Multi-tenant data encryption method and device based on Redfish protocol and storage medium
Through the multi-tenant data encryption method based on the Redfish protocol, combined with advanced encryption and authentication technology, data security and access control of the multi-tenant cloud storage system are realized, and the problems of data leakage, poor permission management, weak abnormal detection capabilities and complex operation and maintenance in the existing technology are solved, providing a more secure, efficient and flexible multi-tenant cloud storage security management system.
Patent Information
- Application Number
- CN202510768101.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-10
- Publication Date
- 2025-07-08
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
The existing multi-tenant cloud storage system has vulnerabilities in data security, lacking a strong storage encryption and access control mechanism, which can easily lead to data leakage or unauthorized access, with extensive permission management, making it difficult to achieve fine-grained access control, traditional systems are difficult to cope with new attacks, lacking intelligent security detection and response mechanisms, and high operation and maintenance costs.
The multi-tenant data encryption method based on the Redfish protocol is adopted, and through the modular design of the gateway department, management control department and storage department, combined with the AES-256 and RSA-4096 encryption mechanism, RBAC and OAuth authentication, AI behavior analysis, and automatic security response mechanism, data encryption, logical volume management, multi-factor authentication and regular maintenance are realized to ensure data security and access control.
It realizes the security of data storage and transmission, ensures physical and logical isolation of data of different tenants, strictly controls access rights, dynamically detects abnormal access, automatically responds to security threats, reduces operation and maintenance costs, and improves system maintenance and security.
Smart Images

Figure CN120281587A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of data security, and in particular to a multi-tenant data encryption method, device and storage medium based on the Redfish protocol. Background Art
[0002] In the era of cloud computing and big data, data security has become an important research direction in the field of information technology. As enterprises, government agencies, and individual users increasingly rely on cloud storage services, the security, integrity, and availability of data face severe challenges. The following are the main pain points of current cloud storage security: (1) High risk of data leakage: Data in cloud storage is usually stored on shared infrastructure, and multiple tenants share storage resources. Without a strong data isolation mechanism, sensitive data may be leaked.
[0003] (2) Difficulty in access control: Traditional permission management methods (such as username + password) cannot meet the security requirements of enterprise-level applications. A more complex identity authentication mechanism, such as role-based access control (RBAC) + OAuth 2.0, is required to ensure that data access permissions are strictly controlled.
[0004] (3) Challenges in data encryption and key management: Data encryption is an important means to protect data, but the storage and management of encryption keys are difficult points. If the key management is improper, the key may be leaked, which may endanger the security of all encrypted data.
[0005] (4) Lack of intelligent security detection and response: Most traditional security management systems rely on static rules (such as access control based on IP blacklists) for security detection and are difficult to effectively respond to advanced attacks (such as APT attacks). In recent years, AI-driven behavior analysis technology has begun to be applied in the field of security detection and can more accurately identify abnormal access patterns.
[0006] (5) Increased compliance and auditing requirements: Governments around the world have increasingly strict regulatory requirements for data security, such as the General Data Protection Regulation (GDPR) and the Data Security Law, which require enterprises to provide more perfect security measures such as data encryption, access control, and log auditing.
[0007] Multi-tenant cloud storage environments have the characteristics of multiple users sharing the same physical storage resources. How to ensure the physical and logical isolation of data from different tenants has become a key issue in cloud storage security. Existing multi-tenant cloud storage systems have loopholes in data security and lack strong storage encryption and access control mechanisms, which can easily lead to data leakage or unauthorized access. Traditional storage architectures have poor isolation of multi-tenant data, which may cause data mixing or conflicts between tenants. The permission management of existing systems is relatively extensive, making it difficult to implement fine-grained access control, resulting in increased security risks. Traditional systems often rely on single-factor authentication methods such as username + password, which are easily cracked by brute force. Existing systems usually rely on static rules to identify security threats and are difficult to respond to new attacks. Traditional security systems usually rely on manual intervention to handle security incidents, and the response speed is slow. Traditional security management systems rely on manual maintenance, with high operation and maintenance costs and low efficiency. Summary of the invention
[0008] The present invention provides a multi-tenant data encryption method, device and storage medium based on the Redfish protocol, aiming to solve at least one of the technical problems existing in the prior art.
[0009] The technical solution of the present invention is a multi-tenant data encryption method based on the Redfish protocol. The multi-tenant data encryption method based on the Redfish protocol is applied to a multi-tenant data encryption device based on the Redfish protocol. The multi-tenant data encryption device based on the Redfish protocol includes a gateway part, a management control part and a storage part connected in sequence. The gateway part includes an identity authentication and access control module and a security monitoring and anomaly detection module; the management control part includes a storage management module, a data encryption and key management module, an automatic security response module and a system operation and maintenance module; the storage part includes a physical storage server and a distributed storage server. The multi-tenant data encryption method based on the Redfish protocol includes the following steps: S100, the terminal device connects to the preset storage unit by accessing the gateway unit, and sends a data storage and / or access request; S200: If access is allowed, the data encryption and key management module returns the encrypted storage volume ID information, performs symmetrical encryption on the data storage process, performs asymmetrical encryption on the key, and performs confidential storage and rotation on the key; S300, the identity authentication and access control module obtains access rights and access storage volumes, verifies the identity of the user of the connected terminal device and checks the access rights, allows authorized access, and denies illegal access; S400, the security monitoring and anomaly detection module monitors the Redfish API remote management interface, analyzes access behaviors, audits logs, and detects abnormal behaviors; S500. If the security monitoring and anomaly detection module detects a security event, the automatic security response module makes an immediate response action, and the immediate response action includes one or more combinations of blocking an IP address, triggering a key revocation action, and recording a security event; S600. The system operation and maintenance module performs real-time and regular maintenance operations on the multi-tenant data encryption device based on the Redfish protocol.
[0010] Further, in step S100, The terminal device is provided with a Redfish API remote management interface for accessing the gateway part; The storage management module of the management control part makes pre-settings for the storage part, including the following steps: S10. Dynamically divide a storage pool through logical volume management (LVM), including setting the name and size of the storage pool; S20. Set the data redundancy level of the divided storage pool, and the data redundancy level is RAID-5 or RAID-10; The terminal device connects to a specific storage pool in the storage part through the Redfish API remote management interface.
[0011] Further, step S200 includes: S210. The data storage process is symmetrically encrypted by AES-256, a key is generated and applied to the storage volume to ensure the secure storage of data and prevent unauthorized users from accessing it; S220. Obtain the key ID information, and perform asymmetric encryption using RSA-4096 to protect the security of key transmission. Among them, the key is stored and rotated through a key management system (KMS).
[0012] Further, step S300 includes: S310. Create user roles; S320. Based on role-based access control (RBAC), restrict the permissions of users, and the restricted user permissions at least include restricting the IP addresses that users can access; S330. Based on the OAuth protocol and JWT token verification, before a user attempts to access a storage volume, the storage part verifies the user's access permission based on the access permission of the storage volume, makes a response to allow or deny access, and records the request log.
[0013] Further, step S300 also includes: S340. If access is allowed, access the stored data in the storage part; S350. Record the access logs and send the access logs to the security monitoring and anomaly detection module.
[0014] Further, step S400 includes: S410. Monitor the access to the Redfish API remote management interface in real time; S420. Identify the access patterns based on AI behavior analysis, monitor the abnormal behaviors and give alarms, where the abnormal behaviors at least include unauthorized access; S430. Audit the request logs and access logs based on Redfish event subscription; S440. The anomaly detection identifies potential attack behaviors and performs brute-force cracking protection.
[0015] Further, step S600 includes: S610. Perform key rotation operations regularly; S620. Perform storage pool status checks regularly; S630. Analyze and give early warnings for the logs; S640. Update and optimize the access control policy; S650. Update the security policy.
[0016] Further, the present invention also proposes a multi-tenant data encryption device based on the Redfish protocol for implementing the multi-tenant data encryption method based on the Redfish protocol. The multi-tenant data encryption device based on the Redfish protocol includes: a gateway part, a management control part and a storage part which are connected in sequence, where the gateway part includes an authentication and access control module and a security monitoring and anomaly detection module; the management control part includes a storage management module, a data encryption and key management module, an automatic security response module and a system operation and maintenance module; the storage part includes a physical storage server and a distributed storage server.
[0017] Further, the authentication and access control module restricts user permissions through role-based access control (RBAC) and OAuth 2.0, ensures API access security through JWT token management, and protects user account security through multi-factor authentication (MFA); the security monitoring and anomaly detection module records the storage status based on Redfish event subscription, monitors the access patterns through AI, detects abnormal behaviors, and ensures storage and access security; The storage management module divides storage pools through Logical Volume Management (LVM), performs dynamic storage allocation through StoragePool, and ensures data redundancy through RAID-5 / RAID-10, ensuring physical and logical isolation of each tenant's data at the storage level to prevent data leakage or access conflicts; The data encryption and key management module protects stored data through AES-256 symmetric encryption, protects key transmission security through RSA-4096 asymmetric encryption, and manages keys through a Key Management System (KMS); The automatic security response module automatically takes security measures when detecting security threats; The system operation and maintenance module continuously optimizes security policies, performs operations such as regular key rotation, log analysis, and access control optimization to ensure long-term security and stability of the system.
[0018] Furthermore, the present invention also proposes a computer-readable storage medium, on which program instructions are stored, and when the program instructions are executed by a processor, the multi-tenant data encryption method based on the Redfish protocol described above is implemented.
[0019] The beneficial effects of the present invention are: The present invention ensures the security of data storage and transmission through AES-256 and RSA-4096 encryption mechanisms; ensures physical and logical isolation of data of different tenants through logical volume management and storage pools to improve data security; adopts RBAC and OAuth authentication to ensure that access rights are strictly controlled and effectively prevent unauthorized access; introduces multi-factor authentication and JWT token mechanisms to ensure the authenticity of user identities; dynamically detects abnormal access patterns through AI behavior analysis to identify potential attack behaviors; integrates an automatic security response mechanism to automatically block suspicious IPs, revoke access keys, and trigger security alerts once abnormal access is detected; provides functions such as regular key rotation, log analysis warning, and storage pool status monitoring to improve the maintainability of the system. Description of the Drawings
[0020] Figure 1 It is a flowchart of the multi-tenant data encryption method based on the Redfish protocol.
[0021] Figure 2 It is a schematic diagram of the multi-tenant data encryption device based on the Redfish protocol.
[0022] Reference Numerals: 100, gateway unit; 110, authentication and access control module; 120, security monitoring and anomaly detection module; 200, management control unit; 210, storage management module; 220, data encryption and key management module; 230, automatic security response module; 240, system operation and maintenance module; 300, storage unit; 310, physical storage server; 320, distributed storage server. Detailed Embodiment
[0023] The following will clearly and completely describe the concept, specific structure and technical effects of the present invention in combination with the embodiments and the drawings, so as to fully understand the purpose, solution and effects of the present invention. It should be noted that, without conflict, the embodiments in the present application and the features in the embodiments may be combined with each other.
[0024] It should be noted that, unless otherwise specified, when a certain feature is referred to as "fixed" or "connected" to another feature, it can be directly fixed or connected to the other feature, or indirectly fixed or connected to the other feature. In addition, the up, down, left, right, top, bottom, etc. used in the present invention are only relative to the mutual positional relationship of the components of the present invention in the drawings.
[0025] In addition, unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by those skilled in the technical field of the present invention. The terms used in the description of the present specification are only for describing specific embodiments, and are not intended to limit the present invention. The term "and / or" used herein includes any combination of one or more of the related listed items.
[0026] It should be understood that although the terms first, second, third, etc. may be used in the present disclosure to describe various elements, these elements should not be limited to these terms. These terms are only used to distinguish elements of the same type from each other. For example, without departing from the scope of the present disclosure, the first element may also be referred to as the second element, and similarly, the second element may also be referred to as the first element.
[0027] Refer to Figures 1 to 2, in some embodiments, the technical solution of the present invention is a multi-tenant data encryption method based on the Redfish protocol. The multi-tenant data encryption method based on the Redfish protocol is applied to a multi-tenant data encryption device based on the Redfish protocol. The multi-tenant data encryption device based on the Redfish protocol includes a gateway unit 100, a management control unit 200, and a storage unit 300 connected in sequence. The gateway unit 100 includes an authentication and access control module 110 and a security monitoring and anomaly detection module 120; the management control unit 200 includes a storage management module 210, a data encryption and key management module 220, an automatic security response module 230, and a system operation and maintenance module 240; the storage unit 300 includes a physical storage server 310 and a distributed storage server 320. Refer to Figure 1 , the multi-tenant data encryption method based on the Redfish protocol includes the following steps: S100. The terminal device connects to the preset storage unit 300 by accessing the gateway unit 100 and sends a data storage and / or access request. S200. If access is allowed, the data encryption and key management module 220 returns the encrypted storage volume ID information. The data encryption and key management module 220 performs symmetric encryption on the data storage process, performs asymmetric encryption on the key, and simultaneously performs secure storage and rotation of the key. S300. The authentication and access control module 110 obtains the access permission and access storage volume, verifies the identity of the terminal device user accessing and checks the access permission, allows authorized access, and rejects illegal access. S400. The security monitoring and anomaly detection module 120 monitors the Redfish API remote management interface, analyzes the access behavior, audits the log, and detects abnormal behavior. S500. If the security monitoring and anomaly detection module 120 discovers a security event, the automatic security response module 230 makes an immediate response behavior, and the immediate response behavior includes one or a combination of blocking the IP address, triggering the key revocation action, and recording the security event. S600. The system operation and maintenance module 240 performs real-time and regular maintenance operations on the multi-tenant data encryption device based on the Redfish protocol.
[0028] The beneficial effects of the present invention are: The present invention ensures the security of data storage and transmission through AES-256 and RSA-4096 encryption mechanisms; guarantees the physical and logical isolation of data for different tenants through logical volume management and storage pools, enhancing data security; adopts RBAC and OAuth authentication to ensure that access rights are strictly controlled, effectively preventing unauthorized access; introduces multi-factor authentication and JWT token mechanisms to ensure the authenticity of user identities; dynamically detects abnormal access patterns through AI behavior analysis to identify potential attack behaviors; integrates an automatic security response mechanism that automatically blocks suspicious IPs, revokes access keys, and triggers security alerts once abnormal access is detected; provides functions such as regular key rotation, log analysis warning, and storage pool status monitoring to improve the maintainability of the system.
[0029] Compared with the prior art, (1) Insufficient data storage security: Data in cloud storage is usually stored on shared infrastructure, and multiple tenants share storage resources. Without a strong data isolation mechanism, sensitive data leakage may occur. Existing multi-tenant cloud storage systems have vulnerabilities in data security, lacking strong storage encryption and access control mechanisms, which are prone to data leakage or unauthorized access. The present invention ensures the security of data storage and transmission through the AES-256 + RSA-4096 encryption mechanism.
[0030] (2) Messy data storage management and lack of isolation: Traditional storage architectures have poor isolation for multi-tenant data, which may lead to data mixing or conflicts between tenants. The present invention adopts logical volume management (LVM) + storage pool to ensure the physical and logical isolation of data for different tenants, enhancing data security.
[0031] (3) Insufficiently fine-grained access control and chaotic permission management: Data encryption is an important means to protect data, but the storage and management of encryption keys are difficult points. If the key management is improper, key leakage may occur, which may endanger the security of all encrypted data. Traditional permission management methods (such as username + password) cannot meet the security requirements of enterprise-level applications and require more complex identity authentication mechanisms. The permission management of existing systems is relatively extensive and difficult to achieve fine-grained access control, resulting in increased security risks. The present invention adopts RBAC (role-based access control) + OAuth 2.0 authentication to ensure that the access rights of different roles are strictly controlled, effectively preventing unauthorized access.
[0032] (4) Weak user authentication mechanism and account security risks: Traditional systems mostly rely on the single-factor authentication method of username + password, which is easily brute-forced. The present invention introduces multi-factor authentication (MFA) + JWT token mechanism to ensure the authenticity of user identities and improve account security.
[0033] (5) Lack of an anomaly detection mechanism and inability to effectively identify attack behaviors: Most traditional security management systems rely on static rules (such as access control based on IP blacklists) for security detection and are difficult to effectively cope with advanced attacks (such as APT attacks). Existing systems usually rely on static rules to identify security threats and are difficult to handle new types of attacks. Through Redfish event subscription + AI behavior analysis, the present invention can dynamically detect abnormal access patterns, identify potential attack behaviors, and give real-time alarms.
[0034] (6) Lack of automatic security response and inability to promptly prevent security threats: Traditional security systems usually rely on manual intervention to handle security incidents, and the response speed is slow. The present invention integrates an automatic security response mechanism. Once abnormal access is detected, it can automatically block suspicious IPs, revoke access keys, and trigger security alerts, thereby quickly preventing attacks and reducing security risks.
[0035] (7) Complex system operation and maintenance, lack of automated management: Traditional security management systems rely on manual maintenance, with high operation and maintenance costs and low efficiency. The present invention provides automated management functions such as regular key rotation, log analysis and warning, and storage pool status monitoring, improving the maintainability and long-term stability of the system.
[0036] Through the present invention, problems in the prior art such as inaccurate access control, inflexible encryption management, weak anomaly detection ability, poor cross-platform compatibility, and complex operation and maintenance can be effectively solved, thereby providing a more secure, efficient, and flexible multi-tenant cloud storage security management system to meet the requirements for data security, compliance, and efficient management in the modern cloud computing environment.
[0037] Based on the Redfish protocol, this technical solution proposes a security management system for multi-tenant cloud storage and server management, which is applicable to cloud computing, enterprise data centers, and multi-tenant server environments. The system provides a complete data security and access control mechanism through remote API management, data encryption, multi-tenant data isolation, fine-grained access control (RBAC), AI behavior detection, and automatic security response. The core objectives include: (1) Data encryption and key management: Use AES-256 and RSA-4096 encryption technologies to protect the security of stored data.
[0038] (2) Multi-tenant data isolation: Through logical volume management (LVM) + storage pool, physical and logical isolation of data is carried out to ensure data security.
[0039] (3) Fine-grained access control: Use RBAC (role-based access control) + OAuth 2.0 to ensure strict control of access permissions for different tenants.
[0040] (4) Security Monitoring and Anomaly Detection: Detect user access patterns through Redfish event subscription (EventService) + AI behavior analysis to prevent malicious attacks.
[0041] (5) Automatic Security Response: Once an abnormal behavior is detected, the system automatically takes measures such as blocking the IP and revoking the key.
[0042] Furthermore, referring to Figure 1 , in step S100, The terminal device is provided with a Redfish API remote management interface for accessing the gateway unit 100; The storage management module 210 of the management control unit 200 performs presetting on the storage unit 300, including the following steps: S10. Dynamically divide the storage pool (Storage Pool) through logical volume management (LVM), including setting the name and size of the storage pool; S20. Set the data redundancy level of the divided storage pool, and the data redundancy level is RAID-5 or RAID-10; The terminal device connects to a specific storage pool in the storage unit 300 through the Redfish API remote management interface.
[0043] Specifically, the design logic of the storage management module 210 is to ensure physical and logical isolation of each tenant's data at the storage level to prevent data leakage or access conflicts. The implementation technical solution is to divide the storage pool (Storage Pool) through logical volume management (LVM), perform dynamic storage allocation on the storage pool (Storage Pool), and protect data redundancy with RAID-5 / RAID-10. In a specific embodiment, Tenant A applies for a 500GB storage pool POST / redfish / v1 / Storage / {id} / StoragePools Content-Type: application / json { "Name": "TenantA_Pool", "RAID": "RAID-5", "Capacity": "500GB" } Tenant B applies for a 1TB storage pool POST / redfish / v1 / Storage / {id} / StoragePools Content-Type: application / json { "Name": "TenantB_Pool", "RAID": "RAID-10", "Capacity": "1TB" } Furthermore, referring to Figure 1 , step S200 includes: S210. The data storage process is symmetrically encrypted by AES-256 to generate a key and apply it to the storage volume to ensure secure data storage and prevent unauthorized access; S220. Obtain the key ID information and perform asymmetric encryption using RSA-4096 to protect the security of key transmission. Among them, the key is stored and rotated through a key management system (KMS).
[0044] Specifically, when storing data, AES-256 is used for encryption to ensure that the data cannot be accessed by unauthorized users. At the same time, RSA-4096 is used to protect the key transmission. Implement the technical solution: AES-256 symmetric encryption to protect data storage; RSA-4096 asymmetric encryption to protect the security of key transmission; the key management system (KMS) is used for key storage and rotation.
[0045] In a specific embodiment, the storage volume of tenant A is encrypted with AES-256: PATCH / redfish / v1 / StorageServices / {id} / Volumes / TenantA_Volume Content-Type: application / json { "EncryptionAlgorithm": "AES-256" } Generate a key and apply it to the storage volume POST / redfish / v1 / KeyManagement / Keys Content-Type: application / json { "KeyType": "AES", "KeySize": 256} Further, referring to Figure 1 , step S300 includes: S310. Create a user role; S320. Restrict the user's permissions based on role-based access control (RBAC), and the restricted user permissions at least include restricting the IP addresses that the user can access; S330. Based on the OAuth protocol and JWT token verification, before the user attempts to access the storage volume, the storage unit 300 verifies the user's access permission based on the access permission of the storage volume, makes a response to allow or deny access, and records the request log.
[0046] Specifically, the access control design logic is to ensure that the user identity is verified and strictly control the user access permissions. The implementation technical solution is to use RBAC (role-based access control) to restrict user permissions; OAuth 2.0 + JWT authentication to ensure API access security and IP access restriction to prevent unauthorized access.
[0047] In a specific embodiment, create an administrator role for tenant A: POST / redfish / v1 / AccountService / Roles Content-Type: application / json { "RoleId": "Admin", "Privileges": ["ConfigureManager", "Login"] } Restrict the administrator's access IP: PATCH / redfish / v1 / AccountService / Accounts / TenantA_Admin Content-Type: application / json { "AllowedIP": "192.168.1.100" } Further, referring to Figure 1 , step S300 further includes: S340. If the access is allowed, access the stored data in the storage unit 300; S350. Record the access log and send the access log to the security monitoring and anomaly detection module 120.
[0048] Specifically, the design logic of data access is to ensure that users have the correct access rights when accessing stored data and record all access logs for auditing and analysis. The implementation technical solution is RBAC-based permission management: ensuring that users can only access authorized data; authentication based on OAuth 2.0 and JWT to ensure API access security; access log recording: monitoring and recording all data access operations.
[0049] In a specific embodiment, a tenant A user attempts to access a storage volume: GET / redfish / v1 / Storage / {id} / Volumes / TenantA_Volume Authorization: Bearer <jwt-token> The server returns the access permission of the storage volume: { "Id": "TenantA_Volume", "Access": "ReadWrite", "Owner": "TenantA_Admin" } Query the access log: GET / redfish / v1 / Storage / {id} / AccessLogs The server returns the access log: { "Logs": {"User": "TenantA_Admin", "Action": "Read", "Timestamp": "2024-06-01T12:00:00Z"}, {"User": "Unknown", "Action": "Read", "Timestamp": "2024-06-01T12:05:00Z"} ] } Furthermore, referring to Figure 1 , step S400 includes: S410. Monitor the access to the Redfish API remote management interface in real time; S420. Identify the access pattern based on AI behavior analysis, monitor abnormal behaviors and alarm, and the abnormal behaviors include at least unauthorized access; S430. Audit the request log and access log based on Redfish event subscription; S440. Detect potential attack behaviors and protect against brute force cracking through anomaly detection.
[0050] Specifically, the design logic of the security monitoring and anomaly detection module 120 is to monitor the access pattern through AI, detect abnormal behaviors, and ensure the security of storage access. The implementation technical solution is to record the storage status through Redfish event subscription; monitor the user access pattern through AI behavior analysis.
[0051] In a specific embodiment, query the storage access log: GET / redfish / v1 / Storage / {id} / AccessLogs In step S500, the design logic of the automatic security response module 230 is to automatically take security measures when a security threat is detected. The implementation technical solution is to automatically block suspicious IPs; revoke keys to ensure data security.
[0052] In a specific embodiment, the code for the automatic security response module 230 to block abnormal IPs is: PATCH / redfish / v1 / AccountService / AccessPolicy Content-Type: application / json { "BlockedIP": ["192.168.xxxx.xxx"] } Furthermore, referring to Figure 1 , step S600 includes: S610. Perform key rotation operations regularly; S620. Regularly perform storage pool status checks; S630. Analyze and give early warnings for logs; S640. Update and optimize access control policies; S650. Update security policies.
[0053] Specifically, the design logic of the system operation and maintenance module 240 is to perform security maintenance on the storage system regularly to ensure long-term stable operation, and provide functions such as key management, log analysis, and storage pool monitoring. The implementation technical solution is to perform key rotation regularly to prevent the long-term use of the same key; perform storage pool status monitoring to detect storage usage and prevent failures; perform log analysis and early warning to identify abnormal behaviors through AI and improve system security; optimize access control policies and dynamically adjust access permissions according to user behaviors.
[0054] In a specific embodiment, the code to trigger key rotation is: PATCH / redfish / v1 / KeyManagement / Keys / Rotate Content-Type: application / json { "KeyId": "Key-12345" } The code to obtain the storage pool status is: GET / redfish / v1 / Storage / {id} / StoragePools The code for the server to return the storage pool status is: { "Pools": {"Name": "TenantA_Pool", "UsedCapacity": "450GB", "TotalCapacity": "500GB"}, {"Name": "TenantB_Pool", "UsedCapacity": "750GB", "TotalCapacity": "1TB"} } The code for obtaining the system log for security analysis is: GET / redfish / v1 / Storage / {id} / StoragePools The code for obtaining the log data returned by the server is: { "Entries": {"Timestamp": "2024-06-01T12:00:00Z", "Event": "User Login","User": "TenantA_Admin"}, {"Timestamp": "2024-06-01T12:05:00Z", "Event": "UnauthorizedAccess Attempt", "User": "Unknown"} } Furthermore, referring to Figure 2 , the present invention further proposes a multi-tenant data encryption device based on the Redfish protocol for implementing the multi-tenant data encryption method based on the Redfish protocol. The multi-tenant data encryption device based on the Redfish protocol includes: a gateway unit 100, a management control unit 200, and a storage unit 300 connected in sequence, wherein, The gateway unit 100 includes an authentication and access control module 110 and a security monitoring and anomaly detection module 120; The management control unit 200 includes a storage management module 210, a data encryption and key management module 220, an automatic security response module 230, and a system operation and maintenance module 240; The storage unit 300 includes a physical storage server 310 and a distributed storage server 320.
[0055] Furthermore, referring to Figure 2 The authentication and access control module 110 restricts user permissions through role-based access control (RBAC) and OAuth 2.0, manages JWT tokens to ensure API access security, and protects user account security through multi-factor authentication (MFA); The security monitoring and anomaly detection module 120 records the storage status based on Redfish event subscriptions, monitors access patterns through AI, detects abnormal behaviors, and ensures storage and access security; The storage management module 210 divides storage pools through logical volume management (LVM), performs dynamic storage allocation through StoragePool, and ensures data redundancy through RAID-5 / RAID-10, ensuring physical and logical isolation of each tenant's data at the storage level to prevent data leakage or access conflicts; The data encryption and key management module 220 protects stored data through AES-256 symmetric encryption, protects key transmission security through RSA-4096 asymmetric encryption, and manages keys through a key management system (KMS); The automatic security response module 230 automatically takes security measures when detecting security threats; The system operation and maintenance module 240 continuously optimizes security policies, performs operations such as regular key rotation, log analysis, and access control optimization to ensure long-term security and stability of the system.
[0056] Specifically, the storage management module 210 ensures physical and logical isolation of data for different tenants through LVM + storage pool. The data encryption and key management module 220 adopts the AES-256 + RSA-4096 encryption mechanism to protect the security of stored data and keys; provides functions such as key generation, storage, and revocation to ensure data integrity. The authentication and access control module 110 protects user account security through JWT + multi-factor authentication (MFA); uses RBAC + OAuth 2.0 for access permission management to prevent unauthorized access. The security monitoring and anomaly detection module 120 uses Redfish event subscriptions to monitor user operation logs in real time, identify brute-force cracking and unauthorized access; uses AI behavior analysis to monitor access patterns, identify abnormal behaviors and alarm. The automatic security response module 230 automatically executes measures such as blocking IPs, restricting access, and revoking keys once detecting abnormal access behaviors. The system operation and maintenance module 240 continuously optimizes security policies, performs operations such as regular key rotation, log analysis, and access control optimization to ensure long-term security and stability of the system.
[0057] Furthermore, referring to Figure 1 , the present invention also provides a computer-readable storage medium, on which program instructions are stored, and when the program instructions are executed by a processor, the multi-tenant data encryption method based on the Redfish protocol described above is implemented.
[0058] As described above, only the preferred embodiments of the present invention are given. The present invention is not limited to the above-mentioned embodiments. As long as it achieves the technical effects of the present invention by the same means, any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of the present disclosure shall be included within the scope of protection of the present disclosure. Within the scope of protection of the present invention, various different modifications and variations can be made to its technical solutions and / or implementation manners.
Claims
1. A multi-tenant data encryption method based on the Redfish protocol, the multi-tenant data encryption method based on the Redfish protocol is applied to a multi-tenant data encryption device based on the Redfish protocol. The multi-tenant data encryption device based on the Redfish protocol includes a gateway unit (100), a management and control unit (200), and a storage unit (300) connected in sequence. The gateway unit (100) includes an authentication and access control module (110) and a security monitoring and anomaly detection module (120); the management and control unit (200) includes a storage management module (210), a data encryption and key management module (220), an automatic security response module (230), and a system operation and maintenance module (240); the storage unit (300) includes a physical storage server (310) and a distributed storage server (320), characterized in that, The multi-tenant data encryption method based on the Redfish protocol includes the following steps: S100. The terminal device connects to the pre-set storage unit (300) through the gateway unit (100) and sends a data storage and / or access request; S200. If access is allowed, the data encryption and key management module (220) returns the encrypted storage volume ID information. The data encryption and key management module (220) performs symmetric encryption on the data storage process, performs asymmetric encryption on the key, and simultaneously performs secure storage and rotation of the key; S300. The authentication and access control module (110) obtains the access permission and access storage volume, verifies the identity of the terminal device user accessing and checks the access permission, allows authorized access, and rejects illegal access; S400. The security monitoring and anomaly detection module (120) monitors the Redfish API remote management interface, analyzes the access behavior, audits the log, and detects abnormal behavior; S500. If the security monitoring and anomaly detection module (120) discovers a security event, the automatic security response module (230) makes an immediate response behavior, and the immediate response behavior includes one or a combination of blocking the IP address, triggering the key revocation action, and recording the security event; S600. The system operation and maintenance module (240) performs real-time and regular maintenance operations on the multi-tenant data encryption device based on the Redfish protocol.
2. The multi-tenant data encryption method based on the Redfish protocol according to claim 1, wherein In step S100, the terminal device is provided with a Redfish API remote management interface for accessing the gateway unit (100); The storage management module (210) of the management control unit (200) performs pre-settings on the storage unit (300), including the following steps: S10. Dynamically divide the storage pool through logical volume management (LVM), including setting the name and size of the storage pool; S20. Set the data redundancy level of the divided storage pool, and the data redundancy level is RAID-5 or RAID-10; The terminal device connects to a specific storage pool in the storage unit (300) through the Redfish API remote management interface.
3. The multi-tenant data encryption method based on the Redfish protocol according to claim 1, wherein Step S200 includes: S210. The data storage process is symmetrically encrypted by AES-256, a key is generated and applied to the storage volume to ensure the secure storage of data and prevent unauthorized users from accessing it; S220. Obtain the key ID information, perform asymmetric encryption using RSA-4096 to protect the security of key transmission, where the key is stored and rotated through the key management system.
4. The multi-tenant data encryption method based on the Redfish protocol according to claim 1, wherein Step S300 includes: S310. Create user roles; S320. Role-based access control restricts the user's permissions, and the restricted user permissions at least include restricting the IP addresses that the user can access; S330. Based on the OAuth protocol and JWT token verification, before the user attempts to access the storage volume, the storage unit (300) verifies the user's access permission based on the access permission of the storage volume, makes a response of allowing or denying access, and records the request log.
5. The multi-tenant data encryption method based on the Redfish protocol according to claim 4, wherein Step S300 further includes: S340. If access is permitted, access the stored data in the storage unit (300); S350. Record the access log and send the access log to the security monitoring and anomaly detection module (120).
6. The multi-tenant data encryption method based on the Redfish protocol according to claim 1, characterized in that Step S400 includes: S410. Listen for access to the Redfish API remote management interface in real time; S420. Identify the access pattern based on AI behavior analysis, monitor abnormal behavior and give an alarm, where the abnormal behavior includes at least unauthorized access; S430. Audit the request log and access log based on Redfish event subscription; S440. Anomaly detection identifies potential attack behaviors and performs brute-force cracking protection.
7. The multi-tenant data encryption method based on the Redfish protocol according to claim 1, wherein Step S600 includes: S610. Perform key rotation operations regularly; S620. Regularly perform storage pool status checks; S630. Analyze and give early warnings for the logs; S640. Update and optimize the access control policy; S650. Update the security policy.
8. A multi-tenant data encryption device based on the Redfish protocol, which is used to implement the multi-tenant data encryption method based on the Redfish protocol as described in any one of claims 1 to 7, characterized in that, The multi-tenant data encryption device based on the Redfish protocol includes a gateway unit (100), a management control unit (200), and a storage unit (300) connected in sequence, where the gateway unit (100) includes an authentication and access control module (110) and a security monitoring and anomaly detection module (120); the management control unit (200) includes a storage management module (210), a data encryption and key management module (220), an automatic security response module (230), and a system operation and maintenance module (240); the storage unit (300) includes a physical storage server (310) and a distributed storage server (320).
9. The multi-tenant data encryption device based on the Redfish protocol according to claim 8, wherein the authentication and access control module (110) restricts user permissions through role-based access control (RBAC) and OAuth 2.0, ensures API access security through JWT token management, and protects user account security through multi-factor authentication (MFA); the security monitoring and anomaly detection module (120) records the storage status based on Redfish event subscription, monitors the access pattern through AI, detects abnormal behavior, and ensures storage and access security; the storage management module (210) divides the storage pool through logical volume management (LVM), performs dynamic storage allocation through the storage pool (StoragePool), and ensures data redundancy through RAID-5 / RAID-10, ensuring physical and logical isolation of each tenant's data at the storage level to prevent data leakage or access conflicts; the data encryption and key management module (220) protects the stored data through AES-256 symmetric encryption, protects the security of key transmission through RSA-4096 asymmetric encryption, and performs key management through a key management system (KMS); the automatic security response module (230) automatically takes security measures when a security threat is detected; The system operation and maintenance module (240) continuously optimizes security policies, performs regular key rotation, log analysis, and access control optimization to ensure the long-term security and stability of the system.
10. A computer-readable storage medium having program instructions stored thereon, characterized in that, When the program instructions are executed by a processor, the method according to any one of claims 1 to 7 is implemented.
Citation Information
Patent Citations
Power grid service information management security authentication method and system, and computer storage medium
CN117951665A
Systems and methods with integrated gaming engines and smart contracts
US20230173395A1