrypting the data, and then the file will be transparently decrypted using this key.
[0079] The above is only a preferred embodiment of the present application, and the present application is not limited to the above embodiments. It is understood that other improvements and changes directly derived or associated by those skilled in the art without departing from the spirit and concept of the present application should be considered to be included in the protection scope of the present application.
Claims
1. A method for online transparent encryption and replacement of dynamic application data, characterized in that The described online transparent encryption replacement method for dynamic application data includes: Deploy a file system transparent encryption and decryption module in the operating system of the business system, and apply the file system transparent encryption and decryption module to the target data directory in the storage device connected to the operating system; During the process that the business system accesses the plaintext of dynamic application data in the original data directory via the file system of the operating system to run the business application, call the file system transparent encryption and decryption module to encrypt the plaintext of dynamic application data in the original data directory, so as to realize the encryption replacement of the plaintext of dynamic application data in the original data directory to the ciphertext of dynamic application data in the target data directory; After completing the encryption replacement and determining that the ciphertext of dynamic application data in the target data directory meets the consistency requirement with the plaintext of dynamic application data in the original data directory, the business system accesses the ciphertext of dynamic application data in the target data directory via the file system transparent encryption and decryption module of the operating system.
2. The dynamic application data online transparent encryption and replacement method according to claim 1, wherein The business system accessing the ciphertext of dynamic application data in the target data directory via the file system transparent encryption and decryption module of the operating system includes: When the operating system receives a write access request from the business system, call the file system transparent encryption and decryption module to encrypt the plaintext of dynamic application data carried in the write access request to obtain the ciphertext of dynamic application data and write it into the target data directory of the storage device; When the operating system receives a read access request from the business system, read the ciphertext of dynamic application data from the target data directory of the storage device according to the read access request, and call the file system transparent encryption and decryption module to decrypt the read ciphertext of dynamic application data to obtain the plaintext of dynamic application data and return it to the business system.
3. The dynamic application data online transparent encryption and replacement method according to claim 1, characterized in that When the business system supports the modification operation of the existing plaintext file of dynamic application data in the original data directory, the target data directory and the original data directory are two different directories; When the business system only supports the read operation of the existing plaintext file of dynamic application data in the original data directory, the target data directory and the original data directory are the same directory.
4. The dynamic application data online transparent encryption and replacement method according to claim 1, characterized in that When the business system supports the modification operation of the existing plaintext file of dynamic application data in the original data directory, calling the file system transparent encryption and decryption module to encrypt the plaintext of dynamic application data in the original data directory includes: Call a synchronization tool to synchronize the plaintext of dynamic application data in the original data directory, and call the file system transparent encryption and decryption module to encrypt the synchronized plaintext of dynamic application data during the synchronization process.
5. The dynamic application data online transparent encryption and replacement method according to claim 3, characterized in that, When the business system supports the modification operation of the existing plaintext file of dynamic application data in the original data directory, the online transparent encryption replacement method for dynamic application data further includes: When it is detected that the encryption replacement ratio reaches the ratio threshold, pause the business system and then complete the encryption replacement of the newly added plaintext of dynamic application data in the original data directory to the ciphertext of dynamic application data in the target data directory; after completing the encryption replacement and determining that the ciphertext of dynamic application data in the target data directory meets the consistency requirement with the plaintext of dynamic application data in the original data directory, use the target data directory to replace the original data directory and restart the business system.
6. The dynamic application data online transparent encryption and replacement method according to claim 5, characterized in that Detecting whether the encryption replacement ratio reaches the ratio threshold includes determining that the encryption replacement ratio reaches the ratio threshold when at least one of the following conditions is met: When the synchronization incremental data of the dynamic application data plaintext under the original data directory is determined to be less than the data volume threshold by the synchronization tool; Or, when the estimated synchronization encryption duration calculated based on the data volume of the dynamic application data plaintext under the original data directory and the synchronization encryption speed is less than the duration threshold; Or, determining that the data volume difference between the dynamic application data plaintext under the original data directory and the dynamic application data ciphertext under the target data directory is within the difference threshold range.
7. The online transparent encryption replacement method for dynamic application data according to claim 1, characterized in that, Detecting whether the dynamic application data ciphertext under the target data directory and the dynamic application data plaintext under the original data directory meet the consistency requirement includes: When it is determined that the data content and data attributes of the dynamic application data ciphertext under the target data directory and the dynamic application data plaintext under the original data directory are both consistent, it is determined that the consistency requirement is met; otherwise, it is determined that the consistency requirement is not met and encryption replacement is performed again.
8. The dynamic application data online transparent encryption and replacement method according to claim 7, characterized in that, Detecting the data content and data attributes of the dynamic application data ciphertext under the target data directory and the dynamic application data plaintext under the original data directory includes: List all file directories under the target data directory and all file directories under the original data directory respectively, compare the file directories under the target data directory and the file directories under the original data directory line by line. When the file directories under the target data directory and the file directories under the original data directory are the same, it is determined that the data content of the dynamic application data ciphertext under the target data directory and the dynamic application data plaintext under the original data directory is consistent; View the hidden permissions of the dynamic application data ciphertext under the target data directory and the hidden permissions of the dynamic application data plaintext under the original data directory respectively, and compare the hidden permissions of the dynamic application data ciphertext and the hidden permissions of the dynamic application data plaintext line by line. When the hidden permissions of the dynamic application data ciphertext and the dynamic application data plaintext are the same, it is determined that the data attributes of the dynamic application data ciphertext under the target data directory and the dynamic application data plaintext under the original data directory are consistent.
9. The online transparent encryption replacement method for dynamic application data according to claim 1, wherein The data operated by the business system is stored based on files, and the operating system of the business system is an operating system based on the Linux kernel, Windows kernel, XNU kernel, or microkernel.
10. The dynamic application data online transparent encryption and replacement method according to claim 4, characterized in that The synchronization tool used is a multi-threaded synchronization tool, and the multi-threaded synchronization tool performs encryption replacement of the dynamic application data plaintext under the original data directory to the dynamic application data ciphertext under the target data directory through multi-threaded parallel execution.
11. The dynamic application data online transparent encryption replacement method according to claim 5, wherein Using the target data directory to replace the original data directory includes: Performing data backup on the dynamic application data plaintext under the original data directory and renaming the original directory name of the original data directory, and then updating the directory name of the target data directory to the original directory name of the original data directory.
12. The dynamic application data online transparent encryption and replacement method according to claim 1, characterized in that Before starting the encryption replacement, configure the file system transparent encryption and decryption module to monitor the target data directory, so that the file system transparent encryption and decryption module automatically encrypts the dynamic application data plaintext synchronized to the target data directory.
13. The online transparent encryption replacement method for dynamic application data according to claim 1, characterized in that The file system transparent encryption and decryption module is deployed in the kernel of the operating system.
14. The dynamic application data online transparent encryption and replacement method according to claim 1, wherein The file system transparent encryption and decryption module is deployed in the user space of the operating system.