Data processing method based on cloud computing
By shaking the IP address hash encryption and TCP protocol handshake to generate encryption keys, data security issues in cloud computing are solved, and data transmission security and tamper-proof are achieved.
Patent Information
- Application Number
- CN202510755739.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-07
- Publication Date
- 2025-07-11
- Estimated Expiration
- 2045-06-07
AI Technical Summary
In a cloud computing environment, data security is difficult to guarantee, especially after data is uploaded in the cloud, users lose control and face serious threats of data leakage and tampering.
By obtaining the IP address of the virtual machine node for hash encryption, a fixed hash value and a public promise value are generated, and a flag quantity is generated in combination with the handshake process of the TCP protocol, and an encryption key is generated to encrypt the data packets to ensure the security of data transmission.
Effectively prevent unauthorized access and tampering, enhance the security of data in the cloud platform, and adapt to the dynamic changes of virtual machine nodes.
Smart Images

Figure CN120301596A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of data processing, and particularly relates to a data processing method based on cloud computing. Background Art
[0002] With the development of Internet technology, cloud platform application technologies such as cloud computing and cloud management systems have developed rapidly. Cloud storage provides a new storage mode, and more and more data is stored in the cloud and transmitted through the network. However, serious security threats are faced during the data transmission and storage processes of cloud computing, such as data leakage and data tampering. In addition, in cloud computing security, the security of data is the most concerned issue for users. However, when users upload data to the cloud, they lose control over the data in the cloud. Therefore, how to ensure the security of data in the cloud computing environment has become an urgent problem to be solved. Summary of the Invention
[0003] In order to solve the above problems, the present invention proposes a data processing method based on cloud computing.
[0004] The technical solution of the present invention is that a data processing method based on cloud computing includes the following steps:
[0005] S1. Obtain the virtual machine nodes where each data block of the data packet in the cloud platform is located;
[0006] S2. Determine the communication requests between the data packet and each virtual machine node according to the IP address of the virtual machine node and the TCP protocol of the data packet;
[0007] S3. Generate an encryption key for the data packet according to the communication requests between the data packet and each virtual machine node;
[0008] S4. Encrypt the data packet in the cloud platform by using the encryption key.
[0009] Further, S2 includes the following sub-steps:
[0010] S21. Obtain the IP addresses of the virtual machine nodes where each data block is located, and perform hash encryption on the IP addresses to obtain the fixed hash values of each virtual machine node;
[0011] S22. Generate public commitment values for each virtual machine node by using random numbers and the fixed hash values of each virtual machine node;
[0012] S23. Obtain the TCP protocol of the data packet, and determine the communication requests between the data packet and each virtual machine node according to the public commitment values of each virtual machine node.
[0013] The beneficial effects of the above further solution are as follows: In the present invention, the IP address is the unique identifier of the virtual machine node in the network and is used for network communication and data transmission. Hash encrypting the IP address of the virtual machine node can obtain a fixed hash value, which helps to hide the real IP address and prevent unauthorized access and attacks; the public commitment value generated by using the hash value and a random number provides a secure verification mechanism for the communication between the data packet and the virtual machine node, making it more difficult for the data packet to be tampered with or forged during the transmission process.
[0014] Further, in S22, the public commitment value of the virtual machine node is calculated by the formula:
[0015] ;
[0016] In the formula, represents a random number, represents the fixed hash value of the virtual machine node.
[0017] Further, S23 includes the following sub-steps:
[0018] S231. Obtain the TCP protocol of the data packet, and generate a flag quantity according to the SYN flag bit and ACK flag bit generated during the handshake process of the TCP protocol;
[0019] S232. Combine the public commitment values of each virtual machine node and the flag quantity as the communication request between the data packet and each virtual machine node.
[0020] The beneficial effects of the above further solution are as follows: In the present invention, the handshake process of the TCP protocol (SYN - SYN - ACK - ACK) is a key step in establishing a reliable connection. By detecting the SYN and ACK flag bits, it can be ensured that the data packet is sent on a valid TCP connection, thus preventing unauthorized access and attacks; combining the public commitment values of each virtual machine node with the flag quantity generated during the TCP handshake process as part of the communication request can further verify the authenticity and legality of the data packet.
[0021] Further, in S231, the flag quantity is calculated by the formula:
[0022] ;
[0023] In the formula, represents a specific bit of the SYN flag bit, represents a specific bit of the ACK flag bit, represents the maximum segment length of the TCP protocol.
[0024] Set specific bits in a bit field to 1 to activate or enable a certain function or status. During the handshake process, the SYN and ACK flag bits play a crucial role. SYN is used to initiate a connection request, and ACK is used to confirm a connection request or the receipt of a data packet. Setting the SYN bit to 1 indicates initiating a new connection request; the ACK flag bit is often set to 1 (ACK = 1) to confirm the receipt of a data packet. The maximum segment size (MSS) of the TCP protocol refers to the maximum amount of data that can be sent in one go in a TCP connection.
[0025] Furthermore, in S232, the communication request between the data packet and the virtual machine node has the expression:
[0026] ;
[0027] In the formula, represents a flag quantity, represents the public commitment value of the virtual machine node, represents a random number.
[0028] Furthermore, S3 includes the following sub-steps:
[0029] S31. Extract the maximum eigenvalue of the communication request as the communication eigenvalue of the virtual machine node;
[0030] S32. Calculate the first encrypted data of the encryption key based on the communication eigenvalues of all virtual machine nodes;
[0031] S33. Determine the second encrypted data and generate the encryption key.
[0032] The beneficial effects of the above further solution are: In the present invention, by extracting the maximum eigenvalue of the communication request as the communication eigenvalue of the virtual machine node, the communication patterns and behaviors of each virtual machine node can be more effectively identified. Calculating the first encrypted data based on the communication eigenvalues of all virtual machine nodes and determining the second encrypted data to generate the encryption key ensure the dynamics and uniqueness of the encryption key. The expression of the encryption key is: ; In the formula, represents the first encrypted data, represents the second encrypted data.
[0033] Furthermore, in S32, the calculation formula for the first encrypted data is:
[0034] ;
[0035] In the formula, represents the Communication eigenvalue of a virtual machine node Indicates the number of virtual machine nodes Indicates the Allocated memory size of the th virtual machine node
[0036] The allocated memory size refers to the memory size allocated to the virtual machine node, which affects the running speed and data processing ability of the node
[0037] Further, in S33, the checksum of the TCP protocol of the data packet is used as the second encrypted data
[0038] The checksum is calculated for the entire TCP segment in 16-bit words, which is a mandatory field. The checksum can be encoded as the second encrypted data when necessary
[0039] The beneficial effects of the present invention are as follows: The present invention determines communication requests based on the IP addresses of virtual machine nodes and the TCP protocol of data packets. The precise generation of communication requests helps prevent unauthorized access and data leakage; The present invention can adapt to the dynamic changes of virtual machine nodes in the cloud platform by generating specific encryption keys for data packets and using these keys for encryption, significantly enhancing the security of data in the cloud platform Description of the Drawings
[0040] Figure 1 Is a flowchart of a data processing method based on cloud computing Detailed Embodiments
[0041] The embodiments of the present invention will be further described below in conjunction with the accompanying drawings
[0042] As Figure 1 Shown, the present invention provides a data processing method based on cloud computing, including the following steps
[0043] S1. Obtain the virtual machine nodes where each data block of the data packet in the cloud platform is located
[0044] S2. Determine the communication requests between the data packet and each virtual machine node according to the IP address of the virtual machine node and the TCP protocol of the data packet
[0045] S3. Generate an encryption key for the data packet according to the communication requests between the data packet and each virtual machine node
[0046] S4. Encrypt the data packet in the cloud platform using the encryption key
[0047] In the embodiments of the present invention, S2 includes the following sub-steps
[0048] S21. Obtain the IP addresses of the virtual machine nodes where each data block is located, and perform hash encryption on the IP addresses to obtain the fixed hash values of each virtual machine node;
[0049] S22. Use random numbers and the fixed hash values of each virtual machine node to generate public commitment values for each virtual machine node;
[0050] S23. Obtain the TCP protocol of the data packet, and determine the communication requests between the data packet and each virtual machine node according to the public commitment values of each virtual machine node.
[0051] The beneficial effects of the above further solution are as follows: In the present invention, the IP address is the unique identifier of the virtual machine node in the network, which is used for network communication and data transmission. Performing hash encryption on the IP address of the virtual machine node can obtain a fixed hash value, which helps to hide the real IP address and prevent unauthorized access and attacks; the public commitment value generated by using the hash value and random numbers provides a secure verification mechanism for the communication between the data packet and the virtual machine node, making it more difficult for the data packet to be tampered with or forged during the transmission process.
[0052] In the embodiment of the present invention, in S22, the public commitment value of the virtual machine node The calculation formula is:
[0053] ;
[0054] In the formula, represents a random number, represents the fixed hash value of the virtual machine node.
[0055] In the embodiment of the present invention, S23 includes the following sub-steps:
[0056] S231. Obtain the TCP protocol of the data packet, and generate a flag quantity according to the SYN flag bit and ACK flag bit generated during the handshake process of the TCP protocol;
[0057] S232. Combine the public commitment values of each virtual machine node and the flag quantity as the communication requests between the data packet and each virtual machine node.
[0058] The beneficial effects of the above further solution are as follows: In the present invention, the handshake process (SYN-SYN-ACK-ACK) of the TCP protocol is a key step in establishing a reliable connection. By detecting the SYN and ACK flag bits, it can be ensured that the data packet is sent on a valid TCP connection, thus preventing unauthorized access and attacks; combining the public commitment values of each virtual machine node with the flag quantity generated during the TCP handshake process as part of the communication request can further verify the authenticity and legality of the data packet.
[0059] In an embodiment of the present invention, in S231, the flag quantity has the following calculation formula:
[0060] ;
[0061] In the formula, represents a specific bit of the SYN flag bit, represents a specific bit of the ACK flag bit, represents the maximum segment size of the TCP protocol.
[0062] Setting a specific bit in the bit field to 1 is used to activate or enable a certain function or status. During the handshake process, the SYN and ACK flag bits play a key role. SYN is used to initiate a connection request, and ACK is used to confirm the connection request or the reception of a data packet. Setting the SYN bit to 1 indicates initiating a new connection request; the ACK flag bit is often set to 1 (ACK = 1) to confirm the reception of a data packet. The maximum segment size (MSS, Maximum Segment Size) of the TCP protocol refers to the maximum amount of data that can be sent in one TCP connection.
[0063] In an embodiment of the present invention, in S232, the communication request between the data packet and the virtual machine node has the following expression:
[0064] ;
[0065] In the formula, represents the flag quantity, represents the public commitment value of the virtual machine node, represents a random number.
[0066] In an embodiment of the present invention, S3 includes the following sub-steps:
[0067] S31. Extract the maximum eigenvalue of the communication request as the communication eigenvalue of the virtual machine node;
[0068] S32. Calculate the first encrypted data of the encryption key according to the communication eigenvalues of all virtual machine nodes;
[0069] S33. Determine the second encrypted data and generate the encryption key.
[0070] The beneficial effects of the above further solution are as follows: In the present invention, by extracting the maximum eigenvalue of the communication request as the communication eigenvalue of the virtual machine node, the communication patterns and behaviors of each virtual machine node can be more effectively identified. Calculating the first encrypted data based on the communication eigenvalues of all virtual machine nodes and determining the second encrypted data to generate the encryption key ensures the dynamics and uniqueness of the encryption key. The expression of the encryption key is: ; where represents the first encrypted data, represents the second encrypted data.
[0071] In an embodiment of the present invention, in S32, the calculation formula of the first encrypted data is:
[0072] ;
[0073] where represents the communication eigenvalue of the th virtual machine node, represents the number of virtual machine nodes, represents the th virtual machine node's allocated memory size.
[0074] The allocated memory size refers to the memory size allocated to the virtual machine node, which affects the running speed and data processing ability of the node.
[0075] In an embodiment of the present invention, in S33, the checksum of the TCP protocol of the data packet is used as the second encrypted data.
[0076] The checksum is calculated for the entire TCP segment in 16-bit words, which is a mandatory field. The checksum can be encoded if necessary as the second encrypted data.
[0077] Those of ordinary skill in the art will realize that the embodiments described herein are to assist the reader in understanding the principles of the present invention, and it should be understood that the protection scope of the present invention is not limited to such specific statements and embodiments. Those of ordinary skill in the art can make various other specific deformations and combinations without departing from the essence of the present invention based on the technical revelations disclosed in the present invention, and these deformations and combinations are still within the protection scope of the present invention.
Claims
1. A data processing method based on cloud computing, characterized in that, It includes the following steps: S1. Obtain the virtual machine nodes where each data block of the data packet in the cloud platform is located; S2. Determine the communication requests between the data packet and each virtual machine node according to the IP address of the virtual machine node and the TCP protocol of the data packet; S3. Generate an encryption key for the data packet according to the communication requests between the data packet and each virtual machine node; S4. Encrypt the data packet in the cloud platform by using the encryption key.
2. The data processing method based on cloud computing according to claim 1, wherein The S2 includes the following sub-steps: S21. Obtain the IP addresses of the virtual machine nodes where each data block is located, and perform hash encryption on the IP addresses to obtain the fixed hash values of each virtual machine node; S22. Generate public commitment values for each virtual machine node by using random numbers and the fixed hash values of each virtual machine node; S23. Obtain the TCP protocol of the data packet, and determine the communication requests between the data packet and each virtual machine node according to the public commitment values of each virtual machine node.
3. The data processing method based on cloud computing according to claim 2, wherein In S22, the publicly committed value of the virtual machine node is calculated as follows: ; In the formula, represents a random number, represents the fixed hash value of the virtual machine node.
4. The data processing method based on cloud computing according to claim 2, wherein The S23 includes the following sub-steps: S231. Obtain the TCP protocol of the data packet, and generate a flag quantity according to the SYN flag bit and ACK flag bit generated during the handshake process of the TCP protocol; S232. Combine the public commitment values of each virtual machine node and the flag quantity as the communication requests between the data packet and each virtual machine node.
5. The data processing method based on cloud computing according to claim 4, wherein In S231, the formula for the flag quantity is as follows: ; In the formula, represents a specific bit of the SYN flag bit, represents a specific bit of the ACK flag bit, represents the maximum segment size of the TCP protocol.
6. The data processing method based on cloud computing according to claim 4, wherein In S232, the communication request between the data packet and the virtual machine node has the following expression: ; In the formula, represents a flag quantity, represents the public commitment value of the virtual machine node, represents a random number.
7. The data processing method based on cloud computing according to claim 1, wherein The S3 includes the following sub-steps: S31. Extract the maximum eigenvalue of the communication request as the communication eigenvalue of the virtual machine node; S32. Calculate the first encrypted data of the encryption key according to the communication eigenvalues of all virtual machine nodes; S33. Determine the second encrypted data and generate the encryption key.
8. The data processing method based on cloud computing according to claim 7, wherein In S32, the first encrypted data is calculated as follows: ; Wherein, represents the communication eigenvalue of the th virtual machine node, represents the number of virtual machine nodes, represents the allocated memory size of the th virtual machine node.
9. The data processing method based on cloud computing according to claim 7, wherein In the S33, the checksum of the TCP protocol of the data packet is used as the second encrypted data.
Citation Information
Patent Citations
XEN cloud platform-based virtual machine block device isolation method
CN103414558A
Virtual machine communication data encryption method and system
CN105245430A
Data processing method
CN116915424A
TCP private protocol communication authentication method of Internet of Things equipment
CN118250016A
Three-factor user authentication method for generating OTP using iris information and secure mutual authentication system using OTP authentication module of wireless communication terminal
US20130268444A1