Security synchronization system and method for cluster data based on national cryptographic algorithm

By introducing a data security synchronization system with Guoxin algorithm into the server cluster, the problem that traditional methods are difficult to meet information security needs is solved, the secure transmission and consistency of data is achieved, and the security and reliability of cluster services are improved.

CN120301897APending Publication Date: 2025-07-11BEIJING CATHAY INTERNET INFORMATION TECH CO LTD +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510438928.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-09
Publication Date
2025-07-11

AI Technical Summary

Technical Problem

In the prior art, traditional data synchronization methods mainly rely on internationally universal encryption algorithms, which are difficult to meet the country's needs for information security. How to apply the national secret algorithm to data security synchronization in server clusters has become an urgent problem.

Method used

A cluster data security synchronization system based on the Guoxin algorithm was designed, including the master-slave data synchronization module, the data management module, the key management module and the master-slave control module. The Guoxin SM4, SM3 and SM2 algorithms are used for data encryption, hashing operations and digital signatures, and data is transmitted through the SSL secure channel to achieve full and incremental synchronization to ensure data security and consistency.

Benefits of technology

It improves the security and reliability of server cluster data synchronization, enhances the flexibility and economy of the system, provides a stable and efficient cluster service experience, and meets the requirements of the national information security policy.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120301897A_ABST
    Figure CN120301897A_ABST
Patent Text Reader

Abstract

The invention provides a cluster data security synchronization system and method based on a national cryptographic algorithm, and the system comprises a master-slave data synchronization module which is used for receiving a data synchronization request of a master node, determining a synchronization mode, and initiating a data backup request; receiving encrypted data returned by the data management and synchronizing the encrypted data to the slave node; the data management module is used for initiating a key request, completing synchronous data backup and encryption processing according to returned key data, and returning encrypted synchronous data to the master-slave data synchronization module; the key management module is used for returning key data and use permission according to the key request; and the master-slave control module is used for completing configuration of master and slave nodes. The method is realized based on the national cryptographic algorithm, so that the secure transmission and consistency of data among clusters are ensured, the diversity of data synchronization is also realized, the flexibility and economy of the system are remarkably improved while the security and reliability are improved, and more stable and efficient cluster service experience is brought to users.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of data encryption transmission, and particularly to a cluster data security synchronization system and method based on national cryptographic algorithms. Background Art

[0002] With the rapid development of information technology, data security has become one of the most concerned issues for enterprises and organizations. As the core infrastructure for processing and storing a large amount of data, the data security synchronization of server clusters is particularly important. Traditional data synchronization methods mainly rely on internationally common encryption algorithms such as AES and RSA. However, with the country's emphasis on information security, national cryptographic algorithms have gradually become an important means to ensure data security. How to apply national cryptographic algorithms in data synchronization is an urgent problem to be solved. Summary of the Invention

[0003] Aiming at the problems existing in the prior art, a cluster data security synchronization system and method based on national cryptographic algorithms are provided, which are used for data security synchronization between server clusters, ensure the security of cluster data synchronization, and realize the high availability of cluster services.

[0004] The first aspect of the present invention proposes a cluster data security synchronization system based on national cryptographic algorithms, including:

[0005] A master-slave data synchronization module, which is used to receive a data synchronization request from the master node, determine the synchronization mode and initiate a data backup request; and receive the encrypted data returned by the data management and synchronize it to the slave node;

[0006] A data management module, which is used to initiate a key request and complete the backup and encryption processing of synchronization data according to the returned key data, and return the encrypted synchronization data to the master-slave data synchronization module;

[0007] A key management module, which is used to return key data and usage permissions according to the key request;

[0008] A master-slave control module, which is used to complete the configuration of the master and slave nodes.

[0009] In a preferred embodiment, in the master-slave data synchronization module, the synchronization mode includes full synchronization and incremental synchronization.

[0010] In a preferred embodiment, in the data management module, the synchronization data backup process includes:

[0011] Receiving a data backup request;

[0012] According to the determined synchronization mode, selecting the corresponding data to perform a data backup operation.

[0013] In a preferred embodiment, the specific working process of the key management module includes:

[0014] Perform permission verification on the requesting party. If the permission passes the verification, the key management module will grant the data management module the permission to use the key and return the key data; otherwise, return an error message.

[0015] In a preferred embodiment, in the data management module, the encryption process is as follows:

[0016] Receive the key data;

[0017] Encrypt the backup data using the national cryptography SM4 block cipher algorithm;

[0018] Perform a Hash operation on the backup data using the national cryptography SM3 cryptographic hash algorithm to generate the Hash value of the data;

[0019] Perform a digital signature on the backup data using the national cryptography SM2 elliptic curve public key cryptography algorithm;

[0020] Integrate the ciphertext, Hash value, and signature value of the backup data, perform data splicing, and return the spliced data to the master-slave data synchronization module.

[0021] In a preferred embodiment, data synchronization is performed between the master node and the slave node through a national cryptography SSL secure channel.

[0022] In a preferred embodiment, it further includes that after the slave node receives the data, verify the Hash value and signature value in the synchronized data. If the verification passes, the slave node will perform data recovery; if the verification fails, return an error message.

[0023] The second aspect of the present invention proposes a method for secure synchronization of cluster data based on national cryptography algorithms, including:

[0024] Receive a data synchronization request initiated by the master node;

[0025] Determine the synchronization mode, and back up the synchronization data to be transmitted according to the synchronization mode;

[0026] Request to obtain the key data and usage permission;

[0027] Use the key data to encrypt the backed-up data;

[0028] Respond to the master node data synchronization request and notify the master node to synchronize the encrypted data to the slave node.

[0029] In a preferred embodiment, the use of the key data to encrypt the backed-up data specifically includes:

[0030] Receive the key data;

[0031] Encrypt the backup data using the national cryptographic SM4 block cipher algorithm;

[0032] Perform a Hash operation on the backup data using the national cryptographic SM3 cryptographic hash algorithm to generate the Hash value of the data;

[0033] Perform a digital signature on the backup data using the national cryptographic SM2 elliptic curve public key cryptography algorithm;

[0034] Integrate the ciphertext, Hash value, and signature value of the backup data, and perform data splicing to complete the encryption process of the backup data.

[0035] In a preferred embodiment, it further includes that after receiving the data, the slave node verifies the Hash value and signature value in the synchronized data. If the verification passes, the slave node will perform data recovery; if the verification fails, an error message will be returned.

[0036] Compared with the prior art, the beneficial effects of adopting the above technical solution are as follows: On the basis of traditional cluster data synchronization, the present invention adds visual management of data, adds full-volume synchronization and incremental synchronization of data, and integrates the advantages of the national cryptographic algorithms SM2, SM3, and SM4. It not only ensures the secure transmission and consistency of data between clusters, but also realizes the diversity of data synchronization, making the present invention significantly improve the flexibility and economy of the system while enhancing the security and reliability of the cluster service, and bringing a more stable and efficient cluster service experience to users. Brief Description of the Drawings

[0037] Figure 1 It is a schematic diagram of a cluster data security synchronization system based on national cryptographic algorithms proposed by the present invention.

[0038] Figure 2 It is a flowchart of a cluster data security synchronization method based on national cryptographic algorithms proposed by the present invention.

[0039] Figure 3 It is a schematic diagram of the cluster data synchronization process in an embodiment of the present invention. Detailed Embodiments

[0040] To make the objectives, technical solutions, and advantages of the present invention more clearly understood, the following will clearly and completely describe the technical solutions in the embodiments of the present application in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all of the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments in the present application without creative efforts belong to the scope of protection of the present application. Without conflict, the embodiments in the present application and the features in the embodiments may be combined with each other arbitrarily. And although the logical order is shown in the flowchart, in some cases, the steps shown or described may be executed in a different order than here.

[0041] The terms "first" and "second" in the specification, claims, and the above-mentioned accompanying drawings of the present application are used to distinguish different objects, rather than to describe a specific order. In addition, the term "comprising" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product, or device that includes a series of steps or units is not limited to the listed steps or units, but optionally further includes steps or units not listed, or optionally further includes other steps or units inherent to these processes, methods, products, or devices.

[0042] In order to achieve secure data synchronization between server clusters, ensure the security of cluster data synchronization, and achieve high availability of cluster services, an embodiment of the present invention proposes a cluster data security synchronization system based on national cryptography algorithms. Please refer to Figure 1 . This system mainly includes a master-slave data synchronization module, a data management module, a key management module, and a master-slave control module.

[0043] Specifically, the master-slave data synchronization module is mainly used to receive the data synchronization request from the master node, determine the synchronization mode and initiate a data backup request; and receive the encrypted data returned by the data management and synchronize it to the slave node; the master-slave data synchronization module is responsible for synchronizing data between the master node and the slave node. Using an efficient data transmission mechanism, it ensures that data changes on the master node can be quickly and accurately synchronized to the slave node, thereby achieving data consistency and redundant backup.

[0044] The data management module is mainly used to initiate a key request and complete the backup and encryption processing of synchronization data according to the returned key data, and return the encrypted synchronization data to the master-slave data synchronization module. This module is responsible for synchronization data management. When the cluster needs data synchronization, it provides specific synchronization data, flexibly manages the data to be synchronized, realizes the visualization of synchronization data and the configurability of synchronization data, and realizes full-volume synchronization and incremental synchronization of synchronization data. It not only improves the flexibility and scalability of synchronization data, but also reduces the resource consumption of the server.

[0045] The key management module is mainly used to return key data and usage permissions based on key requests. This module is responsible for key generation, distribution and management in the system. This module uses advanced encryption technology to ensure the secure storage and transmission of keys. Through strict permission control and audit mechanisms, the key management module effectively prevents the risk of key leakage and abuse, and ensures the security of the system.

[0046] The master-slave control module is mainly used to complete the configuration of the master and slave nodes, and is responsible for managing and coordinating the relationship between the master node and the slave nodes.

[0047] It should be noted that after the master-slave data synchronization module receives the data synchronization request, it starts to prepare the synchronization data. The synchronization data prepared here is related to the selected synchronization mode. In this embodiment, two synchronization modes, full synchronization and incremental synchronization, are provided. In the full synchronization mode, all data are synchronized; in the incremental synchronization mode, the data that has changed since the last synchronization is synchronized.

[0048] In the data management module, the data to be synchronized needs to be backed up and encrypted. After receiving the data backup request, the corresponding data is selected to perform the backup operation according to the determined synchronization mode. If the synchronization mode is full synchronization, full backup is adopted at this time, and the data management module will prepare to back up all the current synchronized data; if the synchronization mode is incremental, incremental backup is adopted at this time, and the data management module will identify the data that has changed since the last backup and only back up the changed data.

[0049] While backing up data, the data management module initiates a key data acquisition request to the key management module to obtain the key (symmetric key, asymmetric key) required for use in the data synchronization process and obtain key usage rights.

[0050] Correspondingly, after receiving the key request, the key management module needs to verify the authority (i.e. check the identity of the requester and whether it has the authority to use the corresponding key). If the authority is verified, the key management module will grant the data management module the authority to use the key and return the key data; otherwise, an error message will be returned. Key management establishes a complete key management system to achieve the generation, storage, distribution and destruction of national secret algorithm keys.

[0051] In this embodiment, the key data requested by the data management module mainly includes national cryptography algorithm data. After receiving the key data, the national cryptography SM4 block cipher algorithm is used to encrypt the currently backed-up data to ensure the security of the data during transmission; the national cryptography SM3 cryptographic hash algorithm is used to perform a Hash operation on the backed-up data to generate the Hash value of the data for subsequent integrity verification; the national cryptography SM2 elliptic curve public key cryptography algorithm is used to perform a digital signature on the backed-up data to ensure the source and integrity of the data; the ciphertext, Hash value, and signature value of the backed-up data are integrated, and data splicing is performed, and finally returned to the master-slave data synchronization module.

[0052] After the master-slave data synchronization module receives the encrypted synchronization data returned by the data management module, it indicates that the synchronization data is ready. At this time, it can respond to the data synchronization request of the master node, and the master node transmits the synchronization data to the slave node to complete the data synchronization.

[0053] In one embodiment, after the master node obtains the synchronization data, it will securely synchronize the data to the slave node through the national cryptography SSL secure channel to ensure the confidentiality and integrity of the data during transmission.

[0054] It should be added that after the slave node receives the data, it also needs to verify the integrity of the data and restore the data, specifically including: verifying the Hash value and signature value in the synchronization data to confirm the integrity of the data and the legality of the source; if the verification passes, the slave node will perform data restoration; if the verification fails, an error message will be returned.

[0055] In one embodiment, the server can select the data to be synchronized, view the synchronization type of the data, etc. through the management interface, manage the synchronized data, and perform operations such as archiving, deleting, and downloading.

[0056] In the present invention, the application of national cryptography algorithms is mainly reflected in the following aspects:

[0057] 1. Data transmission encryption: During the process of data transmission from one server node to another, the SM2 key negotiation algorithm is used to calculate the session key, and the SM4 algorithm is used to perform symmetric encryption on the data to ensure the confidentiality of data transmission.

[0058] 2. Authentication and integrity verification: The SM3 hash algorithm is used to perform integrity verification on the data, which can effectively prevent the synchronized data from being attacked by a man-in-the-middle, ensuring that the data has not been tampered with during transmission and storage. At the same time, combined with the SM2 algorithm for digital signature, the authentication of the data source is realized.

[0059] 3. Key management: Establish a complete key management system to ensure the security of the keys used in national cryptography algorithms during the processes of generation, storage, distribution, and destruction.

[0060] In summary, the national cryptography algorithm-based cluster data security synchronization method and system can not only meet the requirements of national information security policies, but also have high security and reliability in practical applications. With the further promotion and application of national cryptography algorithms, their advantages in the field of data security will become more obvious, providing strong technical support for the development of China's information security cause.

[0061] An embodiment of the present invention also proposes a national cryptography algorithm-based cluster data security synchronization method. Please refer to Figure 2 、 Figure 3 , and the specific process includes:

[0062] S100. Receive a data synchronization request initiated by the master node.

[0063] S200. Determine the synchronization mode, and back up the synchronization data to be transmitted according to the synchronization mode. In this embodiment, the synchronization mode mainly includes two modes: full synchronization and incremental synchronization. In the full synchronization mode, all data is synchronized; in the incremental synchronization mode, the data that has changed since the last synchronization is synchronized.

[0064] S300. Request to obtain key data and usage permissions. In this step, after receiving the key request, the key provider needs to perform permission verification (i.e., check the identity of the requester and whether it has the permission to use the corresponding key). If the permission passes the verification, the key management module will grant the data management module the permission to use the key and return the key data; otherwise, an error message will be returned.

[0065] S400. Encrypt the backed-up data using the key data. In this step, the national cryptography SM4 block cipher algorithm is used to encrypt the backed-up data; the national cryptography SM3 cryptographic hash algorithm is used to perform a Hash operation on the backed-up data to generate the Hash value of the data; the national cryptography SM2 elliptic curve public key cryptography algorithm is used to perform a digital signature on the backed-up data; the ciphertext, Hash value, and signature value of the backed-up data are integrated, and data splicing is performed to complete the encryption process of the backed-up data.

[0066] S500. Respond to the master node data synchronization request, and notify the master node to synchronize the encrypted data to the slave node. In this step, an SSL secure channel is established between the master node and the slave node to achieve the transmission of synchronization data.

[0067] In the national cryptography algorithm-based cluster data security synchronization method proposed by the present invention, after receiving the synchronization data, the slave node also needs to verify the data integrity and source, that is, verify the Hash value and signature value in the synchronization data. If the verification passes, the slave node will perform data recovery; if the verification fails, an error message will be returned.

[0068] The present invention provides a method and system for secure synchronization of cluster data based on national cryptographic algorithms, constructing a multi-level and highly reliable technical architecture that covers multiple key modules such as data synchronization, control management, key management, and data management. These modules cooperate with each other to jointly ensure the stable operation of the system and the security of data, providing users with efficient and reliable data synchronization. The present invention not only improves the security of server cluster data synchronization but also ensures the high availability of cluster services. This enables the entire server cluster to still operate stably and provide reliable services in the face of large-scale concurrent access and complex network environments.

[0069] For those of ordinary skill in the art, the specific meanings of the above terms can be understood according to specific circumstances; the accompanying drawings in the embodiments are used to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are some, but not all, of the embodiments of the present invention. Usually, the components of the embodiments of the present invention described and shown in the drawings here can be arranged and designed in various different configurations.

[0070] Although the embodiments of the present application have been shown and described above, it can be understood that the above embodiments are exemplary and should not be construed as limiting the present application. Those of ordinary skill in the art can make changes, modifications, substitutions, and variations to the above embodiments within the scope of the present application.

Claims

1. A cluster data security synchronization system based on national cryptographic algorithms, characterized in that, It includes: The master-slave data synchronization module is used to receive the data synchronization request from the master node, determine the synchronization mode and initiate a data backup request; And receive the encrypted data returned by the data management and synchronize it to the slave node; The data management module is used to initiate a key request and complete the synchronization data backup and encryption process according to the returned key data, and return the encrypted synchronization data to the master-slave data synchronization module; The key management module is used to return the key data and usage permissions according to the key request; The master-slave control module is used to complete the configuration of the master and slave nodes.

2. The cluster data security synchronization system based on the national cryptographic algorithm according to claim 1, characterized in that, In the master-slave data synchronization module, the synchronization mode includes full synchronization and incremental synchronization.

3. The cluster data security synchronization system based on the national cryptographic algorithm according to claim 1 or 2, characterized in that In the data management module, the synchronization data backup process includes: Receive a data backup request; According to the determined synchronization mode, select the corresponding data to perform the data backup operation.

4. The cluster data security synchronization system based on the national cryptographic algorithm according to claim 1 or 2, characterized in that, The specific working process of the key management module includes: Verify the permissions of the requester. If the permissions pass the verification, the key management module will grant the data management module the permission to use the key and return the key data; otherwise, an error message will be returned.

5. The cluster data security synchronization system based on the national cryptographic algorithm according to claim 1, characterized in that In the data management module, the encryption process: Receive the key data; Use the national cipher SM4 block cipher algorithm to encrypt the backup data; Use the national cipher SM3 cryptographic hash algorithm to perform a Hash operation on the backup data to generate the Hash value of the data; Use the national cipher SM2 elliptic curve public key cipher algorithm to perform a digital signature on the backup data; Integrate the ciphertext, Hash value and signature value of the backup data, and perform data splicing, and return the spliced data to the master-slave data synchronization module.

6. The cluster data security synchronization system based on the national cryptographic algorithm according to claim 1, characterized in that Data synchronization between the master node and the slave node is carried out through the national cipher SSL secure channel.

7. The cluster data security synchronization system based on the national cryptographic algorithm according to claim 1, characterized in that It also includes that after the slave node receives the data, it verifies the Hash value and signature value in the synchronization data. If the verification passes, the slave node will perform data recovery; if the verification fails, an error message will be returned.

8. A method for secure synchronization of cluster data based on national cryptographic algorithms, characterized in that, It includes: Receive the data synchronization request initiated by the master node; Determine the synchronization mode, and back up the synchronization data to be transmitted according to the synchronization mode; Request to obtain the key data and usage permissions; Use the key data to encrypt the backed-up data; In response to the master node data synchronization request, notify the master node to synchronize the encrypted data to the slave node.

9. The method for secure synchronization of cluster data based on national cryptographic algorithm according to claim 8, characterized in that, The use of the key data to encrypt the backed-up data specifically includes: Receive the key data; Use the national cipher SM4 block cipher algorithm to encrypt the backup data; Use the national cipher SM3 cryptographic hash algorithm to perform a Hash operation on the backup data to generate the Hash value of the data; Use the national cipher SM2 elliptic curve public key cipher algorithm to perform a digital signature on the backup data; Integrate the ciphertext, Hash value and signature value of the backup data, and perform data splicing to complete the encryption process of the backup data.

10. The method for secure synchronization of cluster data based on national cryptographic algorithm according to claim 8, wherein, It also includes that after the slave node receives the data, it verifies the Hash value and signature value in the synchronization data. If the verification passes, the slave node will perform data recovery; if the verification fails, an error message will be returned.