Distributed cache data encryption method and device, electronic equipment and storage medium

By using hash values and encryption methods in the distributed cache system to encrypt data, generate encrypted information and send it to the server, the problem of difficult security of cached data is solved, and the encrypted storage and access of data is realized to prevent data leakage and tampering.

CN120342765APending Publication Date: 2025-07-18AGRICULTURAL BANK OF CHINA
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510705526.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-29
Publication Date
2025-07-18

AI Technical Summary

Technical Problem

The data security of distributed cache systems is difficult to effectively guarantee, especially when multiple systems share the same distributed cache for information, cached data is easily leaked, stolen or tampered with.

Method used

By obtaining the information of the distributed cache client, determining the hash value recorded in the configuration information and data encryption method, encrypting the data, and generating new information containing the encrypted data, sending it to the server to perform response operations, ensuring that the data is in an encrypted state on the server.

Benefits of technology

The data encryption of the distributed cache server is realized, avoiding the problems of low complexity and poor protection of a single encryption method, ensuring data security, preventing encryption methods from leaking, and ensuring the security of cached data.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120342765A_ABST
    Figure CN120342765A_ABST
Patent Text Reader

Abstract

The invention discloses a distributed cache data encryption method and device, electronic equipment and a storage medium. The method comprises the following steps: acquiring first information sent by a distributed cache client; determining first configuration information, wherein a preset number of first hash values and a data encryption mode corresponding to each first hash value are recorded in the first configuration information; the first data is encrypted based on the first configuration information to obtain second data, second information is determined based on the first information and the second data, and the second information is composed of the second data and parts, except the first data, in the first information; and sending the second information to the distributed cache server, so that the distributed cache server executes a response operation corresponding to the second information. According to the scheme, the distributed cache server performs the data access operation based on the second data contained in the second information, so that the security of the cache data stored in the distributed cache server is effectively guaranteed.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of distributed caching, and in particular, to a method, device, electronic device and storage medium for encrypting distributed cache data. Background Art

[0002] High-performance caches can be used for high-speed data caching, status information synchronization, information sharing, etc. between distributed systems, and play an important role in improving the performance and stability of distributed systems. Distributed caches are one of the representatives of high-performance caches. With the increasingly diversified deployment modes of distributed cache systems, each component of the distributed cache system is deployed relatively dispersedly at various locations. However, the network security environment of the deployment location of the distributed cache system is relatively complex. If the distributed cache system is located in an insecure location, especially in the scenario where multiple systems share the same distributed cache for information sharing, there are many access parties, and the cached data is easily leaked, stolen or tampered with, resulting in difficulty in ensuring the security of the distributed cache data. Summary of the Invention

[0003] The present invention provides a method, device, electronic device and storage medium for encrypting distributed cache data to solve the problem that the security of distributed cache data is difficult to effectively guarantee.

[0004] According to one aspect of the present invention, a method for encrypting distributed cache data is provided. The method includes:

[0005] Obtain a first piece of information sent by a distributed cache client. The first piece of information is used to indicate a data access operation on cached data stored in a distributed cache server based on first data included in the first piece of information, and the first data includes a cached data name;

[0006] Determine first configuration information, in which a preset number of first hash values and data encryption methods respectively corresponding to each first hash value are recorded;

[0007] Encrypt the first data based on the first configuration information to obtain second data, and determine second information based on the first piece of information and the second data. The second information is composed of the part other than the first data in the first piece of information and the second data;

[0008] Send the second piece of information to the distributed cache server so that the distributed cache server performs a response operation corresponding to the second piece of information.

[0009] According to another aspect of the present invention, a device for encrypting distributed cache data is provided. The device includes:

[0010] A first acquisition module, configured to acquire first information sent by a distributed cache client, where the first information is used to indicate a data access operation on cache data stored in a distributed cache server based on first data included in the first information, and the first data includes a cache data name;

[0011] A first determination module, configured to determine first configuration information, where the first configuration information records a preset number of first hash values and data encryption methods respectively corresponding to each first hash value;

[0012] A second determination module, configured to encrypt the first data based on the first configuration information to obtain second data, and determine second information based on the first information and the second data, where the second information is composed of a part of the first information other than the first data and the second data;

[0013] A first sending module, configured to send the second information to the distributed cache server, so that the distributed cache server performs a response operation corresponding to the second information.

[0014] According to another aspect of the present invention, there is provided an electronic device, which includes:

[0015] At least one processor; and a memory communicatively connected to the at least one processor; wherein, the memory stores a computer program executable by the at least one processor, and when the computer program is executed by the at least one processor, the at least one processor is enabled to execute the distributed cache data encryption method according to any embodiment of the present invention.

[0016] According to another aspect of the present invention, there is provided a computer-readable storage medium, which stores computer instructions for enabling a processor to implement the distributed cache data encryption method according to any embodiment of the present invention when executed.

[0017] The technical solution of the embodiment of the present invention obtains the first information sent by the distributed cache client; determines the first configuration information, which records a preset number of first hash values and the data encryption methods corresponding to each first hash value respectively; encrypts the first data based on the first configuration information to obtain the second data, and determines the second information based on the first information and the second data. The second information is composed of the part of the first information other than the first data and the second data. It realizes encrypting the first data through the data encryption methods recorded in the first configuration information. Different data encryption methods corresponding to different first hash values in the first configuration information enable different data encryption methods to be used for different first data, thereby avoiding the problems of low encryption complexity and poor data protection of a single data encryption method; at the same time, the second information contains the encrypted second data, so that only the corresponding operation instructions can be obtained through the second information, and the actual access data cannot be obtained; sending the second information to the distributed cache server to enable the distributed cache server to execute the response operation corresponding to the second information realizes that the distributed cache server performs data access operations based on the second data included in the second information, so that the cached or returned data of the distributed cache server is in an encrypted state; at the same time, the data encryption method is independently stored in the first configuration information, which can avoid the leakage of the data encryption method corresponding to the cached data stored in the distributed cache server, thus effectively ensuring the security of the cached data.

[0018] It should be understood that the content described in this part is not intended to identify the key or important features of the embodiments of the present invention, nor is it used to limit the scope of the present invention. Other features of the present invention will become easily understood through the following description. BRIEF DESCRIPTION OF THE DRAWINGS

[0019] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained based on these drawings.

[0020] Figure 1 It is a flowchart of a distributed cache data encryption method provided by an embodiment of the present invention;

[0021] Figure 2 It is a flowchart of another distributed cache data encryption method provided by an embodiment of the present invention;

[0022] Figure 3 It is a structural schematic diagram of a distributed cache data encryption device provided by an embodiment of the present invention;

[0023] Figure 4Schematic diagram of another distributed cache data encryption device provided by an embodiment of the present invention;

[0024] Figure 5 Schematic diagram of a distributed cache system provided by an embodiment of the present invention;

[0025] Figure 6 Schematic diagram of an electronic device for implementing a distributed cache data encryption method provided by an embodiment of the present invention. Detailed implementation manners

[0026] In order to enable those skilled in the art to better understand the solution of the present invention, the technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.

[0027] It should be noted that the terms "first", "second", etc. in the specification and claims of the present invention and the above-mentioned drawings are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequence. It should be understood that the data used in this way can be interchanged under appropriate circumstances, so that the embodiments of the present invention described here can be implemented in an order other than those illustrated or described here. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product or device including a series of steps or units is not necessarily limited to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products or devices.

[0028] Figure 1 Flowchart of a distributed cache data encryption method provided by an embodiment of the present invention. The embodiment of the present invention is applicable to the situation where the data included in the instruction sent by the distributed cache client is encrypted and then sent to the distributed cache server. This method can be executed by a distributed cache data encryption device, which can be implemented in the form of hardware and / or software and can be configured in an electronic device for implementing the distributed cache data encryption method. As Figure 1 shown, the distributed cache data encryption method includes:

[0029] S101. Obtain first information sent by the distributed cache client, where the first information is used to indicate a data access operation on the cache data stored in the distributed cache server based on first data included in the first information, and the first data includes a cache data name.

[0030] Among them, a distributed cache can provide an efficient and scalable data caching service by storing cached data on at least two service nodes. A distributed cache client can refer to the access party of the distributed cache. A distributed cache server can refer to the service party of the distributed cache. The distributed cache server stores cached data and can provide cache read and write services to the distributed cache client. The cached data of the distributed cache server is stored in the form of key-value pairs (K-V). The Key can refer to the cached data name. The Value can refer to the cached data value. The data access operation at least includes a data read operation and a data write operation.

[0031] The first information can refer to a distributed cache instruction for implementing data reading and writing. Based on the first information, the specific data access operation to be performed on the distributed cache server can be determined. Based on the first data included in the first information, the cached data involved in performing the data access operation on the distributed cache server can be determined.

[0032] S102. Determine the first configuration information, which records a preset number of first hash values and the data encryption method corresponding to each first hash value respectively.

[0033] Among them, the preset number of first hash values can be obtained through a hash algorithm. The hash algorithm can refer to a pre-set mathematical function that can map any input data to a hash value. The limited number of hash values output by the hash algorithm can be used as the preset number of first hash values. Data encryption can refer to converting the first data into an unreadable or difficult-to-understand form to prevent the first data from being leaked or tampered with. The data encryption method corresponding to the first hash value can refer to the specific method used for data encryption of the first data when preset. Different data encryption methods corresponding to different first hash values can avoid the problems of low encryption complexity and poor data protection of a single data encryption method when encrypting the first data.

[0034] S103. Encrypt the first data based on the first configuration information to obtain the second data, and determine the second information based on the first information and the second data. The second information is composed of the part of the first information other than the first data and the second data.

[0035] Among them, encrypting the first data can refer to encrypting the cached data name included in the first data. At the same time, if the first data also includes a cached data value, the same encryption is performed on the cached data value included in the first data. The same data encryption method is used for different first data containing the same cached data name, so that the different second data obtained contain the same encrypted cached data name, thus ensuring that the distributed cache server performs accurate response operations based on the second information.

[0036] Specifically, the first data can be encrypted by a data encryption method recorded in the first configuration information to obtain second data corresponding to the first data. Furthermore, the second information is obtained by replacing the first data included in the first information with the second data, so that the second information instructs to perform the same data access operation on the distributed cache server as that instructed by the first information.

[0037] S104. Send the second information to the distributed cache server so that the distributed cache server performs a response operation corresponding to the second information.

[0038] Among them, the response operation corresponding to the second information may refer to, after the distributed cache server receives the second information, performing a data access operation on the cached data stored in the distributed cache server based on the second data included in the second information, so that all the cached data stored in the distributed cache server is encrypted to improve the security of the cached data.

[0039] As an alternative implementation manner of the embodiment of the present invention, the instruction types of the first information and the second information belong to the read instruction type or the write instruction type.

[0040] Specifically, the second information is obtained by replacing the first data included in the first information with the second data, so that the instruction types of the first information and the second information are the same. When the first information belongs to the read instruction type, the first data only includes the cached data name, and the second data only includes the encrypted cached data name. When the first information belongs to the write instruction type, the first data includes the cached data name and the cached data value, and the second data includes the encrypted cached data name and the encrypted cached data value.

[0041] As an alternative implementation manner of the embodiment of the present invention, after sending the second information to the distributed cache server, the following steps A1 - A2 are included:

[0042] Step A1. If the instruction type of the second information belongs to the write instruction type, store the second data in the distributed cache server.

[0043] Step A2. If the instruction type of the second information belongs to the read instruction type, determine the third data corresponding to the second data in the distributed cache server, and decrypt the third data based on the data encryption method corresponding to the first data and send it to the distributed cache client. The third data is the encrypted cached data value corresponding to the encrypted cached data name included in the second data.

[0044] Specifically, when the instruction type of the second information belongs to the write instruction type, the second information instructs to perform a data write operation on the distributed cache server. Furthermore, store the encrypted cached data name and the encrypted cached data value included in the second information in the distributed cache server.

[0045] When the instruction type of the second information belongs to the read instruction type, the second information instructs to perform a data reading operation on the distributed cache server. Further, the encrypted cache data value corresponding to the encrypted cache data name included in the second information is searched for in the distributed cache server as the third data.

[0046] The technical solution of the embodiment of the present invention obtains the first information sent by the distributed cache client; determines the first configuration information, which records a preset number of first hash values and the data encryption methods respectively corresponding to each first hash value; encrypts the first data based on the first configuration information to obtain the second data, and determines the second information based on the first information and the second data. The second information is composed of the part of the first information except the first data and the second data. By doing so, it realizes encrypting the first data through the data encryption methods recorded in the first configuration information. Different data encryption methods corresponding to different first hash values in the first configuration information enable different data encryption methods to be used for different first data, thus avoiding the problems of low encryption complexity and poor data protection of a single data encryption method. At the same time, the second information contains the encrypted second data, so that only the corresponding operation instruction can be obtained through the second information, and the actual access data cannot be obtained. The second information is sent to the distributed cache server so that the distributed cache server performs the response operation corresponding to the second information, realizing that the distributed cache server performs data access operations based on the second data included in the second information, making the cached or returned data of the distributed cache server in an encrypted state. At the same time, the data encryption method is independently stored in the first configuration information, which can avoid the leakage of the data encryption method corresponding to the cached data stored in the distributed cache server, thus effectively ensuring the security of the cached data.

[0047] Figure 2 It is a flowchart of another distributed cache data encryption method provided by the embodiment of the present invention. The technical solution of this embodiment further optimizes the process of encrypting the first data based on the first configuration information to obtain the second data in the technical solution of the foregoing embodiment. The solutions not described in detail in this embodiment can be seen in the foregoing embodiment, and this embodiment can be combined with various alternative solutions in the above one or more embodiments. As Figure 2 shown, the distributed cache data encryption method includes:

[0048] S201. Obtain the first information sent by the distributed cache client. The first information is used to instruct to perform a data access operation on the cached data stored in the distributed cache server based on the first data included in the first information, and the first data includes the cache data name.

[0049] S202. Determine the first configuration information, which records a preset number of first hash values and the data encryption methods respectively corresponding to each first hash value.

[0050] S203. Determine the data encryption method corresponding to the first data in the first configuration information.

[0051] Specifically, a first hash value associated with the first data can be determined in the first configuration information. Further, the data encryption method corresponding to the first hash value associated with the first data in the first configuration information can be used as the data encryption method corresponding to the first data.

[0052] As an alternative implementation manner of the embodiment of the present invention, determining the data encryption method corresponding to the first data in the first configuration information includes: determining the hash algorithm corresponding to the first hash value; determining the second hash value corresponding to the first data based on the hash algorithm, where the second hash value is the hash value of the cache data name included in the first data; determining the data encryption method corresponding to the first data in the first configuration information based on the second hash value.

[0053] Wherein, the second hash value may refer to the hash value obtained by inputting the cache data name included in the first data into the hash algorithm corresponding to the first hash value. The preset number of first hash values is a limited number of hash values output by a hash algorithm, such that there is a first hash value identical to the second hash value among the preset number of first hash values. Further, the data encryption method corresponding to the first hash value identical to the second hash value in the first configuration information can be used as the data encryption method corresponding to the first data.

[0054] S204. Encrypt the first data based on the data encryption method corresponding to the first data to obtain the second data.

[0055] Specifically, encrypt the cache data name included in the first data through the data encryption method corresponding to the first data, and use the encrypted cache data name as the second data. If the first data further includes a cache data value, encrypt the cache data value included in the first data through the data encryption method corresponding to the first data, and use the encrypted cache data name and the encrypted cache data value as the second data.

[0056] As an alternative implementation manner of the embodiment of the present invention, the data encryption method corresponding to the first hash value is determined by an encryption algorithm, a key, and a salt value. Exemplarily, the first configuration information can be as shown in Table 1.

[0057] Table 1 First configuration information

[0058] First Hash Value 1 Encryption Algorithm 1 Encryption Key 1 Salt Value 1 First Hash Value 2 Encryption Algorithm 1 Encryption Key 2 Salt Value 2 First Hash Value 3 Encryption Algorithm 2 Encryption Key 1 Salt Value 3 First Hash Value 4 Encryption Algorithm 2 Encryption Key 2 Salt Value 4

[0059] Among them, the encryption algorithm may refer to a mathematical function that converts plaintext into ciphertext. The key may refer to a key parameter in the encryption algorithm. The salt value may refer to a randomly generated fixed-length string. Furthermore, when encrypting the first data through the data encryption method corresponding to the first data, the salt value can be added to the first data, and the encrypted algorithm and the key are used to encrypt the first data with the added salt value to obtain the second data. When decrypting the third data through the data encryption method corresponding to the first data, the encrypted algorithm and the key are used to decrypt the third data, and then the salt value is removed to obtain the decryption data corresponding to the third data.

[0060] S205. Determine the second information based on the first information and the second data. The second information is composed of the part of the first information other than the first data and the second data.

[0061] S206. Send the second information to the distributed cache server so that the distributed cache server performs the response operation corresponding to the second information.

[0062] As an optional implementation manner of the embodiment of the present invention, the distributed cache server is composed of a main node and at least one slave node. The main node is used to perform the response operation corresponding to the second information, and each slave node in the at least one slave node is used to synchronize the cache data in the main node.

[0063] Among them, the distributed cache server may refer to a distributed cache cluster composed of a distributed cache main node and slave nodes. The main node is used to provide services to the distributed cache client and send the synchronized cache data to the slave nodes. The slave node is used to receive the synchronized cache data sent by the main node and promote to the main node when the main node cannot provide services.

[0064] As an optional implementation manner of the embodiment of the present invention, sending the second information to the distributed cache server includes: determining the second configuration information, where the second configuration information records the configuration information of each node in the distributed cache server, and the configuration information of the node is used to indicate whether the node is the main node or the slave node; and sending the second information to the main node of the distributed cache server based on the second configuration information.

[0065] Among them, the second configuration information can be determined based on the distributed cache cluster topology corresponding to the distributed cache server, and when the master-slave switch occurs in the distributed cache cluster, the second configuration information is updated in a timely manner. The configuration information of a node may include the IP address, port information, access password, and node identifier of the node. The node identifier is used to indicate whether the node is a master node or a slave node. The IP address, port information, and access password of the node are used to establish a communication connection with the node. Furthermore, based on the configuration information of the master node recorded in the second configuration information, the second information can be sent to the master node of the distributed cache server, or the third data returned by the master node of the distributed cache server can be received.

[0066] The technical solution of the embodiment of the present invention realizes the association of the first data with the data encryption method in the first configuration information by obtaining the first information sent by the distributed cache client, determining the first configuration information, where the first configuration information records a preset number of first hash values and the data encryption method corresponding to each first hash value respectively, and determining the data encryption method corresponding to the first data in the first configuration information; determines the second information based on the first information and the second data, where the second information is composed of the part of the first information other than the first data and the second data, so that only the corresponding operation instruction can be obtained through the second information, and the actual access data cannot be obtained; sends the second information to the distributed cache server so that the distributed cache server executes the response operation corresponding to the second information, realizing that the distributed cache server performs data access operations based on the second data included in the second information, so that the cached or returned data of the distributed cache server is in an encrypted state; at the same time, the data encryption method is independently stored in the first configuration information, which can prevent the data encryption method corresponding to the cached data stored in the distributed cache server from being leaked, thus effectively ensuring the security of the cached data.

[0067] Figure 3 It is a schematic structural diagram of a distributed cache data encryption device provided by an embodiment of the present invention. The embodiment of the present invention is applicable to the situation where the data included in the instruction sent by the distributed cache client is encrypted and then sent to the distributed cache server, and the device can be implemented in the form of hardware and / or software. As Figure 3 shown, the distributed cache data encryption device includes:

[0068] A first acquisition module 301, configured to acquire the first information sent by the distributed cache client, where the first information is used to indicate a data access operation on the cached data stored in the distributed cache server based on the first data included in the first information, and the first data includes the cached data name;

[0069] The first determination module 302 is configured to determine first configuration information, where the first configuration information records a preset number of first hash values and the data encryption method corresponding to each first hash value respectively;

[0070] The second determination module 303 is configured to encrypt the first data based on the first configuration information to obtain second data, and determine second information based on the first information and the second data, where the second information is composed of the part of the first information except the first data and the second data;

[0071] The first sending module 304 is configured to send the second information to the distributed cache server so that the distributed cache server performs the response operation corresponding to the second information.

[0072] Based on any of the above optional technical solutions, optionally, the second determination module 303 includes: a third determination unit and a fourth determination unit. Among them, the third determination unit is configured to determine the data encryption method corresponding to the first data in the first configuration information; the fourth determination unit is configured to encrypt the first data based on the data encryption method corresponding to the first data to obtain second data.

[0073] Based on any of the above optional technical solutions, optionally, the third determination unit is specifically configured to determine the hash algorithm corresponding to the first hash value; determine the second hash value corresponding to the first data based on the hash algorithm, where the second hash value is the hash value of the cache data name included in the first data; determine the data encryption method corresponding to the first data in the first configuration information based on the second hash value.

[0074] Based on any of the above optional technical solutions, optionally, the data encryption method corresponding to the first hash value is determined by an encryption algorithm, a key, and a salt value.

[0075] Based on any of the above optional technical solutions, optionally, the instruction types of the first information and the second information belong to the read instruction type or the write instruction type.

[0076] Based on any of the above optional technical solutions, optionally, the distributed cache data encryption device further includes: a data access module. Among them, the data access module is configured to, after sending the second information to the distributed cache server, if the instruction type of the second information belongs to the write instruction type, store the second data in the distributed cache server; if the instruction type of the second information belongs to the read instruction type, determine the third data corresponding to the second data in the distributed cache server, and decrypt the third data based on the data encryption method corresponding to the first data and send it to the distributed cache client, where the third data is the encrypted cache data value corresponding to the encrypted cache data name included in the second data.

[0077] Based on any of the above optional technical solutions, optionally, the distributed cache server is composed of a master node and at least one slave node. The master node is used to execute the response operation corresponding to the second information, and each of the at least one slave node is used to synchronize the cache data in the master node.

[0078] Based on any of the above optional technical solutions, optionally, the first sending module 304 includes: a fifth determining unit and a second sending unit. The fifth determining unit is used to determine the second configuration information, and the second configuration information records the configuration information of each node in the distributed cache server. The configuration information of the node is used to indicate whether the node is a master node or a slave node. The second sending unit is used to send the second information to the master node of the distributed cache server based on the second configuration information.

[0079] Exemplarily, Figure 4 FIG. is a schematic structural diagram of another distributed cache data encryption device provided by an embodiment of the present invention. As Figure 4 shown, the distributed cache data encryption device includes: a parsing unit, an encryption / decryption unit, and an access unit. The parsing unit is used to receive the first information sent by the distributed cache client, parse the first information to determine the instruction type of the first information, and thus determine the first data included in the first information. The encryption / decryption unit is used to determine the data encryption method corresponding to the first data, and encrypt the first data based on the data encryption method corresponding to the first data to obtain the second data. The parsing unit is further used to determine the second information based on the first information and the second data. The access unit is used to perform information interaction with the distributed cache server, send the second information to the distributed cache server, or receive the third data returned by the distributed cache server. The encryption / decryption unit is further used to decrypt the third data based on the data encryption method corresponding to the first data.

[0080] The parsing unit includes: a command analyzer, an encryption executor, and a data forwarder. The command analyzer is used to parse the first information to determine the first data. The encryption executor is used to call the encryption / decryption unit to encrypt the first data to obtain the second data. The data forwarder is used to forward the second information to the access unit.

[0081] The encryption / decryption unit includes: an encryptor and a decryptor. The encryptor is used to encrypt the first data based on the encryption algorithm library and the first configuration information. The decryptor is used to decrypt the third data based on the encryption algorithm library and the first configuration information.

[0082] The access unit includes: a configuration memory, a cluster detector, and a data transceiver. Among them, the configuration memory is used to store second configuration information; the cluster detector is used to periodically detect the master-slave node change information of the distributed cache server and synchronize it to the configuration memory to update the second configuration information; the data transceiver is used to interact with the master node of the distributed cache server for information.

[0083] Exemplarily, Figure 5 is a schematic structural diagram of a distributed cache system provided by an embodiment of the present invention. As Figure 5 shown, the distributed cache system includes: a distributed cache client, the distributed cache data encryption device of any embodiment of the present invention, and a distributed cache server. The distributed cache client is connected to the distributed cache server through the distributed cache data encryption device.

[0084] Among them, the distributed cache client is used to send first information to the distributed cache data encryption device;

[0085] The distributed cache data encryption device is used to obtain the first information sent by the distributed cache client. The first information is used to indicate a data access operation on the cache data stored in the distributed cache server based on the first data included in the first information. The first data includes the cache data name; determine the first configuration information, where the first configuration information records a preset number of first hash values and the data encryption method corresponding to each first hash value; encrypt the first data based on the first configuration information to obtain second data, and determine second information based on the first information and the second data. The second information is composed of the part of the first information except the first data and the second data; send the second information to the distributed cache server so that the distributed cache server performs the response operation corresponding to the second information;

[0086] The distributed cache server is used to receive the second information sent by the distributed cache data encryption device and perform the response operation corresponding to the second information.

[0087] In the technical solution of the embodiment of the present invention, the first acquisition module 301 acquires the first information sent by the distributed cache client; the first determination module 302 determines the first configuration information, in which a preset number of first hash values and the data encryption methods respectively corresponding to each first hash value are recorded; the second determination module 303 encrypts the first data based on the first configuration information to obtain the second data, and determines the second information based on the first information and the second data. The second information is composed of the part other than the first data in the first information and the second data. By encrypting the first data with the data encryption methods recorded in the first configuration information, and different data encryption methods corresponding to different first hash values in the first configuration information, different data encryption methods can be used for different first data, thus avoiding the problems of low encryption complexity and poor data protection of a single data encryption method; at the same time, the second information contains the encrypted second data, so that only the corresponding operation instructions can be obtained through the second information, and the actual access data cannot be obtained; the first sending module 304 sends the second information to the distributed cache server, so that the distributed cache server executes the response operation corresponding to the second information, realizing that the distributed cache server performs data access operations based on the second data included in the second information, so that the cached or returned data of the distributed cache server is in an encrypted state; at the same time, the data encryption method is independently stored in the first configuration information, which can avoid the leakage of the data encryption method corresponding to the cached data stored by the distributed cache server, thus effectively ensuring the security of the cached data.

[0088] The distributed cache data encryption device provided by the embodiment of the present invention can execute the distributed cache data encryption method provided by any embodiment of the present invention, and has the corresponding functional modules and beneficial effects for executing the method.

[0089] Figure 6 It is a schematic structural diagram of an electronic device for implementing a distributed cache data encryption method provided by an embodiment of the present invention. The electronic device is intended to represent various forms of digital computers, such as, laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as, personal digital processors, cellular phones, smart phones, wearable devices (such as helmets, glasses, watches, etc.) and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely examples and are not intended to limit the implementation of the present invention described and / or claimed herein.

[0090] Such as Figure 6As shown, the electronic device 10 includes at least one processor 11 and a memory communicatively connected to the at least one processor 11, such as a read-only memory (ROM) 12, a random access memory (RAM) 13, etc. The memory stores a computer program executable by the at least one processor. The processor 11 can execute various appropriate actions and processes according to the computer program stored in the read-only memory (ROM) 12 or the computer program loaded from the storage unit 18 into the random access memory (RAM) 13. In the RAM 13, various programs and data required for the operation of the electronic device 10 can also be stored. The processor 11, the ROM 12, and the RAM 13 are connected to each other through a bus 14. An input / output (I / O) interface 15 is also connected to the bus 14.

[0091] Multiple components in the electronic device 10 are connected to the I / O interface 15, including: an input unit 16, such as a keyboard, a mouse, etc.; an output unit 17, such as various types of displays, speakers, etc.; a storage unit 18, such as a disk, an optical disc, etc.; and a communication unit 19, such as a network card, a modem, a wireless communication transceiver, etc. The communication unit 19 allows the electronic device 10 to exchange information / data with other devices through a computer network such as the Internet and / or various telecommunication networks.

[0092] The processor 11 can be various general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of the processor 11 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various dedicated artificial intelligence (AI) computing chips, various processors running machine learning model algorithms, a digital signal processor (DSP), and any appropriate processor, controller, microcontroller, etc. The processor 11 executes the various methods and processes described above, such as the distributed cache data encryption method.

[0093] In particular, according to an embodiment of the present invention, the process described above with reference to the flowchart can be implemented as a computer software program. For example, an embodiment of the present invention includes a computer program product, which includes a computer program carried on a non-transitory computer-readable medium. The computer program includes program code for executing the method shown in the flowchart. In such an embodiment, the computer program can be downloaded and installed from the network through the communication unit 19, or installed from the storage unit 18, or installed from the ROM 12. When the computer program is executed by the processor 11, the above functions defined in the method of the embodiment of the present invention are executed.

[0094] In some embodiments, the distributed cache data encryption method may be implemented as a computer program tangibly embodied in a computer-readable storage medium, such as storage unit 18. In some embodiments, part or all of the computer program may be loaded and / or installed onto the electronic device 10 via the ROM 12 and / or the communication unit 19. When the computer program is loaded into the RAM 13 and executed by the processor 11, one or more steps of the distributed cache data encryption method described above may be performed. Alternatively, in other embodiments, the processor 11 may be configured to execute the distributed cache data encryption method by any other suitable means (e.g., by means of firmware).

[0095] Various embodiments of the systems and techniques described above in this document can be implemented in digital electronic circuitry, integrated circuit systems, field programmable gate arrays (FPGA), application specific integrated circuits (ASIC), application specific standard products (ASSP), systems on a chip (SOC), complex programmable logic devices (CPLD), computer hardware, firmware, software, and / or combinations thereof. These various embodiments can include: implemented in one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, which can be a special-purpose or general-purpose programmable processor that can receive data and instructions from a storage system, at least one input device, and at least one output device, and transmit the data and instructions to the storage system, the at least one input device, and the at least one output device.

[0096] The computer program for implementing the method of the present invention can be written in any combination of one or more programming languages. These computer programs can be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device, such that when the computer program is executed by the processor, the functions / operations specified in the flowchart and / or block diagram are implemented. The computer program can be executed entirely on the machine, partially on the machine, as a stand-alone software package partially on the machine and partially on a remote machine, or entirely on a remote machine or server.

[0097] In the context of the present invention, a computer-readable storage medium can be a tangible medium that can contain or store a computer program for use by or in connection with an instruction execution system, apparatus, or device. The computer-readable storage medium can include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatuses, or devices, or any suitable combination of the foregoing. Alternatively, the computer-readable storage medium can be a machine-readable signal medium. More specific examples of the machine-readable storage medium would include an electrical connection based on one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.

[0098] To provide for interaction with a user, the systems and techniques described herein can be implemented on an electronic device having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and a pointing device (e.g., a mouse or a trackball) by which the user can provide input to the electronic device. Other kinds of devices can also be used to provide for interaction with the user; for example, feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including acoustic, speech, or tactile input).

[0099] The systems and techniques described herein can be implemented in a computing system that includes backend components (e.g., as a data server), or a computing system that includes middleware components (e.g., an application server), or a computing system that includes frontend components (e.g., a user computer having a graphical user interface or a web browser through which the user can interact with an implementation of the systems and techniques described herein), or a computing system that includes any combination of such backend components, middleware components, or frontend components. The components of the system can be interconnected by any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include: a local area network (LAN), a wide area network (WAN), a blockchain network, and the Internet.

[0100] A computing system may include a client and a server. The client and the server are generally far from each other and usually interact via a communication network. The relationship between the client and the server is created by computer programs running on respective computers and having a client-server relationship with each other. The server may be a cloud server, also known as a cloud computing server or a cloud host, which is a host product in the cloud computing service system, solving the defects of difficult management and weak business scalability existing in traditional physical hosts and VPS services.

[0101] It should be understood that various forms of the processes shown above can be used, steps can be reordered, added or deleted. For example, the steps recited in the present invention can be executed in parallel, sequentially or in a different order, as long as the desired results of the technical solution of the present invention can be achieved, and no limitation is made herein.

[0102] The above specific embodiments do not constitute a limitation on the protection scope of the present invention. Those skilled in the art should understand that various modifications, combinations, sub-combinations and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions and improvements made within the spirit and principle of the present invention shall be included within the protection scope of the present invention.

Claims

1. A distributed cache data encryption method, characterized in that, The method includes: Obtaining first information sent by a distributed cache client, where the first information is used to indicate a data access operation on cache data stored in a distributed cache server based on first data included in the first information, and the first data includes a cache data name; Determining first configuration information, where a preset number of first hash values and data encryption methods respectively corresponding to each first hash value are recorded in the first configuration information; Encrypting the first data based on the first configuration information to obtain second data, and determining second information based on the first information and the second data, where the second information is composed of the part of the first information other than the first data and the second data; Sending the second information to the distributed cache server so that the distributed cache server performs a response operation corresponding to the second information.

2. The method according to claim 1, wherein Encrypting the first data based on the first configuration information to obtain second data, including: Determining the data encryption method corresponding to the first data in the first configuration information; Encrypting the first data based on the data encryption method corresponding to the first data to obtain the second data.

3. The method according to claim 2, characterized in that, Determining the data encryption method corresponding to the first data in the first configuration information, including: Determining a hash algorithm corresponding to the first hash value; Determining a second hash value corresponding to the first data based on the hash algorithm, where the second hash value is a hash value of the cache data name included in the first data; Determining the data encryption method corresponding to the first data in the first configuration information based on the second hash value.

4. The method according to claim 1, wherein The data encryption method corresponding to the first hash value is determined by an encryption algorithm, a key, and a salt value.

5. The method according to claim 1, wherein The instruction types of the first information and the second information belong to a read instruction type or a write instruction type; After sending the second information to the distributed cache server, it includes: If the instruction type of the second information belongs to the write instruction type, storing the second data in the distributed cache server; If the instruction type of the second information belongs to the read instruction type, determining third data corresponding to the second data in the distributed cache server, and decrypting the third data based on the data encryption method corresponding to the first data and sending it to the distributed cache client, where the third data is the encrypted cache data value corresponding to the encrypted cache data name included in the second data.

6. The method according to claim 1, characterized in that, The distributed cache server consists of a main node and at least one slave node, where the main node is used to perform a response operation corresponding to the second information, and each slave node in the at least one slave node is used to synchronize the cache data in the main node.

7. The method according to claim 6, wherein Sending the second information to the distributed cache server, including: Determining second configuration information, where configuration information of each node in the distributed cache server is recorded in the second configuration information, and the configuration information of the node is used to indicate whether the node is a main node or a slave node; Sending the second information to the main node of the distributed cache server based on the second configuration information.

8. A distributed cache data encryption device, characterized in that, The device includes: A first acquisition module, configured to acquire first information sent by a distributed cache client, where the first information is used to indicate a data access operation on cache data stored in a distributed cache server based on first data included in the first information, and the first data includes a cache data name; A first determination module, configured to determine first configuration information, where a preset number of first hash values and data encryption methods respectively corresponding to each first hash value are recorded in the first configuration information; A second determination module, configured to encrypt the first data based on the first configuration information to obtain second data, and determine second information based on the first information and the second data, where the second information is composed of a part of the first information other than the first data and the second data; A first sending module, configured to send the second information to the distributed cache server, so that the distributed cache server executes a response operation corresponding to the second information.

9. An electronic device, characterized in that, The electronic device includes: At least one processor; and a memory communicatively connected to the at least one processor; wherein, the memory stores a computer program executable by the at least one processor, and the computer program is executed by the at least one processor, so that the at least one processor can execute the distributed cache data encryption method according to any one of claims 1-7.

10. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer instructions, and the computer instructions are used to implement the distributed cache data encryption method according to any one of claims 1-7 when executed by a processor.