Data encryption method and system based on cloud computing

Through cloud computing-based data encryption method, layered encryption is carried out in combination with user behavior and data characteristics, the problem of high efficiency and low resource consumption in the existing technology is solved, and efficient data security management is achieved.

CN120296764AInactive Publication Date: 2025-07-11YANCHENG INST OF IND TECH
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202510353485.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-25
Publication Date
2025-07-11
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

The existing cloud computing data encryption methods consume huge computing resources when the amount of data increases, resulting in inefficient management and ineffective response to data security needs in multi-tenant environments.

Method used

By obtaining user access logs and interest collections, user behavior analysis, popularity analysis and interest analysis are carried out, data comprehensive scores are calculated, and layered encryption is implemented according to the score threshold, including three strategies: advanced, intermediate and no encryption, to optimize resource utilization.

Benefits of technology

Improve data encryption management efficiency, rational allocation of computing resources, ensure the security of high-value data, and avoid unnecessary encryption processing, improving system performance.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120296764A_ABST
    Figure CN120296764A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of big data management, and discloses a data encryption method and system based on cloud computing, and the method comprises the steps: obtaining a user access log and a user interest set; performing user behavior analysis according to the user access log to obtain user access frequency and data sensitivity; performing popularity analysis according to the user access frequency and the user access log to obtain data access popularity; performing interest analysis according to the user interest set and the data access popularity to obtain data interestingness; performing comprehensive evaluation according to the user access frequency, the data access popularity, the data sensitivity and the data interestingness to obtain a data comprehensive score; and encrypting the data according to the data comprehensive score and a preset score threshold. The method has the following effect that the management efficiency of data encryption can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of data management, and in particular to a data encryption method and system based on cloud computing. Background Art

[0002] With the popularity of cloud computing services, enterprises and individual users are increasingly relying on cloud storage to save and manage their data. However, data privacy and security issues have also become the focus of attention. Especially in a multi-tenant environment, how to ensure the security of data in transmission and at rest has become particularly important. Data security occupies a core position, because once the data is attacked in the cloud environment, it will not only lead to damage to business continuity, but also cause technological progress to stagnate. Especially in today's frequent data leakage incidents, how to effectively protect data in the cloud has become a key issue that needs to be solved in various industries. In order to solve these problems, some advanced solutions have begun to explore more efficient encryption algorithms and technologies, such as the application of cutting-edge technologies such as homomorphic encryption and zero-knowledge proof, so as to provide stronger security without affecting data availability. At the same time, optimizing the key management process and using automated tools and technologies to simplify the key generation, distribution and revocation process are also important directions to improve overall data security and management efficiency.

[0003] One existing technology uses a multi-level data encryption strategy to enhance data security. First, during the data transmission stage, the communication link is encrypted using the SSL / TLS protocol to ensure that the data will not be eavesdropped or tampered with when transmitted over the network. Secondly, during the data storage stage, a strong encryption algorithm, such as AES-256, is implemented on static data to ensure that even if the data storage medium is stolen, unauthorized parties cannot easily interpret the information therein. In addition, a key management service (KMS) is introduced to further strengthen the security protection capabilities of data by centrally managing and distributing encryption keys. These measures work together to form a complete data security protection system designed to minimize potential risks and improve the overall security of data.

[0004] Although the above methods have improved the security of data to a certain extent, they still have some shortcomings. With the continuous growth of data volume, the existing encryption process is relatively time-consuming and consumes a lot of computing resources, resulting in low management efficiency of data encryption. Summary of the invention

[0005] The present invention provides a data encryption method and system based on cloud computing, so as to improve the management efficiency of data encryption.

[0006] In a first aspect, in order to solve the above technical problems, the present invention provides a data encryption method based on cloud computing, comprising:

[0007] Obtain the user access logs and the user interest set;

[0008] Conduct user behavior analysis based on the user access logs to obtain the user access frequency and data sensitivity;

[0009] Conduct heat analysis based on the user access frequency and the user access logs to obtain the data access heat;

[0010] Conduct interest analysis based on the user interest set and the data access heat to obtain the data interest degree;

[0011] Conduct comprehensive evaluation based on the user access frequency, the data access heat, the data sensitivity, and the data interest degree to obtain the data comprehensive score;

[0012] Encrypt the data according to the data comprehensive score and a preset score threshold.

[0013] In an alternative embodiment, the conducting user behavior analysis based on the user access logs to obtain the user access frequency and data sensitivity includes:

[0014] Calculate the user access frequency through the following formula:

[0015]

[0016] where, F d represents the user access frequency, nt represents the total number of access timestamps, ti represents the access timestamp number, α represents the decay coefficient, t current represents the current timestamp, and T ti represents the ti-th access timestamp;

[0017] Calculate the data sensitivity through the following formula:

[0018] S d = w type · C type + w source · C source + w op · C operation

[0019] where, S d represents the data sensitivity, w type represents the data type weight, C type represents the data type score, w source represents the data source weight, C source represents the data source score, w op represents the data operation weight, and C operation represents the data operation score.

[0020] In an alternative embodiment, before performing heat analysis based on the user access frequency and the user access log to obtain the data access heat, the following steps are further included:

[0021] When the user access frequency is higher than a preset frequency threshold, subsequent steps are performed;

[0022] When the user access frequency is lower than the frequency threshold, subsequent steps are skipped, and the data encryption step is also skipped.

[0023] In an alternative embodiment, performing heat analysis based on the user access frequency and the user access log to obtain the data access heat includes:

[0024] Obtaining the recent access timestamps and the number of independent users within a preset time window;

[0025] Calculating the data access heat through the following formula:

[0026]

[0027] where H d represents the data access heat, i represents the access timestamp number within the time window, T current represents the current timestamp, β represents the heat coefficient, T i represents the i-th access timestamp within the time window, n represents the number of recent accesses, and N user represents the number of independent users within the time window.

[0028] In an alternative embodiment, performing interest analysis based on the user interest set and the data access heat to obtain the data interest degree includes:

[0029] Extracting interest tags and tag weights from the user interest set;

[0030] Calculating the interest matching degree through the following formula:

[0031]

[0032] where M interest represents the interest matching degree, k represents the total number of data, j represents the data number, T j represents the data tag, represents the binary correlation degree, represents the tag weight;

[0033] Calculating the data interest degree based on the interest matching degree and the data access heat through the following formula:

[0034] I d = M interest×H d

[0035] Among them, I d represents the data interest degree, M interest represents the interest matching degree, H d represents the data access heat.

[0036] In an alternative embodiment, a comprehensive evaluation is performed according to the user access frequency, the data access heat, the data sensitivity, and the data interest degree to obtain a data comprehensive score, including:

[0037] The data comprehensive score is calculated by the following formula:

[0038] Score = k1I d + k2H d + k3F d + k4S d

[0039] Among them, Score represents the data comprehensive score, I d represents the data interest degree, H d represents the data access heat, F d represents the user access frequency, S d represents the data sensitivity, and k1, k2, k3, and k4 represent score weight coefficients.

[0040] In an alternative embodiment, encrypting the data according to the data comprehensive score and a preset score threshold includes:

[0041] When the data comprehensive score is higher than a preset first threshold, perform high-level encryption on the data;

[0042] When the data comprehensive score is lower than the first threshold and higher than a preset second threshold, perform medium-level encryption on the data;

[0043] When the data comprehensive score is lower than the second threshold, skip the data encryption step.

[0044] In a second aspect, the present invention provides a data encryption system based on cloud computing, including:

[0045] A data acquisition module, configured to acquire user access logs and user interest sets;

[0046] A user analysis module, configured to perform user behavior analysis according to the user access logs to obtain the user access frequency and data sensitivity;

[0047] A heat analysis module, configured to perform heat analysis according to the user access frequency and the user access logs to obtain the data access heat;

[0048] An interest analysis module, configured to perform interest analysis based on the user interest set and the data access popularity to obtain data interest degrees;

[0049] A comprehensive score module, configured to perform a comprehensive evaluation based on the user access frequency, the data access popularity, the data sensitivity, and the data interest degrees to obtain a data comprehensive score;

[0050] A data encryption module, configured to encrypt data according to the data comprehensive score and a preset score threshold.

[0051] In a third aspect, the present invention further provides an electronic device, including a processor, a memory, and a computer program stored in the memory and configured to be executed by the processor. When the processor executes the computer program, the above-mentioned data encryption method based on cloud computing according to any one of the above is implemented.

[0052] In a fourth aspect, the present invention further provides a computer-readable storage medium, which includes a stored computer program. When the computer program runs, it controls the device where the computer-readable storage medium is located to execute the above-mentioned data encryption method based on cloud computing according to any one of the above.

[0053] Compared with the prior art, the present invention has the following beneficial effects:

[0054] (1) The present invention relates to the technical field of big data management, and discloses a data encryption method and system based on cloud computing, which can improve the management efficiency of data encryption; the method for calculating the user access frequency takes into account all access timestamps, and distinguishes the roles of new and old access records by adjusting the influence of each access event on the final access frequency. This method emphasizes that recent accesses have a higher weight than older accesses, so as to better reflect the user's recent behavior patterns and help to more accurately analyze the user's real-time activity situation.

[0055] (2) For the evaluation of data sensitivity, the present invention evaluates the sensitivity of data from three dimensions: data type, data source, and data operation. This method allows different degrees of attention to be given to different types of data, different data sources, and their processing methods, so as to achieve a detailed classification of data sensitivity. Such an evaluation mechanism can identify which data requires more stringent encryption measures or access controls. This method can better adapt to the characteristics of data mobility and user behavior diversity in the cloud computing environment, and improve the overall security and response speed of the system.

[0056] (3) The interest analysis of the user interest set and data access popularity in the present invention aims to obtain the data interest degree. This process first extracts interest tags and their corresponding tag weights from the user interest set. Then, the interest matching degree is calculated, which is obtained by accumulating the products of the tag weights of all data and their corresponding binary association degrees. The interest matching degree here reflects the correlation strength between the user's interest and specific data. Finally, the data interest degree is calculated by multiplying the interest matching degree by the data access popularity. This step integrates the user's interest degree in different data and the frequency or popularity of access to these data. This calculation method enables the final data interest degree to not only reflect the user's personal preferences but also take into account the actual usage of the data. Compared with the method relying on a single factor, this method has significant improvements in both accuracy and practicality.

[0057] (4) In the present invention, the calculation of the data comprehensive score is the result of a comprehensive evaluation based on the user access frequency, data access popularity, data sensitivity, and data interest degree. Specifically, this goal is achieved through a weighted summation formula. It can comprehensively consider multiple dimensions affecting data security, not only paying attention to the sensitivity of the data itself but also taking into account the user's usage habits (such as access frequency) and preferences (such as data interest degree), as well as the popularity of data access. This multi-dimensional consideration makes the encryption strategy more reasonable and accurate.

[0058] (5) In the present invention, different encryption measures are taken for data according to the relationship between the data comprehensive score and the preset score threshold. When the data comprehensive score is higher than the first threshold, it means that these data have high importance and sensitivity, so the Advanced Encryption Standard is used for protection; if the score is between the first and second thresholds, it is considered that the importance of the data is secondary, and medium-level encryption is selected to balance security and efficiency; when the score is lower than the second threshold, it indicates that the security requirements of the data are relatively low or insensitive, and at this time, the encryption step can be skipped, thereby optimizing resource utilization and improving system efficiency. Such a hierarchical encryption strategy not only ensures the security of high-value data but also avoids unnecessary encryption processing, improving the overall system performance and the management efficiency of big data encryption. BRIEF DESCRIPTION OF THE DRAWINGS

[0059] Figure 1 is a schematic flowchart of a data encryption method based on cloud computing provided by the first embodiment of the present invention;

[0060] Figure 2 is a schematic structural diagram of a data encryption system based on cloud computing provided by the second embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0061] The following will be combined with the drawings in the embodiments of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.

[0062] With the popularity of cloud computing services, enterprises and individual users are increasingly relying on cloud storage to save and manage their data. However, data privacy and security issues have also become the focus of attention. Especially in a multi-tenant environment, how to ensure the security of data in transmission and at rest has become particularly important. Data security occupies a core position, because once the data is attacked in the cloud environment, it will not only lead to damage to business continuity, but also cause technological progress to stagnate. Especially in today's frequent data leakage incidents, how to effectively protect data in the cloud has become a key issue that needs to be solved in various industries. In order to solve these problems, some advanced solutions have begun to explore more efficient encryption algorithms and technologies, such as the application of cutting-edge technologies such as homomorphic encryption and zero-knowledge proof, so as to provide stronger security without affecting data availability. At the same time, optimizing the key management process and using automated tools and technologies to simplify the key generation, distribution and revocation process are also important directions to improve overall data security and management efficiency.

[0063] One existing technology uses a multi-level data encryption strategy to enhance data security. First, during the data transmission stage, the communication link is encrypted using the SSL / TLS protocol to ensure that the data will not be eavesdropped or tampered with when transmitted over the network. Secondly, during the data storage stage, a strong encryption algorithm, such as AES-256, is implemented on static data to ensure that even if the data storage medium is stolen, unauthorized parties cannot easily interpret the information therein. In addition, a key management service (KMS) is introduced to further strengthen the security protection capabilities of data by centrally managing and distributing encryption keys. These measures work together to form a complete data security protection system designed to minimize potential risks and improve the overall security of data.

[0064] Although the above methods have improved the security of data to a certain extent, they still have some shortcomings. With the continuous growth of data volume, the existing encryption process is relatively time-consuming and consumes a lot of computing resources, resulting in low management efficiency of data encryption.

[0065] To solve the above problems, refer to Figure 1 The first embodiment of the present invention provides a data encryption method based on cloud computing, comprising the following steps:

[0066] S11, Obtain the user access log and the user interest set;

[0067] S12, Conduct user behavior analysis based on the user access log to obtain the user access frequency and data sensitivity;

[0068] S13, Conduct heat analysis based on the user access frequency and the user access log to obtain the data access heat;

[0069] S14, Conduct interest analysis based on the user interest set and the data access heat to obtain the data interest degree;

[0070] S15, Conduct comprehensive evaluation based on the user access frequency, the data access heat, the data sensitivity and the data interest degree to obtain the data comprehensive score;

[0071] S16, Encrypt the data according to the data comprehensive score and the preset score threshold.

[0072] In step S11, obtain the user access log and the user interest set.

[0073] In one implementation, the user access log can automatically collect the user's activity data through a log recording system deployed on the cloud server. Whenever the user interacts with the system (such as logging in, querying data, downloading files, etc.), these behaviors will be recorded as part of the access log. The log is stored in a dedicated log server or database. The user interest set is obtained by means such as the interest tags set by the user himself.

[0074] It should be noted that the user access log contains the user's identity identifier (such as user ID), access timestamp, accessed resource identifier (such as file name or database table name), executed operation type (such as read, write) and other relevant information (such as IP address). For example, an entry is "User 001 accessed the database table 'Customer Information' at 14:57 on January 30, 2025 for a query operation". The user interest set is a set reflecting the user's preferences, including but not limited to the domain tags the user is interested in (such as technology, sports), specific product categories (such as electronic products, books), or more fine-grained interest points (such as artificial intelligence, football games). For example, "The interest set of User 001 is [artificial intelligence, big data analysis, technology news]".

[0075] In step S12, conduct user behavior analysis based on the user access log to obtain the user access frequency and data sensitivity.

[0076] In one implementation, the user access frequency is calculated by the following formula:

[0077]

[0078] Among them, F d represents the user access frequency, nt represents the total number of access timestamps, ti represents the access timestamp number, α represents the decay coefficient, and T current represents the current timestamp, and T ti represents the ti-th access timestamp;

[0079] The data sensitivity is calculated through the following formula:

[0080] S d = w type ·C type + w source ·C source + w op ·C operation

[0081] Among them, S d represents the data sensitivity, w type represents the data type weight, C type represents the data type score, w source represents the data source weight, and C source represents the data source score, w op represents the data operation weight, and C operation represents the data operation score.

[0082] It should be noted that calculating the user access frequency is to understand the frequency of interaction between the user and specific data, which helps to identify which data is more important or commonly used by the user, so as to provide a basis for subsequent data encryption strategies.

[0083] In one implementation, the decay coefficient is set to 0.1, which is used to adjust the influence degree of access at different time points on the final access frequency. Newer access records will have higher weights. The timestamp is in days. For example, 7 days ago, 12 days ago.

[0084] It should be noted that evaluating the data sensitivity is to determine the importance or confidentiality level of the data, so as to decide what level of encryption measures to take. The data type score is set in advance according to the type of data. For example, customer personal information is highly sensitive data and is rated the highest score of 10 points; ordinary product information is public or does not involve confidential content, and even if it is leaked, it will not cause much impact. Therefore, its risk score is relatively low and can be set to 2 or 3 points.

[0085] It should be noted that a risk scoring standard is also set for each data source, also using a scale of 1 to 10, where 1 represents the lowest risk and 10 represents the highest risk. The scoring basis includes but is not limited to the reliability of the data source, whether it is vulnerable to attacks, and whether there is a perfect verification mechanism, etc. Taking an online retailer as an example, if they want to upgrade their inventory management system, they need to integrate data from multiple different sources. For the inventory information of goods obtained from the internal system, since it comes from a controlled environment, a relatively low data source score (set to 2) is given. For the product reviews and feedback collected from social media platforms, since this information comes from the open network and is unverified, a relatively high data source score (set to 8) is given, which means that these data need to be processed more carefully to ensure that decision-making errors or other security issues will not occur due to the use of unreliable information.

[0086] It should be noted that a risk scoring standard is set for each data operation, using a scale of 1 to 10, where 1 represents the lowest risk and 10 represents the highest risk. The scoring basis includes but is not limited to whether the operation changes the state of the data, whether it will cause data leakage, and whether there is strict access control, etc. The risk of only reading data without making any modifications is relatively small. Therefore, this type of operation gets a relatively low risk score, such as 3 points. If the deletion operation is abused, it will cause data loss and is difficult to recover, especially when there is no proper backup mechanism. Therefore, the risk score of this type of operation is relatively high and can be set to 7 points.

[0087] In step S13, heat analysis is performed based on the user access frequency and the user access log to obtain the data access heat.

[0088] In one implementation, before performing the heat analysis based on the user access frequency and the user access log to obtain the data access heat, it further includes: when the user access frequency is higher than a preset frequency threshold, perform the subsequent steps; when the user access frequency is lower than the frequency threshold, skip the subsequent steps and skip the data encryption step.

[0089] In one implementation, obtain the recent access timestamps and the number of independent users within a preset time window;

[0090] Calculate the data access heat through the following formula:

[0091]

[0092] where H d represents the data access heat, i represents the access timestamp number within the time window, T current represents the current timestamp, β represents the heat coefficient, T irepresents the i-th access timestamp within the time window, n represents the number of recent accesses, and N user represents the number of unique users within the time window.

[0093] It should be noted that the time window is a preset time period, and all relevant activities (such as the number of accesses, the number of unique users, etc.) within this time period will be incorporated into the heat calculation. The time window can be a few minutes, a few hours, a few days, or even longer, depending on the requirements of the application scenario. For example: for the data of an educational platform, the time window can be set to 7 days, which means only considering all the access records of students to various course materials in the past week.

[0094] It should be noted that the purpose of performing heat analysis is to evaluate the activity or popularity of specific data being accessed. The first half of this formula is a weighted sum of all access events over a period of time, where more recent access records have higher weights; the second half amplifies the impact of the number of unique users on the total heat through a logarithmic function, emphasizing the importance of multiple different users accessing the same data.

[0095] It should be noted that before performing heat analysis, first check whether the user's access frequency exceeds a preset frequency threshold. If the access frequency is low, skip the subsequent heat analysis steps and do not perform encryption operations on the relevant data. The purpose is to reduce unnecessary computational burdens, focus on the data that truly needs attention, and improve the overall system efficiency and response speed. Only when the access frequency exceeds the threshold, further analyze its heat and then decide whether to encrypt and what level of encryption measures to adopt.

[0096] In step S14, perform interest analysis based on the user interest set and the data access heat to obtain the data interest degree.

[0097] In one implementation, extract interest tags and tag weights from the user interest set;

[0098] Calculate the interest matching degree through the following formula:

[0099]

[0100] where M interest represents the interest matching degree, k represents the total number of data, j represents the data number, and T j represents the data tag, represents the binary association degree, represents the tag weight;

[0101] Calculate the data interest degree based on the interest matching degree and the data access heat through the following formula:

[0102] I d = M interest × H d

[0103] Wherein, I d represents the data interest degree, M interest represents the interest matching degree, and H d represents the data access heat.

[0104] It should be noted that the value of the binary correlation degree is 0 or 1. For a piece of data that contains tags of interest to the user, its correlation degree is 1; otherwise, it is 0. For example: The user marked that he is interested in "programming", especially "Python programming", and he is also interested in "data analysis" to a certain extent, and weights are set respectively. Among them, the tag weight of "Python programming" is set to 0.8, and the weight of "data analysis" is 0.6. For a specific data item, such as an article about "Python programming basics", its tags will include "Python programming", so the binary correlation degree for this tag is 1, while the binary correlation degree for the "pet" tag is 0.

[0105] In step S15, a comprehensive evaluation is performed according to the user access frequency, the data access heat, the data sensitivity, and the data interest degree to obtain a data comprehensive score.

[0106] In one implementation, the data comprehensive score is calculated through the following formula:

[0107] Score = k1I d + k2H d + k3F d + k4S d

[0108] Wherein, Score represents the data comprehensive score, I d represents the data interest degree, H d represents the data access heat, F d represents the user access frequency, S d represents the data sensitivity, and k1, k2, k3, and k4 represent score weight coefficients.

[0109] It should be noted that the final comprehensive data score is used to measure the overall security requirement level of the data. Data interest reflects the interest level of a specific user group in this data; data access heat measures the activity level of data being accessed; user access frequency indicates the frequency of interaction between a specific user and this data; data sensitivity evaluates the importance and confidentiality requirements of the information carried by the data itself. For example, calculate the comprehensive score for a report on the latest market trend analysis to decide whether to encrypt it: The interest matching degree of this report is very high because many employees have shown a high degree of concern for market trends, and the calculated interest degree is 9; since many employees have viewed this report recently and multiple different users have accessed it, the access heat is 8; for the main team members who wrote this report, they often consult this document, and the average number of accesses per person per month reaches 10 times, so the user access frequency is 7; considering that this report contains some content about the company's future strategic direction but does not involve specific financial or personal privacy information, its sensitivity is set to a medium level, that is, the sensitivity is 6. Set the weight coefficient of all items to 1, and the calculated comprehensive score is 30. Set the first threshold to 25 points and the second threshold to 15 points. Adopt advanced encryption.

[0110] In step S16, encrypt the data according to the data comprehensive score and the preset score threshold.

[0111] In one implementation, when the data comprehensive score is higher than the preset first threshold, perform advanced encryption on the data;

[0112] When the data comprehensive score is lower than the first threshold and higher than the preset second threshold, perform intermediate encryption on the data;

[0113] When the data comprehensive score is lower than the second threshold, skip the encryption step of the data.

[0114] In one implementation, advanced encryption uses the AES - 256 (Advanced Encryption Standard) encryption method, with a key length of 256 bits, which means there are 2^256 cases of key combinations. This huge key space makes brute - force attack impossible because even for the most advanced supercomputer, it is infeasible to try all cases of key combinations. At the same time, perform 14 rounds of encryption operations, and each round includes steps such as byte substitution, row shift, column mixing, and round key addition.

[0115] In one implementation, the specific steps of the AES-256 encryption process include: First, the original 256-bit key generates a series of sub-keys through a key expansion process, and these sub-keys will be used for subsequent round key addition operations. This process is called key scheduling. Round key addition: The input data (in 128-bit blocks) is XORed with the expanded key of the first round. This is the only operation that is not performed in each round, and a specific round key will be applied in each subsequent round. Then, 14 rounds of the main loop include: Sub Bytes (byte substitution): In this step, each byte is replaced with its corresponding value according to a fixed S-box (lookup table). This step provides a non-linear transformation and enhances the security of the cipher. Shift Rows (row shift): Each row in the matrix is circularly shifted by a different offset. For example, the second row is shifted left by one position, the third row is shifted left by two positions, and the fourth row is shifted left by three positions. This step ensures the diffusion effect on the columns. MixColumns (column mixing): This step involves matrix multiplication, where each column is regarded as a polynomial and multiplied by a fixed polynomial. This process increases the mutual dependence between bytes and further strengthens the encryption intensity. Arounder (round key addition): At the end of each round, the current state is XORed with the sub-key of that round. This step is the only part that involves the key and is the core of each round of encryption. After 14 rounds of the loop, compared with the previous rounds, the final round does not include the Mix Columns step and only performs the three steps of Sub Bytes, Shift Rows, and Arounder. This is because Mix Columns is mainly used to increase the complexity between multiple rounds and is no longer needed in the last round.

[0116] In one implementation, medium-level encryption uses the AES-128 (Advanced Encryption Standard) encryption method with a key length of 128 bits, which means there are 2^128 possible key combinations. At the same time, 10 rounds of encryption operations are performed, and each round includes steps such as byte substitution, row shift, column mixing, and round key addition. Since AES-128 uses a shorter key and fewer rounds, its encryption and decryption speeds are faster than AES-256. Especially in resource-constrained environments (such as mobile devices or embedded systems), AES-128 can provide better performance.

[0117] In summary, the present invention discloses a data encryption method based on cloud computing, which aims to improve the efficiency of data encryption management. Specifically, the method extracts information from user access logs to perform user behavior analysis, thereby obtaining the user's access frequency and the sensitivity of the data. The calculation of user access frequency not only takes into account all access timestamps, but also introduces a decay coefficient to distinguish the role of new and old access records, emphasizing that recent access has a higher weight than long-term access, so as to better reflect the user's recent behavior pattern. The assessment of data sensitivity is carried out from three dimensions: data type, source, and operation. This method allows different levels of attention to be given to different types of data, which helps to identify which data requires more stringent encryption measures or access control.

[0118] Furthermore, a heat analysis is performed based on the user access frequency and user access log to obtain the data access heat. This process first obtains the recent access timestamp and the number of independent users within the preset time window, and then uses a specific formula to calculate the data access heat, which takes into account both the time factor of the access and the impact of the number of independent users on the data activity. In addition, the data interest is calculated through interest analysis of the user interest set and the data access heat. This step first extracts the interest tags and their corresponding tag weights from the user interest set, then calculates the interest matching, and finally combines the interest matching with the data access heat to calculate the data interest, so that the final result not only reflects the user preference, but also takes into account the actual use of the data.

[0119] Based on the above indicators (including user access frequency, data access popularity, data sensitivity and data interest), this method conducts a comprehensive evaluation and obtains a comprehensive data score. According to different intervals of the data comprehensive score, different levels of encryption strategies are adopted: when the data comprehensive score is higher than the first threshold, the data is encrypted at a high level; data between the first and second thresholds is encrypted at a medium level; data below the second threshold is not encrypted. Such a layered encryption strategy not only ensures the security of high-value data, but also avoids unnecessary encryption processing, thereby improving the performance of the overall system.

[0120] In summary, the data encryption method proposed in the present invention not only enhances the effectiveness of traditional data encryption methods, but also pays attention to the sensitivity of the data itself, takes into account the user's usage habits and preferences, and takes into account the actual access frequency and popularity of the data, making the encryption strategy more reasonable and accurate, thereby improving the overall efficiency of data security management.

[0121] Reference Figure 2 The second embodiment of the present invention provides a data encryption system based on cloud computing, including:

[0122] A data acquisition module for acquiring user access logs and user interest sets;

[0123] A user analysis module for performing user behavior analysis based on the user access logs to obtain user access frequency and data sensitivity;

[0124] A heat analysis module for performing heat analysis based on the user access frequency and the user access logs to obtain data access heat;

[0125] An interest analysis module for performing interest analysis based on the user interest set and the data access heat to obtain data interest degree;

[0126] A comprehensive score module for performing a comprehensive evaluation based on the user access frequency, the data access heat, the data sensitivity, and the data interest degree to obtain a data comprehensive score;

[0127] A data encryption module for encrypting data according to the data comprehensive score and a preset score threshold.

[0128] Preferably, the data acquisition module is used to:

[0129] Acquire user access logs and user interest sets.

[0130] Preferably, the user analysis module is used to:

[0131] Perform user behavior analysis based on the user access logs to obtain user access frequency and data sensitivity, including:

[0132] Calculate the user access frequency through the following formula:

[0133]

[0134] where F d represents the user access frequency, nt represents the total number of access timestamps, ti represents the access timestamp number, α represents the decay coefficient, T current represents the current timestamp, and T ti represents the ti-th access timestamp;

[0135] Calculate the data sensitivity through the following formula:

[0136] S d = w type ·C type + w source ·C source + w op ·C operation

[0137] where S dRepresents data sensitivity, w type Represents the weight of data type, C type Represents the score of data type, w source Represents the weight of data source, C source Represents the score of data source, w op Represents the weight of data operation, C operation Represents the score of data operation.

[0138] Preferably, the popularity analysis module is used for:

[0139] Performing popularity analysis based on the user access frequency and the user access log to obtain data access popularity, including:

[0140] Obtaining the recent access timestamps and the number of independent users within a preset time window;

[0141] Calculating the data access popularity through the following formula:

[0142]

[0143] where H d represents the data access popularity, i represents the access timestamp number within the time window, T current represents the current timestamp, β represents the popularity coefficient, T i represents the i-th access timestamp within the time window, n represents the recent number of accesses, N user represents the number of independent users within the time window.

[0144] Preferably, before performing the popularity analysis based on the user access frequency and the user access log to obtain the data access popularity, it further includes:

[0145] When the user access frequency is higher than a preset frequency threshold, perform the subsequent steps;

[0146] When the user access frequency is lower than the frequency threshold, skip the subsequent steps and skip the data encryption step.

[0147] Preferably, the interest analysis module is used for:

[0148] Performing interest analysis based on the user interest set and the data access popularity to obtain data interest degree, including:

[0149] Extracting interest tags and tag weights from the user interest set;

[0150] Calculating the interest matching degree through the following formula:

[0151]

[0152] Among them, M interest represents the interest matching degree, k represents the total number of data, j represents the data number, and T j represents the data label, represents the binary correlation degree, represents the label weight;

[0153] Calculate the data interest degree according to the interest matching degree and the data access popularity through the following formula:

[0154] I d = M interest ×H d

[0155] Among them, I d represents the data interest degree, M interest represents the interest matching degree, and H d represents the data access popularity.

[0156] Preferably, the comprehensive score module is used for:

[0157] Conduct a comprehensive evaluation according to the user access frequency, the data access popularity, the data sensitivity, and the data interest degree to obtain the data comprehensive score, including:

[0158] Calculate the data comprehensive score through the following formula:

[0159] Score = k1I d + k2H d + k3F d + k4S d

[0160] Among them, Score represents the data comprehensive score, I d represents the data interest degree, H d represents the data access popularity, F d represents the user access frequency, S d represents the data sensitivity, and k1, k2, k3, k4 represent the score weight coefficients.

[0161] Preferably, the data encryption module is used for:

[0162] Encrypt the data according to the data comprehensive score and a preset score threshold, including:

[0163] When the data comprehensive score is higher than the preset first threshold, perform high-level encryption on the data;

[0164] When the data comprehensive score is lower than the first threshold and higher than the preset second threshold, perform intermediate-level encryption on the data;

[0165] When the comprehensive data score is lower than the second threshold, skip the data encryption step.

[0166] It should be noted that a data encryption system based on cloud computing provided in an embodiment of the present invention is used to execute all the process steps of a data encryption method based on cloud computing in the above embodiment. The working principles and beneficial effects of the two correspond one by one, so they will not be elaborated here.

[0167] An embodiment of the present invention also provides an electronic device. The electronic device includes: a processor, a memory, and a computer program stored in the memory and executable on the processor, such as a data acquisition program. When the processor executes the computer program, the steps in the above various embodiments of the data encryption method based on cloud computing are implemented, such as Figure 1 the step S11 shown. Alternatively, when the processor executes the computer program, the functions of each module / unit in the above device embodiments are implemented, such as the data acquisition module.

[0168] Exemplarily, the computer program can be divided into one or more modules / units. The one or more modules / units are stored in the memory and executed by the processor to complete the present invention. The one or more modules / units can be a series of computer program instruction segments capable of performing specific functions, and these instruction segments are used to describe the execution process of the computer program in the electronic device.

[0169] The electronic device can be a computing device such as a desktop computer, a notebook, a palm computer, and a smart tablet. The electronic device may include, but is not limited to, a processor and a memory. Those skilled in the art can understand that the above components are only examples of the electronic device and do not constitute a limitation on the electronic device. It may include more or fewer components than the above, or combine some components, or different components. For example, the electronic device may further include input / output devices, network access devices, a bus, etc.

[0170] The so-called processor may be a Central Processing Unit (CPU), or it may also be other general-purpose processors, Digital Signal Processors (DSPs), Application Specific Integrated Circuits (ASICs), Field-Programmable Gate Arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor or the processor may also be any conventional processor, etc. The processor is the control center of the electronic device and connects all parts of the electronic device using various interfaces and lines.

[0171] The memory can be used to store the computer programs and / or modules. The processor realizes various functions of the electronic device by running or executing the computer programs and / or modules stored in the memory, and by invoking the data stored in the memory. The memory mainly includes a program storage area and a data storage area. Among them, the program storage area can store an operating system, application programs required for at least one function (such as a sound playback function, an image playback function, etc.); the data storage area can store data created according to the use of the mobile phone (such as audio data, phone book, etc.). In addition, the memory can include high-speed random access memory, and can also include non-volatile memory, such as a hard disk, memory, plug-in hard disk, Smart Media Card (SMC), Secure Digital (SD) card, Flash Card, at least one magnetic disk storage device, flash device, or other volatile solid-state storage devices.

[0172] Among them, if the modules / units integrated in the electronic device are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on such an understanding, to implement all or part of the processes in the above-described embodiment methods of the present invention, it can also be completed by a computer program instructing relevant hardware. The computer program can be stored in a computer-readable storage medium. When the computer program is executed by a processor, the steps of the above-described various method embodiments can be implemented. Among them, the computer program includes computer program code, and the computer program code can be in the form of source code, object code, executable file, or some intermediate form, etc. The computer-readable medium can include: any entity or device capable of carrying the computer program code, recording medium, USB flash drive, mobile hard disk, magnetic disk, optical disc, computer memory, read-only memory (ROM), random access memory (RAM), electrical carrier signal, telecommunication signal, and software distribution medium, etc. It should be noted that the content included in the computer-readable medium can be appropriately increased or decreased according to the requirements of legislation and patent practice in the jurisdiction. For example, in some jurisdictions, according to legislation and patent practice, the computer-readable medium does not include electrical carrier signals and telecommunication signals.

[0173] It should be noted that the device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed to multiple network units. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment. In addition, in the attached drawings of the device embodiments provided by the present invention, the connection relationship between the modules indicates that they have a communication connection, which can be specifically implemented as one or more communication buses or signal lines. Those of ordinary skill in the art can understand and implement it without creative work.

[0174] The specific embodiments described above further elaborate on the purpose, technical solution, and beneficial effects of the present invention. It should be understood that the above description is only the specific embodiments of the present invention and is not used to limit the protection scope of the present invention. It is particularly pointed out that for those skilled in the art, any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of the present invention shall be included in the protection scope of the present invention.

Claims

1. A data encryption method based on cloud computing, characterized in that, including: Obtain user access logs and user interest sets; Perform user behavior analysis based on the user access logs to obtain user access frequencies and data sensitivities; Perform heat analysis based on the user access frequencies and the user access logs to obtain data access heats; Perform interest analysis based on the user interest sets and the data access heats to obtain data interest degrees; Perform comprehensive evaluation based on the user access frequencies, the data access heats, the data sensitivities, and the data interest degrees to obtain data comprehensive scores; Encrypt data based on the data comprehensive scores and preset score thresholds.

2. The data encryption method based on cloud computing according to claim 1, wherein The performing user behavior analysis based on the user access logs to obtain user access frequencies and data sensitivities includes: Calculate the user access frequency through the following formula: Among them, F d represents the user access frequency, nt represents the total number of access timestamps, ti represents the access timestamp number, α represents the decay coefficient, T current represents the current timestamp, T ti represents the ti-th access timestamp; Calculate the data sensitivity through the following formula: S d = w type · C type + w source · C source + w op · C operation Among them, S d represents the data sensitivity, w type represents the data type weight, C type represents the data type score, w source represents the data source weight, C source represents the data source score, w op represents the data operation weight, C operation represents the data operation score.

3. The data encryption method based on cloud computing according to claim 1, characterized in that Before performing heat analysis based on the user access frequencies and the user access logs to obtain data access heats, it further includes: When the user access frequency is higher than a preset frequency threshold, perform subsequent steps; When the user access frequency is lower than the frequency threshold, skip subsequent steps and skip the data encryption step.

4. The data encryption method based on cloud computing according to claim 1, wherein The performing heat analysis based on the user access frequencies and the user access logs to obtain data access heats includes: Obtain recent access timestamps and the number of independent users within a preset time window; Calculate the data access heat through the following formula: Among them, H d represents the data access heat, i represents the access timestamp number within the time window, T current represents the current timestamp, β represents the heat coefficient, T i represents the i-th access timestamp within the time window, n represents the recent number of accesses, N user represents the number of independent users within the time window.

5. The data encryption method based on cloud computing according to claim 1, characterized in that, The performing interest analysis based on the user interest sets and the data access heats to obtain data interest degrees includes: Extract interest tags and tag weights from the user interest sets; Calculate the interest matching degree through the following formula: Among them, M interest represents the interest matching degree, k represents the total number of data, j represents the data number, and T j represents the data label, represents the binary correlation degree, represents the label weight; Calculate the data interest degree through the following formula based on the interest matching degree and the data access heat; I d = M interest × H d Among them, I d represents the data interest degree, M interest represents the interest matching degree, H d represents the data access heat.

6. The data encryption method based on cloud computing according to claim 1, wherein, The performing comprehensive evaluation based on the user access frequencies, the data access heats, the data sensitivities, and the data interest degrees to obtain data comprehensive scores includes: Calculate the data comprehensive score through the following formula: Score=k1I d +k2H d +k3F d +k4S d Among them, Score represents the comprehensive data score, I d represents the data interest degree, H d represents the data access heat, F d represents the user access frequency, S d represents the data sensitivity, and k1, k2, k3, k4 represent the score weight coefficients.

7. The data encryption method based on cloud computing according to claim 1, wherein The encrypting data based on the data comprehensive scores and preset score thresholds includes: When the data comprehensive score is higher than a preset first threshold, perform high-level encryption on the data; When the data comprehensive score is lower than the first threshold and higher than a preset second threshold, perform medium-level encryption on the data; When the data comprehensive score is lower than the second threshold, skip the data encryption step.

8. A data encryption system based on cloud computing, characterized in that, including: A data acquisition module for obtaining user access logs and user interest sets; A user analysis module for performing user behavior analysis based on the user access logs to obtain user access frequencies and data sensitivities; A heat analysis module for performing heat analysis based on the user access frequencies and the user access logs to obtain data access heats; An interest analysis module for performing interest analysis based on the user interest sets and the data access heats to obtain data interest degrees; A comprehensive score module for performing comprehensive evaluation based on the user access frequencies, the data access heats, the data sensitivities, and the data interest degrees to obtain data comprehensive scores; A data encryption module, configured to encrypt data according to the comprehensive data score and a preset score threshold.

9. An electronic device, characterized in that, It includes a processor, a memory, and a computer program stored in the memory and configured to be executed by the processor. When the processor executes the computer program, it implements the data encryption method based on cloud computing according to any one of claims 1 to 7.

10. A computer-readable storage medium, characterized in that, The computer-readable storage medium includes a stored computer program, wherein when the computer program runs, it controls the device where the computer-readable storage medium is located to execute the data encryption method based on cloud computing according to any one of claims 1 to 7.

Citation Information

Cited By

  • Data security processing method and system based on team cooperation sharing

    CN121173556A