Document encryption storage method
Through dynamic encryption editing and hierarchical storage management, the plain text exposure and lack of targeted encryption strategies during document editing are solved, and the security and efficiency of documents are improved in the editing, storage and access links are achieved, and the complex needs of modern information security are met.
Patent Information
- Application Number
- CN202510490746.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-18
- Publication Date
- 2025-07-11
- Estimated Expiration
- 2045-04-18
AI Technical Summary
The existing document encryption storage technology has risks of plain text exposure, lack of dynamic protection mechanisms, lack of targeted encryption policies and insufficient version management when editing, which cannot meet the complex needs of modern information security threats.
The dynamic encryption editing mechanism and hierarchical encryption storage management are adopted. By dividing logical operation units, encryption policies are generated based on sensitivity and importance. Only the current editing content is decrypted and encrypted in real time, and segmented decryption and real-time editing schemes are introduced, combining differentiated storage and multi-version management to optimize user access control and security verification.
It significantly improves document editing security, optimizes decryption performance, improves storage and transmission efficiency, and meets the compliance and traceability needs of sensitive documents.
Smart Images

Figure CN120296795A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of document encryption storage, and particularly relates to a document encryption storage method. Background Art
[0002] With the rapid development of digital information, the frequency of use and importance of documents in personal, corporate, and social affairs have been continuously increasing. Especially in scenarios involving sensitive data, such as legal contracts, financial statements, business plans, etc., document security is of particular importance. However, traditional document editing and storage technologies have obvious shortcomings in data protection and cannot effectively cope with modern information security threats.
[0003] Currently, the widely used document protection technologies mainly rely on static encryption storage and simple password verification mechanisms. Generally, when a document is saved, it is encrypted as a whole using a symmetric encryption algorithm (such as AES), and can only be decrypted and viewed after the user enters the correct password. Although these methods have a certain degree of security in the static data storage stage, there are still significant problems in actual use:
[0004] Decryption exposure risk during editing: In order to edit a document, the system must first completely decrypt the encrypted document into memory, which makes the document completely exposed in plain text during the editing process. Once the memory is intercepted by an attacker or the user's operating device is invaded, the document content will be revealed.
[0005] One-size-fits-all encryption strategy: Existing technologies usually encrypt the entire document uniformly, regardless of whether the content is sensitive. This "one-size-fits-all" approach not only wastes computing resources but also makes the encryption scheme lack pertinence, reducing the balance between security and performance.
[0006] Lack of dynamic protection mechanism: In scenarios of multi-user collaboration or hierarchical access, existing document encryption storage schemes are difficult to dynamically adjust the encryption strength and access permissions, resulting in easy leakage of sensitive content and low collaboration efficiency.
[0007] Insufficient storage and version management: Traditional document encryption technologies lack consideration for document modification and version management. After editing a document, it needs to be re-encrypted and overwrite the original file, which not only makes it inconvenient to trace historical versions but also increases the storage and transmission overhead.
[0008] In addition, with the diversification of user needs and the complexity of information security threats (such as side-channel attacks, RAM attacks), traditional encryption storage technologies are no longer able to meet the requirements of modern application scenarios. Therefore, there is an urgent need for a new technical solution that can balance the security of document dynamic editing, flexible storage strategies, and efficient access performance. The present invention is proposed under this background, aiming to comprehensively solve the above problems and provide a systematic innovative solution for the security of document editing and storage. Summary of the Invention
[0009] The object of the present invention is to design a method for encrypted storage of documents. By introducing a dynamic encryption and editing mechanism and a hierarchical encryption storage management strategy, an intelligent document editing and encrypted storage method is designed, which fundamentally improves the security and practicality of documents in the aspects of editing, storage and access.
[0010] To achieve the above object, the present invention provides a method for encrypted storage of documents, and the method includes the following steps:
[0011] S1. Obtain the document Doc, perform initialization processing on the document Doc, divide it into logical operation units, ensure that each logical operation unit contains an independent content segment, perform sensitivity classification on the basis of the logical operation units using a classification model, output the sensitivity label of the unit, the sensitivity label includes units with high sensitivity and units with low sensitivity, calculate the importance weight for the units with high sensitivity, and finally generate an encryption policy for each logical operation unit in combination with the sensitivity label and the importance weight to obtain an encryption policy table;
[0012] S2. Traverse the logical operation units, encrypt each unit according to the policy specified in the encryption policy table, generate each encrypted ciphertext, generate a unique integrity fingerprint for each encrypted ciphertext, record the unique integrity fingerprint in the verification table, and then store the ciphertext in the corresponding storage block according to the sensitivity label. The storage block includes a high-sensitivity block and a normal block, and at the same time, use a storage control table to record the allocation situation of all blocks;
[0013] S3. Design a segmented decryption and real-time editing scheme to ensure that when the user edits the document, only the current operation unit is decrypted, and it is encrypted and updated immediately and the integrity is verified after the editing is completed:
[0014] S4. Compare the new ciphertext and the original ciphertext of the logical operation unit after the user edits, extract the difference data. If the difference data is not empty, record that the unit is in a modified state and enter the storage process. When storing, record the meta-information of the difference data, including the version number, modification timestamp and storage location, write it into the difference storage control table, and then store the difference data in the corresponding block according to the sensitivity label of the logical operation unit. After each update, generate a version fingerprint for the entire document and merge it to generate a version chain. After each storage operation, generate a log and a version log, recording the difference storage and version update situations, including unit index, storage timestamp, difference size and version fingerprint;
[0015] S5. Design a user access control and security verification mechanism to ensure the access security of the document through integrity verification and access permission management, and at the same time optimize the loading efficiency of user requests;
[0016] S6. Collect logs and dynamically adjust the encryption policy and storage layout by combining access pattern analysis, content sensitivity changes, and environmental security status.
[0017] Further, decompose the document into logical units using a hierarchical parsing model, then extract the features of each logical unit, including structural features and content features, and combine them into the combined features of the unit;
[0018] Divide into granularity operation units according to the combined features of each logical unit, where each granularity operation unit contains an independent content segment.
[0019] Further, generate an encryption policy for each logical unit according to the sensitivity label and importance weight, including:
[0020] If the sensitivity label Tag i = high, that is, a unit with high sensitivity and importance weight S i > threshold Threshold, then assign the strong encryption policy AES 256 and the high-strength key Key high,i ;
[0021] If the sensitivity label Tag i = low, that is, a unit with low sensitivity, then assign the lightweight encryption policy AES 128 and the ordinary key Key low,i .
[0022] Further, during the encryption process of each unit according to the policy specified in the encryption policy table, introduce a perturbation term generated according to the content features of the unit to enhance the unpredictability of the encryption result:
[0023] Storing the ciphertext into the corresponding storage block according to the sensitivity label includes:
[0024] High-sensitivity block: Store the unit with Tag i = high;
[0025] Ordinary block: Store the unit with Tag i = low.
[0026] Further, update the status of the storage block to the storage control table Control Store , which records:
[0027] The index Index of the high-sensitivity block H = {Unit i |Tag i = high};
[0028] The index Index of the ordinary blockN = {Unit i | Tag i = low};
[0029] Dynamically adjust the physical storage locations of high - sensitive blocks and normal blocks according to the access frequency of units, ensuring that frequently accessed units are stored on devices with fast response.
[0030] Furthermore, the S3 further includes:
[0031] When receiving an edit request for a document from a user, first parse the logical operation units of the document, then query the storage locations of the logical operation units of the document through the storage control table and locate them. Generate a storage path according to the location result, pointing to the physical storage address of the ciphertext, and at the same time read its encryption algorithm and key;
[0032] Load the ciphertext and integrity fingerprint from the storage path, perform integrity verification. For the ciphertext that passes the integrity verification, use the decryption algorithm and key to decrypt it to obtain the decrypted plaintext;
[0033] Load the decrypted plaintext into the memory protection area, and at the same time design control rules for the memory protection area for real - time editing management. When the user finishes editing, generate the modified plaintext and trigger real - time encryption update;
[0034] For the modified plaintext, re - encrypt it according to the encryption algorithm and key in the encryption policy table to generate a new ciphertext and a new integrity fingerprint. Update the storage control table and the verification table according to the new ciphertext and new integrity fingerprint, and write the new ciphertext and fingerprint back to the storage block;
[0035] At the same time, during the entire editing process, monitor the access and usage conditions of the memory area in real time;
[0036] Among them, parsing the logical operation units of the document includes:
[0037] Query the storage location of the granularity operation unit Unit Store through the storage control table Control i :
[0038] If the granularity operation unit Unit i ∈ high - sensitive block H - Block, then this unit belongs to the high - sensitive block;
[0039] If the granularity operation unit Unit i ∈ normal block N - Block, then this unit belongs to the normal block;
[0040] Generate a storage path Path i from the query result, pointing to the target ciphertext Cipheri The physical storage address, and at the same time read its encryption algorithm Enc i and the key Key i ;
[0041] During integrity verification, if the integrity verification Hash Verify,i = integrity fingerprint Hash i , the verification passes, otherwise the decryption is refused and the exception is recorded;
[0042] Regarding loading the decrypted plaintext into the memory protection area, the following control rules are provided:
[0043] Unauthorized access attempts will trigger immediate locking and clear Mem Secure ;
[0044] If the user does not complete the editing within the specified time, it will be automatically re-encrypted and written back to the storage block to avoid the long-term existence of the plaintext in the memory;
[0045] When monitoring the access and usage of the memory area in real time:
[0046] If an anomaly is detected, immediately trigger locking and generate an alarm record; record the log of each editing operation, including access time, modification status, verification result, and write it to the system log Log Ops .
[0047] Furthermore, the differential data is calculated as follows:
[0048] ΔCipher i = Func Diff (Cipher i ', Cipher i ) + ξ·F cnt,i
[0049] where Func Diff (·) is a calculation function based on block-level differences; ξ is an influence coefficient for adjusting the content characteristics in differential calculation; F cnt,i is the content feature vector of the step unit, enhancing the sensitivity of differential calculation to semantic changes;
[0050] The version fingerprint V-Hash t is generated as follows:
[0051]
[0052] where H(·) is a hash function; ΔCipher i is the differential data of the modified unit; α is a weighting factor; G Tag is the global sensitivity statistic of the current version, strengthening the diversity and verifiability of the version fingerprint.
[0053] Further, according to the sensitivity tag Tag of the unit i , the differential data ΔCipher i is stored in the corresponding block:
[0054] High-sensitivity block H-Block: Stores units with Tag i = high and with differences;
[0055] Normal block N-Block: Stores units with Tag i = low and with differences;
[0056] According to the updated sensitivity tag Tag i , multiple differential versions are periodically merged into the main version Version Main ;
[0057] After the merging is completed, the differential data of the old version is archived to the read-only storage area Archive Store , releasing the space of the main storage area.
[0058] Further, the designed user access control and security verification mechanism ensures the access security of the document through integrity verification and access right management, and at the same time optimizes the loading efficiency of user requests, specifically including:
[0059] When a user initiates an access request, the request parameters Req = (User, Unit i , Version t ) are taken, including the user identity, the target unit Unit i and the target version Version t , and the user permissions are verified. If the permission verification passes, the next step is continued;
[0060] According to the request version Version t and the storage control table Control Diff , the differential data of the target granularity operation unit is located Load the differential ciphertext from H-Block or N-Block and perform integrity verification. If the verification is successful, the next step is executed;
[0061] For the ciphertext Cipher i,t that passes the integrity check, perform decryption according to the encryption algorithm Enc i and the key Key i in the storage control table;
[0062] After each access is completed, update the storage log Log Diff and the operation log Log Ops: Record the accessed unit index, version number, access timestamp, and user identity;
[0063] If an exception occurs during the access, record the exception status in the log Log Err , and trigger a system alert.
[0064] Furthermore, when the user initiates an access request, simultaneously verify through the user permission table Access Auth whether User has the permission to access the target unit Unit i :
[0065] If User is not authorized to access Unit i , reject the request and record the exception in the log Log Err ;
[0066] If the permission verification passes, continue with the next step;
[0067] When reconstructing the ciphertext Cipher of the target version according to the requested version Version t and the storage control table Control Diff , reconstruct the ciphertext Cipher of the target version through a differential merge operation i,t ; The differential merge operation iteratively accumulates differential data in chronological order;
[0068] Further verification of the integrity of the target version is required:
[0069]
[0070] If Hash Verify,t matches the record in the version chain Version Chain , the integrity check passes; if not, reject the access and record the exception;
[0071] Load the decrypted plaintext Plain i,t into the memory protection area Mem Secure , set the access window Win t , and ensure that the plaintext data in the memory is only visible within the authorized range during the user's access:
[0072] If the user exceeds the access window time or attempts an unauthorized operation, immediately clear the memory protection area Mem Secure and trigger a warning.
[0073] The beneficial technical effects of the present invention are at least as follows:
[0074] The present invention adopts dynamic granularity division and segmented decryption technology. During the document editing process, only the content being currently edited (granularity unit) is decrypted, while other content remains encrypted. After the editing is completed, the system immediately re-encrypts this unit and stores it in the encrypted block. This design significantly reduces the time window of document exposure, avoids the problem of complete decryption exposure of the entire document during the editing process, and greatly improves the security of document editing.
[0075] Aiming at the deficiencies of the "one-size-fits-all" encryption strategy, the present invention proposes a hierarchical encryption storage method based on content sensitivity. Through semantic analysis technology, the document content is automatically classified into highly sensitive and ordinary information, and different strength encryption algorithms are selected for different types of content (such as AES-256 for highly sensitive content and AES-128 for ordinary content). This hierarchical storage strategy not only improves the protection intensity of sensitive data, but also optimizes the decryption performance and reduces the system resource overhead.
[0076] To solve the deficiencies of traditional encryption technology in document modification and version management, the present invention introduces a differential storage and multi-version management mechanism. After each edit, the system only stores the encrypted content of the modified part and records it in the document version management module. Through the encryption policy table and version control mechanism, users can efficiently trace the historical versions of the document or restore the content of a specific version as needed. This mechanism not only improves the storage and transmission efficiency, but also meets the compliance and traceability requirements of sensitive documents. Brief Description of the Drawings
[0077] The present invention is further described with reference to the accompanying drawings. However, the embodiments in the drawings do not constitute any limitation to the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained according to the following drawings.
[0078] Figure 1 It is a flowchart of a document encryption storage method of the present invention. Detailed Embodiments
[0079] The embodiments of the present invention are described in detail below. The examples of the embodiments are shown in the accompanying drawings, where the same or similar reference numerals represent the same or similar elements or elements with the same or similar functions throughout. The embodiments described below with reference to the accompanying drawings are exemplary and are only used to explain the present invention and should not be construed as a limitation to the present invention.
[0080] In one or more embodiments, as Figure 1 shown, a document encryption storage method is disclosed, and the method includes the following steps:
[0081] S1. Obtain the document Doc, initialize and process the document Doc, divide it into logical operation units, ensure that each logical operation unit contains an independent content segment, perform sensitivity classification on the logical operation units using a classification model, output the sensitivity labels of the units, where the sensitivity labels include units with high sensitivity and units with low sensitivity, calculate the importance weights for the units with high sensitivity, and finally generate an encryption policy for each logical operation unit by combining the sensitivity labels and importance weights to obtain an encryption policy table.
[0082] Specifically, in this step, the document Doc is initialized and processed, divided into granularity operation units Units suitable for dynamic encryption and hierarchical storage, and a corresponding encryption policy table Policy is generated according to the content and structural characteristics of the document. Enc This step lays the foundation for the dynamic encryption storage technology of the patent and directly serves the subsequent steps of segmented encryption, real-time decryption, and version management.
[0083] Furthermore, input the document Doc, first parse it, and extract the logical structure features (such as chapters, paragraphs, pictures) and content features (such as text semantics) of the document.
[0084] Use the hierarchical parsing model Model Parse to decompose the document into logical units L i (each L i represents a structure such as a paragraph, a picture, a table, etc.).
[0085] Extract the features of each L i :
[0086] Structural feature F str,i : including the unit type (such as paragraph, picture) and its hierarchical depth (such as title level).
[0087] Content feature F cnt,i : Use the pre-trained language model embedding Model Embedding to generate a high-dimensional semantic vector of the text.
[0088] Combine F str,i and F cnt,i to form the combined feature F i ={F str,i , F cnt,i}.
[0089] Furthermore, according to the combined feature F i of each logical unit L i , divide it into granularity operation units Units={Unit1, Unit2,…, Unit n}, ensuring that each unit contains an independent content segment (such as a paragraph, a picture).
[0090] Furthermore, the granularity division follows the following rules:
[0091] Integrity: The content of each unit is indivisible, ensuring the independence and encryption integrity of the unit.
[0092] Flexibility: Different types of content are divided separately. For example, paragraphs and pictures are processed separately.
[0093] Furthermore, sensitivity classification:
[0094] For each granularity operation unit Unit i , use the classification model Model Sensitive to perform sensitivity classification on its combined feature F i and output the label Tag i , with values of high or low. The classification model is calculated as follows:
[0095]
[0096] Where:
[0097] F i : The combined feature vector of the granularity unit;
[0098] W: The weight matrix of the classifier;
[0099] b: The bias term;
[0100] σ: The activation function (such as sigmoid);
[0101] The predicted probability of unit sensitivity.
[0102] If then Tag i = high; otherwise Tag i = low.
[0103] Furthermore, for units with high sensitivity (Tag i = high), further calculate its importance weight S i , and the formula is as follows:
[0104] S i = α·L i + β·Sim key (F cnt,i )
[0105] Where:
[0106] L i : The text length of the granularity unit, measuring the amount of information in the unit;
[0107] Sim key (F cnt,i ):The semantic similarity between the unit content and the set of sensitive keywords;
[0108] α and β: Weight factors, obtained through training and optimization.
[0109] Furthermore, according to the sensitivity label Tag i and the importance weight S i , an encryption policy Enc i is generated for each unit:
[0110] If Tag i = high and S i > Threshold, then assign the strong encryption policy AES 256 and the high-strength key Key high,i .
[0111] If Tag i = low, then assign the lightweight encryption policy AES 128 and the ordinary key Key low,i .
[0112] The encryption policy table Policy Enc records the encryption algorithm, key, and storage location of each unit.
[0113] Output
[0114] The set of granularity operation units Units, where each unit is an independent content segment.
[0115] The encryption policy table Policy Enc , which guides the encryption and storage in subsequent steps.
[0116] S2. Traverse the logical operation units, encrypt each unit according to the policy specified in the encryption policy table, generate each encrypted ciphertext, generate a unique integrity fingerprint for each encrypted ciphertext, record the unique integrity fingerprint in the verification table, and then store the ciphertext in the corresponding storage block according to the sensitivity label. The storage block includes a high-sensitivity block and an ordinary block, and the storage control table is used to record the allocation of all blocks.
[0117] Specifically, this step is based on the output of step 1: the set of granularity operation units Units and the encryption policy table Policy Enc , encrypt each unit of the document, and store it in layers according to sensitivity. Through the design of innovative encryption and storage strategies, efficient segmented decryption and secure storage are achieved. The whole process focuses on reducing the exposure time of plaintext and ensuring the security and integrity of the content.
[0118] Furthermore, traverse the granularity operation units Units = {Unit1, Unit2, …, Unit n}, and for each unit Unit i encrypt it according to the policy Enc Enc specified in the encryption policy table Policy i . The innovation of the encryption process lies in introducing a specific perturbation term δ i to enhance the unpredictability of the encryption result:
[0119] Cipher i = Enc i (Plain i , Key i + δ i )
[0120] where:
[0121] Plain i is the plaintext content of the unit Unit i ;
[0122] Enc i is the encryption algorithm specified in the policy table (such as AES 256 or AES 128 );
[0123] Key i is the basic key specified in the policy table;
[0124] δ i = γ · Sim key (F cnt,i ), which is a perturbation term generated according to the characteristics of the unit content, where γ is an adjustable intensity factor, and Sim key (·) is the similarity between the unit content and the sensitive keyword.
[0125] Furthermore, generate a unique integrity fingerprint Hash i for each encrypted ciphertext Cipher i to ensure the integrity of the data during storage and access:
[0126]
[0127] where:
[0128] H(·) is a secure hash function (such as SHA-256);
[0129] denotes the bitwise exclusive OR operation, which is used to mix the ciphertext Cipher i and the meta-information Meta i ;
[0130] Meta i includes the storage sensitivity label Tag of the unit i and the encryption algorithm Enc i .
[0131] Fingerprint Hash i is recorded in the verification table Verify Enc for subsequent integrity verification.
[0132] Furthermore, according to the sensitivity label Tag of the unit i , the ciphertext Cipher i is stored in the corresponding storage block:
[0133] High-sensitivity block (H-Block): Stores units with Tag i = high;
[0134] Normal block (N-Block): Stores units with Tag i = low.
[0135] During storage, Cipher i and its integrity fingerprint Hash i are stored together to ensure the verifiability of the data.
[0136] Use a storage control table Control Store to record the allocation of blocks, including the storage location and sensitivity classification of each unit.
[0137] Furthermore, update the status of the storage block to Control Store , which records:
[0138] The index Index of the high-sensitivity block H = {Unit i | Tag i = high};
[0139] The index Index of the normal block N = {Unit i | Tag i = low}.
[0140] Optimize the storage layout: Dynamically adjust the physical storage locations of the high-sensitivity block and the normal block according to the access frequency of the unit, ensuring that frequently accessed units are stored on fast-response devices (such as SSDs).
[0141] Final output, high-sensitivity block H-Block: Contains the ciphertext and fingerprint of high-sensitivity units;
[0142] Normal Block N-Block: contains the ciphertext and fingerprint of normal units;
[0143] Storage Control Table Control Store : Records the block status and the storage location of units;
[0144] Verification Table Verify Enc : Records the integrity fingerprint of the ciphertext.
[0145] By introducing a content-related perturbation term δ in the encryption i , the unpredictability of the encryption result is further enhanced. The XOR operation of the integrity verification formula ensures the strong binding of the ciphertext and the meta-information, optimizing the storage security. The above design is optimized for the dynamic encryption scenario to ensure efficient and secure hierarchical storage.
[0146] S3. Design a segmented decryption and real-time editing scheme to ensure that when the user edits a document, only the currently operating unit is decrypted, and it is encrypted and updated immediately and the integrity is verified after the editing is completed.
[0147] Specifically, this step is based on the highly sensitive block H-Block, normal block N-Block, storage control table Control Store and verification table Verify Enc output in step 2, and design a segmented decryption and real-time editing scheme to ensure that when the user edits a document, only the currently operating unit is decrypted, and it is encrypted and updated immediately and the integrity is verified after the editing is completed.
[0148] Furthermore, when the user requests to edit a certain part of a document, the system parses the granular operating unit Unit i (such as a specific paragraph, picture).
[0149] The system queries the storage location of Unit Store through the storage control table Control i :
[0150] If Unit i ∈H-Block, then this unit belongs to the highly sensitive block;
[0151] If Unit i ∈N-Block, then this unit belongs to the normal block.
[0152] The query result generates a storage path Path i pointing to the physical storage address of the target ciphertext Cipher i , and at the same time reads its encryption algorithm Enc i and key Key i .
[0153] Further, load the ciphertext Cipher i and the integrity fingerprint Hash i from the storage path Path i , and perform integrity verification:
[0154]
[0155] Where:
[0156] H(·) is a secure hash function (such as SHA-256);
[0157] denotes bitwise exclusive OR;
[0158] Meta i includes the sensitivity label Tag i of Unit i and the encryption algorithm Enc i ;
[0159] P i is the perturbation vector introduced during the encryption process (the perturbation term from step 2);
[0160] λ is a factor used to strengthen the impact of the perturbation.
[0161] If Hash Verify,i = Hash i , the verification passes, otherwise the decryption is rejected and the exception is recorded.
[0162] For the ciphertext Cipher i for which the verification passes, use the decryption algorithm Dec i and the key Key i to perform decryption:
[0163] Plain i = Dec i (Cipher i , Key i )
[0164] Further, the decrypted plaintext Plain i is loaded into the memory protection area Mem Secure , and the following control rules are set:
[0165] Access control: An unauthorized access attempt will trigger an immediate lock and clear Mem Secure .
[0166] Timed lock: If the user does not complete the editing within the specified time, the system automatically re-encrypts and writes back to the storage block to avoid the plaintext existing in the memory for a long time.
[0167] When the user finishes editing, update the plaintext to Plain i ', and trigger real-time encryption update.
[0168] Furthermore, for the modified plaintext Plain i ', according to the encryption algorithm Enc Enc in the encryption policy table Policy i and the key Key i , re-encrypt to generate a new ciphertext Cipher i ':
[0169] Cipher i ' = Enc i (Plain i ', Key i + δ i )
[0170] where δ i is the dynamic perturbation term during encryption (defined in step 2).
[0171] Regenerate the integrity fingerprint Hash i ', and add a specific regularization term to enhance data integrity:
[0172]
[0173] η is a factor that controls the influence of the regularization term;
[0174] F cnt,i is the content feature vector of the unit (from step 1).
[0175] Update the storage control table Control Store and the verification table Verify Enc , and write the new ciphertext Cipher i ' and the fingerprint Hash i ' back to the storage block.
[0176] Furthermore, during the entire editing process, the system monitors the access and usage of the memory area in real time:
[0177] If an anomaly is detected (such as unauthorized access or memory leak), immediately trigger locking and generate an alarm record.
[0178] Record the log of each editing operation, including the access time, modification status, verification result, and write it to the system log Log Ops , for subsequent auditing and security analysis.
[0179] Furthermore, the final output
[0180] The updated highly sensitive block H-Block and ordinary block N-Block contain the new ciphertext Cipher i ';
[0181] The updated storage control table Control Store , used to track the storage status of the unit;
[0182] The updated verification table Verify Enc , recording the new integrity fingerprint;
[0183] The system operation log Log Ops , recording all edit operations and exception information.
[0184] S4. Compare the new ciphertext and the original ciphertext of the logical operation unit after user editing, extract the differential data. If the differential data is not empty, record that the unit is in the modified state and enter the storage process. When storing, record the meta-information of the differential data, including the version number, modification timestamp, and storage location, write it into the differential storage control table, and then store the differential data in the corresponding block according to the sensitivity label of the logical operation unit. After each update, generate a version fingerprint for the entire document and merge it to form a version chain. After each storage operation, generate a log and a version log, recording the differential storage and version update situations, including the unit index, storage timestamp, differential size, and version fingerprint.
[0185] Specifically, this step is based on the output of step 3: the updated highly sensitive block H-Block, ordinary block N-Block, storage control table Control Store and verification table Verify Enc , to implement the differential storage and version management mechanism of the document. By calculating the differences of the document units, the storage efficiency is optimized, and at the same time, multiple version fingerprints are recorded to achieve version traceability and merging.
[0186] Furthermore, compare the new ciphertext Cipher i of the unit Unit i after user editing and the original ciphertext Cipher i , and extract the differential part ΔCipher i .
[0187] The differential calculation formula is:
[0188] ΔCipher i =Func Diff (Cipher i ',Cipher i )+ξ·F cnt,i
[0189] Where:
[0190] Func Diff (·): A calculation function based on block-level differences (such as byte comparison or block hash comparison);
[0191] ξ: Influence coefficient for adjusting the content characteristics in difference calculation;
[0192] F cnt,i : The unit content feature vector extracted in Step 1, which enhances the sensitivity of difference calculation to semantic changes.
[0193] If then record this unit as the modified state and enter the storage process.
[0194] Furthermore, according to the sensitivity label Tag of the unit i , store the difference data ΔCipher i into the corresponding block:
[0195] High-sensitivity block H-Block: Store units with Tag i = high and with differences;
[0196] Normal block N-Block: Store units with Tag i = low and with differences.
[0197] During storage, record the meta information Meta of the difference data i , including version number, modification timestamp, and storage location, and write it into the difference storage control table Control Diff .
[0198] Furthermore, after each update, generate a version fingerprint V-Hash for the entire document t :
[0199]
[0200] Wherein:
[0201] H(·): Hash function;
[0202] ΔCipher i : The difference data of the modified unit;
[0203] α: Weighting factor;
[0204] G Tag : The global sensitivity statistic of the current version (such as the proportion of high-sensitivity units), which enhances the diversity and verifiability of the version fingerprint.
[0205] Record the version fingerprint V-Hash t to the version chain Version Chain for version traceability.
[0206] Furthermore, according to the strategy, multiple differential versions are regularly merged into the master version Version Main , and the merging formula is:
[0207]
[0208] where represents the merging operation of multi-version differential data.
[0209] After the merging is completed, the differential data of the old version is archived to the read-only storage area Archive Store , and the space of the main storage area is released.
[0210] Furthermore, after each storage operation, a log Log Diff and a version log Log Version are generated to record the differential storage and version update situations, including unit index, storage timestamp, differential size, and version fingerprint.
[0211] If data anomalies are detected (such as inconsistent differential data or failed version chain verification), an alarm is triggered and an exception log Log Err is recorded.
[0212] Furthermore, the final outputs are:
[0213] Differential storage blocks (updated H-Block and N-Block);
[0214] Differential storage control table Control Diff ;
[0215] Version chain Version Chain ;
[0216] Storage and version logs Log Diff 、Log Version .
[0217] S5. Design a user access control and security verification mechanism. Through integrity verification and access privilege management, ensure the access security of the document, and at the same time optimize the loading efficiency of user requests.
[0218] Specifically, this step is based on the outputs of step 4: differential storage blocks {H-Block, N-Block}, differential storage control table Control Diff , version chain Version Chain and storage log Log Diff , and design a user access control and security verification mechanism. Through integrity verification and access privilege management, ensure the access security of the document, and at the same time optimize the loading efficiency of user requests.
[0219] Further, the user initiates an access request, and the system extracts the request parameters Req = (User, Unit i , Version t ), including the user identity, the target unit Unit i and the target version Version t .
[0220] The system verifies whether User has the permission to access the target unit Unit Auth through the user permission table Access i :
[0221] If User is not authorized to access Unit i , the request is rejected and the exception is recorded in the log Log Err ;
[0222] If the permission verification passes, continue with the next step.
[0223] Further, according to the requested version Version t and the storage control table Control Diff , locate the differential data of the target unit Unit i and load the differential ciphertext from H-Block or N-Block. Load the differential ciphertext from H-Block or N-Block.
[0224] Reconstruct the ciphertext Cipher of the target version i,t :
[0225]
[0226] where represents the differential merge operation, and iteratively accumulates the differential data in chronological order.
[0227] Further, verify the integrity of the target version:
[0228]
[0229] If Hash Verify,t matches the record in the version chain Version Chain , the integrity check passes;
[0230] If not, access is denied and the exception is recorded.
[0231] Further, for the ciphertext Cipher that passes the integrity check i,t , perform decryption according to the encryption algorithm Enc i and the key Key i in the storage control table:
[0232] Plain i,t = Dec i (Cipher i,t , Key i )
[0233] The decrypted plaintext Plain i,t Loaded into the memory protection area Mem Secure , Set the access window Win t , Ensure that the plaintext data in memory is only visible within the authorized range during user access:
[0234] If the user exceeds the access window time or attempts an unauthorized operation, immediately clear Mem Secure And trigger a warning.
[0235] Furthermore, after each access is completed, update the storage log Log Diff And the operation log Log Ops :
[0236] Record the unit index, version number, access timestamp, and user identity of the access.
[0237] Dynamically adjust the storage layout: According to the access frequency statistics of the unit in the access log, move the frequently accessed unit from N - Block to a faster storage medium (such as SSD) to optimize the subsequent access performance.
[0238] Furthermore, if an exception occurs during the access (such as integrity check failure, permission overrun, or memory leak), record the exception status in the log Log Err , And trigger a system alert.
[0239] Furthermore, for the final output, return the decrypted content Plain requested by the user i,t ;
[0240] The updated storage log Log Diff And the operation log Log Ops ;
[0241] The exception status log Log Err (If an exception occurs).
[0242] S6. Collect logs, and dynamically adjust the encryption policy and storage layout in combination with access pattern analysis, content sensitivity changes, and environmental security conditions.
[0243] Specifically, extract the following core information from the access log Log Ops And the exception log Log Err :
[0244] Freqi : The access frequency of Unit, which measures its usage frequency; i
[0245] Anom i : The anomaly event count of Unit (such as unauthorized access attempts, verification failures, etc.); i
[0246] Risk Env : The current environmental risk level of the system, provided by an external security module and based on attack trend assessment.
[0247] Furthermore, calculate the encryption policy adjustment factor Adj i , which is used to dynamically optimize the encryption policy and storage allocation:
[0248] Adj i = β1·log(1 + Freq i ) + β2·Anom i + β3·Risk Env
[0249] Where:
[0250] β1, β2, β3 are weight coefficients, fitted through historical data;
[0251] log(1 + Freq i ) increases the non - linear impact of frequency to prevent over - adjustment;
[0252] Risk Env introduces the global impact of environmental security.
[0253] Furthermore, dynamically adjust the sensitivity label Tag of Unit i according to Adj i : i
[0254] If Adj i > Threshold high , upgrade Tag i to high - sensitive high;
[0255] If Adj i < Threshold low , downgrade Tag i to normal - sensitive low.
[0256] For the unit with sensitivity change, regenerate the encryption policy Enc i :
[0257] High - sensitive units adopt AES 256 or higher - strength algorithms;
[0258] The ordinary units adopt AES 128 or lightweight algorithms.
[0259] Furthermore, adjust the storage location according to the sensitivity and access frequency:
[0260] Migrate the units with Tag i = high to the H-Block;
[0261] Migrate the units with Tag i = low to the N-Block.
[0262] For the units with a relatively high access frequency (Freq i > Threshold freq ), preferentially migrate them to high-performance storage media (such as SSD);
[0263] Update the storage control table Control Store to reflect the latest storage allocation status.
[0264] Furthermore, for the units Unit i whose sensitivity or encryption policy has changed, generate a new key Key i ' and re-encrypt:
[0265] Cipher i ' = Enc i (Plain i , Key i '+ γ·Risk Env )
[0266] where γ·Risk Env is an external risk-sensitive term, which improves the encryption strength in a high-risk environment.
[0267] Meanwhile, update the integrity fingerprint Hash i ', and record it in the verification table Verify Enc :
[0268]
[0269] ξ·Anom i Introduce a regular term for abnormal event counting to enhance the sensitivity of the fingerprint to abnormal activities.
[0270] Furthermore, record the results of each adjustment in the dynamic adjustment log Log Adjust :
[0271] Record the unit index, adjustment time, encryption policy changes, and storage location changes.
[0272] If an abnormality is detected during the adjustment process (such as failure of re-encryption, failure of storage migration, or risk exceeding the standard), an exception log Log is generated Err , and a system alarm is triggered.
[0273] Furthermore, the final output is:
[0274] The updated differential storage blocks {H-Block, N-Block}, reflecting the latest encryption policy and storage status;
[0275] The updated storage control table Control Store and the verification table Verify Enc ;
[0276] The dynamic adjustment log Log Adjust , recording the adjustment result;
[0277] The exception log Log Err (if an exception occurs).
[0278] The above-disclosed are only some preferred embodiments of the present invention. Of course, the scope of the rights of the present invention cannot be limited thereby. Those of ordinary skill in the art can understand all or part of the processes of implementing the above embodiments, and the equivalent changes made according to the claims of the present invention still fall within the scope covered by the invention.
Claims
1. A method for encrypted storage of documents, characterized in that, The method includes the following steps: S1. Obtain the document Doc, initialize and process the document Doc, divide it into logical operation units, ensure that each logical operation unit contains an independent content segment, perform sensitivity classification on the logical operation units using a classification model, output the sensitivity labels of the units, where the sensitivity labels include units with high sensitivity and units with low sensitivity, calculate the importance weights for the units with high sensitivity, and finally generate an encryption policy for each logical operation unit by combining the sensitivity labels and importance weights to obtain an encryption policy table; S2. Traverse the logical operation units, encrypt each unit according to the policy specified in the encryption policy table, generate each encrypted ciphertext, generate a unique integrity fingerprint for each encrypted ciphertext, record the unique integrity fingerprint in the verification table, and then store the ciphertext in the corresponding storage block according to the sensitivity label. The storage block includes a high-sensitivity block and a normal block, and at the same time, use a storage control table to record the allocation situation of all blocks; S3. Design a segmented decryption and real-time editing scheme to ensure that when the user edits the document, only the current operation unit is decrypted, and it is encrypted and updated immediately and the integrity is verified after the editing is completed: S4. Compare the new ciphertext and the original ciphertext of the logical operation unit after the user edits, extract the difference data. If the difference data is not empty, record that the unit is in a modified state and enter the storage process. When storing, record the meta-information of the difference data, including the version number, modification timestamp, and storage location, write it into the difference storage control table, and then store the difference data in the corresponding block according to the sensitivity label of the logical operation unit. After each update, generate a version fingerprint for the entire document and merge it to form a version chain. After each storage operation, generate a log and a version log to record the difference storage and version update situations, including the unit index, storage timestamp, difference size, and version fingerprint; S5. Design a user access control and security verification mechanism to ensure the access security of the document through integrity verification and access permission management, and at the same time optimize the loading efficiency of user requests; S6. Collect logs, and dynamically adjust the encryption policy and storage layout by combining access pattern analysis, content sensitivity changes, and environmental security conditions.
2. The method for encrypting and storing a document according to claim 1, wherein Use a hierarchical parsing model to decompose the document into logical units, and then extract the features of each logical unit, including structural features and content features, and combine them into the combined features of the unit; Divide into granularity operation units according to the combined features of each logical unit, where each granularity operation unit contains an independent content segment.
3. A document encryption and storage method according to claim 1, characterized in that, Generate an encryption policy for each logical unit according to the sensitivity label and importance weight, including: If the sensitivity label Tag i = high, i.e., a unit with high sensitivity and the importance weight S i > the threshold Threshold, then assign the strong encryption policy AES 256 and the high-strength key Key high,i ; If the sensitivity label Tag i = low, i.e., a unit with low sensitivity, then assign the lightweight encryption policy AES 128 and the ordinary key Key low,i .
4. A method for encrypting and storing documents according to claim 3, characterized in that, During the encryption process of each unit according to the policy specified in the encryption policy table, introduce a perturbation term generated according to the content features of the unit to enhance the unpredictability of the encryption result: The storing the ciphertext in the corresponding storage block according to the sensitivity label includes: High-sensitivity block: storing Tag i = unit of high; Normal block: Store Tag i = The cell with low 5. A method for encrypted storage of documents according to claim 4, characterized in that Update the status of the storage block to the storage control table Control Store , which records: Index of High-Sensitivity Blocks H ={Unit i |Tag i =high}; Index of the ordinary block N = {Unit i | Tag i = low}; Dynamically adjust the physical storage locations of the high-sensitivity block and the normal block according to the access frequency of the unit to ensure that the frequently accessed units are stored on devices with fast response.
6. A document encryption storage method according to claim 4, wherein The S3 further includes: When receiving an editing request from the user for a document, first parse the logical operation units of the document, then query the storage location of the logical operation units of the document through the storage control table and locate it, generate a storage path according to the location result, point to the physical storage address of the ciphertext, and at the same time read its encryption algorithm and key; Load the ciphertext and integrity fingerprint from the storage path, perform integrity verification, and for the ciphertext that passes the integrity verification, use the decryption algorithm and key to decrypt it to obtain the decrypted plaintext; Load the decrypted plaintext into the memory protection area, and at the same time design control rules for the memory protection area for real-time editing management. When the user finishes editing, generate the modified plaintext and trigger real-time encryption update; For the modified plaintext, re-encrypt it according to the encryption algorithm and key in the encryption policy table to generate a new ciphertext and a new integrity fingerprint, update the storage control table and the verification table according to the new ciphertext and the new integrity fingerprint, and write the new ciphertext and fingerprint back to the storage block; At the same time, during the entire editing process, monitor the access and usage of the memory area in real time; Among them, parsing the logical operation units of the document includes: By storing the control table Control Store Query granularity operation unit Unit i Storage location of: If the granularity operation unit Unit i ∈ high-sensitivity block H-Block, then this unit belongs to the high-sensitivity block; If the granularity operation unit Unit i ∈ ordinary block N-Block, then this unit belongs to the ordinary block; Query result generation storage path Path i , pointing to the physical storage address of the target ciphertext Cipher i , and simultaneously read its encryption algorithm Enc i and key Key i ; During integrity verification, if the integrity verification Hash Verify,i = integrity fingerprint Hash i , the verification passes; otherwise, decryption is refused and the exception is recorded; Loading the decrypted plaintext into the memory protection area Mem Secure , the following control rules are provided: Unauthorized access attempts trigger an immediate lock and clear the memory protection area Mem Secure ; If the user fails to complete the editing within the specified time, automatically re-encrypt and write it back to the storage block to avoid the long-term existence of the plaintext in the memory; When monitoring the access and usage of the memory area in real time: If an anomaly is detected, immediately trigger locking and generate an alarm record; record the log of each editing operation, including access time, modification status, and verification result, and write it to the system log Log Ops .
7. A document encryption and storage method according to claim 6, characterized in that The differential data is calculated as follows: ΔCipher i = Func Diff (Cipher i ', Cipher i ) + ξ·F cnt,i Among them, Func Diff (·) is a calculation function based on block-level differences; ξ is an influence coefficient for adjusting the content features in difference calculation; F cnt,i is the content feature vector of the step unit, enhancing the sensitivity of difference calculation to semantic changes; The version fingerprint V-Hash t is generated as follows: where H(·) is a hash function; ΔCipher i is the differential data of the modification unit; α is a weighting factor; G Tag is the global sensitivity statistic of the current version, enhancing the diversity and verifiability of the enhanced version fingerprint.
8. A method for encrypting and storing documents according to claim 7, characterized in that According to the sensitivity label Tag of the unit i , store the differential data ΔCipher i into the corresponding block: High-Sensitivity Block H-Block: Store Tags i = high and differentiated cells; Normal Block N-Block: Store Tag i = low and different cells; According to the updated sensitivity label Tag i , multiple differential versions are regularly merged into the main version Version Main ; After the merge is completed, archive the differential data of the old version to the read-only storage area Archive Store , and free up the space in the main storage area.
9. A method for encrypted storage of documents according to claim 1, characterized in that Designing the user access control and security verification mechanism to ensure the access security of the document through integrity verification and access right management, and at the same time optimizing the loading efficiency of the user request, specifically including: When the user initiates an access request, obtain the request parameters Req = (User, Unit i , Version t ), including the user identity, the target unit Unit i and the target version Version t , and verify the user's permissions. If the permission verification passes, continue with the next step; According to the requested version Version t and the storage control table Control Diff , locate the differential data of the target granularity operation unit Load the differential ciphertext from the H-Block or N-Block, perform integrity check. If the verification is successful, execute the next step; For the ciphertext Cipher that has passed the integrity check i,t , perform decryption according to the encryption algorithm Enc i and the key Key i ; After each access is completed, update the storage log Log Diff and the operation log Log Ops : Record the unit index, version number, access timestamp, and user identity of the access; If an exception occurs during the access, record the exception status in the log Log Err and trigger a system alert.
10. A method for encrypting and storing documents according to any one of claims 8-9, characterized in that, When the user initiates an access request, simultaneously verify through the user permission table Access Auth whether User has the permission to access the target unit Unit i : If the User is not authorized to access the Unit i , reject the request and record the exception in the log Log Err ; If the permission verification passes, continue to execute the next step; When according to the requested version Version t and the storage control table Control Diff the target version ciphertext Cipher is reconstructed through a differential merge operation i,t ; the differential merge operation iteratively accumulates differential data in chronological order; It is further necessary to verify the integrity of the target version: If Hash Verify,t matches the record in the version chain Version Chain the integrity check passes; if not, access is denied and the exception is recorded; Load the decrypted plaintext Plain i,t into the memory protection area Mem Secure , set the access window Win t , and ensure that the plaintext data in the memory is only visible within the authorized range during user access: If the user exceeds the access window time or attempts an unauthorized operation, immediately clear the memory protection area Mem Secure and trigger a warning.
Citation Information
Patent Citations
Encryption device, encryption system and data encryption method
CN110995757A
Cloud storage information processing system and method based on dynamic encryption RBAC model
CN111090622A
File processing method and system based on digital information security
CN118114301A
Remodification, identification and alarm system and method for sensitive archives
CN119046933A
Systems for mandatory access control of secured hierarchical documents and related methods
EP4361872A1
Cited By
Document information data encryption and privacy protection method
CN121118082A