Data security protection method based on encryption algorithm and erasure code fusion
By integrating encryption algorithms with erasure coding, and combining ECB encryption mode with array erasure coding technology, the problem of difficult performance and confidentiality in traditional methods is solved, efficient data protection is achieved, and data processing efficiency and storage resource utilization are improved.
Patent Information
- Application Number
- CN202510485792.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-17
- Publication Date
- 2025-07-25
AI Technical Summary
It is difficult for the prior art to take into account both the reliability, confidentiality and performance of data. The combination of traditional encryption methods and erasure coding technology will affect the computing performance or confidentiality.
The encryption algorithm is fused with erasure coding, the ECB encryption mode is combined with array erasure coding technology, and the key block and verification block are introduced to optimize encoding, decoding, update and reconstruction operations, and performance is improved through joint operations and confidentiality and reliability are enhanced.
It improves data processing efficiency, reduces data bloat rate, enhances storage resource utilization efficiency, reduces redundancy and space usage, and improves the system's operating efficiency and flexibility in dealing with failures.
Smart Images

Figure CN120372657A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of data storage and information security, and in particular to a data security protection method based on the fusion of encryption algorithms and erasure codes. Background Art
[0002] In the context of the big data era, data owners' requirements for data confidentiality and reliability have shown a significant upward trend. The importance of data confidentiality is self-evident. In recent years, the hacking community's attack methods have been continuously refined, and the attack patterns have become more diverse, resulting in frequent outbreaks of malicious data security incidents. Take Equifax, the largest credit rating agency in the United States in 2017, as an example. It suffered a hacker intrusion, resulting in the leakage of personal sensitive data of 147 million users; in 2020, the Finnish psychotherapy institution Vastaamo was also attacked by hackers, resulting in the leakage of medical record data of tens of thousands of patients. At the same time, the importance of data reliability cannot be underestimated. Taking the 9 / 11 attack as a typical case, affected by this, the data centers of Bank of New York and Deutsche Bank were both devastated. Six months after the incident, Bank of New York lacked an effective data backup strategy and finally went into bankruptcy liquidation; on the contrary, Deutsche Bank, relying on a data backup mechanism pre-deployed dozens of kilometers away, successfully survived the crisis and maintained normal operations.
[0003] The most common means of hacker attacks are stealing and destroying. Preventing stealing mainly relies on encryption. For example, EFS, a technology developed by Microsoft to protect data confidentiality based on the NTFS file system, has greatly improved data confidentiality; preventing destruction, that is, improving reliability, mainly relies on redundancy, generally replicas and erasure codes. RAID technology is the most widely used erasure code technology, which realizes redundant protection of data by storing parity check information. With the development of RAID technology in recent years, a variety of different RAID levels have emerged, and each level has its specific advantages and application scenarios. Since the development of RAID technology to date, multiple levels with good scalability such as RAID0, RAID1, RAID4, RAID5, and RAID6 have been formed.
[0004] To simultaneously take into account data reliability and confidentiality, it is often necessary to use erasure code technology and encryption algorithms at the same time, which can be roughly divided into two ideas: one is the combined use of traditional encryption methods and erasure code technology. Whether encrypting first and then performing checksum calculations or performing checksum calculations first and then encrypting will seriously affect the calculation performance and increase the space occupancy of data; the other is to combine erasure codes with security mechanisms not based on encryption in order to improve performance, but the confidentiality is affected. Therefore, how to design a data coding method and system that takes into account data reliability, confidentiality, and performance has become an important research direction in the current technical field. Summary of the Invention
[0005] To solve the above technical problems, the present invention proposes a data security protection method based on the fusion of encryption algorithms and erasure codes. The combination of the key and the check block replaces the function of the check block. The ECB encryption algorithm is combined with the array erasure code technology to improve the operation performance of processes such as encoding, decoding, updating, and reconstruction, making the selection and utilization of algorithms more flexible, while ensuring high confidentiality and reliability of data.
[0006] A data security protection method based on the fusion of encryption algorithms and erasure codes includes the following steps:
[0007] Step S1: Divide a single stripe into K stripe blocks of the same size. The first K - 1 stripe blocks are all data blocks of the original data, and the Kth stripe block is a check block;
[0008] Step S2: Use Intel SGX technology to build an isolated execution area on the CPU, defined as the key management area;
[0009] Step S3: Introduce a key block M with the same data volume as each data block into the key management area;
[0010] Step S4: Perform specific data protection operations on the basis of the optimized ECB encryption mode, specifically including encoding operations, decoding operations, update operations, check operations, and reconstruction operations.
[0011] Further, in the step S4, the optimized ECB encryption mode, that is, the EUCB encryption mode performs a joint operation on two adjacent data blocks before and after, and uses the previous original data block as the key block of the next original data block.
[0012] Further, in the step S4, using letters to represent the order of the stripe blocks, the single - stripe encoding operation is as follows:
[0013] Perform a binary operation on the key block M and the first data block A to obtain the ciphertext block MA and write it into the first data block of the new stripe. The operation satisfies that the data volume of the ciphertext block MA is the same as that of the key block M and the first data block A and can perform an inverse operation;
[0014] Then perform a binary operation on the first data block A and the second data block B to obtain the ciphertext block AB and write it into the second data block of the new stripe;
[0015] And so on, until the (K - 1)th data block performs a binary operation with the key block M to obtain the ciphertext block and write it into the check block of the new stripe, completing the encoding process of the stripe; the ciphertext block obtained by performing a binary operation on the (K - 1)th data block and the key block M is the redundant data of the stripe;
[0016] The encoded data N of the ith stripe block i-cFor
[0017]
[0018] wherein, M is the key block, n is the number of blocks in a single stripe, N i-p is the original data of the i-th block from the start to the end of encoding, N (i-1)-p is the original data of the (i - 1)-th block from the start to the end of encoding.
[0019] Furthermore, in step S4, when extending the single-stripe encoding operation to a multi-stripe encoding operation, the data and parity information are evenly distributed in the form of stripes on all hard disks, and each hard disk stores part of the data and parity check information.
[0020] Furthermore, in step S4, using letters to represent the block order, the decoding operation is as follows: performing a binary operation on the key block M and the ciphertext block MA to obtain the first data block A, and then performing a binary operation on the first data block and the ciphertext block AB to obtain the second data block B, and so on, until the (K - 1)-th data block is obtained, completing the decoding process;
[0021] The reverse decoding operation is as follows: performing a binary operation on the verification block and the key block M to obtain the (K - 1)-th data block, and so on, until the first data block A is obtained, completing the reverse decoding operation;
[0022] The computational performance of the decoding operations in the above two directions is the same. Select the decoding or reverse decoding according to the position of the ciphertext block to be accurately decoded in the stripe.
[0023] Furthermore, in step S4, using letters to represent the block order, the update operation is as follows: determining the position of the original data block to be updated, obtaining the previous data block of the original data block through the decoding operation, obtaining the next data block of the original data block through the reverse decoding operation, and performing binary operations with the updated data block in sequence to obtain two updated ciphertext blocks, and replacing the corresponding pre-updated ciphertext blocks with the updated ciphertext blocks, completing the update operation.
[0024] Furthermore, in step S4, using letters to represent the block order, the verification operation is as follows: performing a binary operation on the ciphertext block MA and the key block M to obtain the first data block A, and then performing a binary operation on the ciphertext block AB and the first data block A to obtain the second data block B, and so on, until the (K - 1)-th data block is obtained, performing a binary operation on the (K - 1)-th data block and the key block M, and comparing the obtained ciphertext block with the ciphertext block directly obtained by performing a binary operation on the (K - 1)-th data block and the key block M, completing the verification operation.
[0025] Further, in step S4, the reconstruction operation is as follows: Determine the position of the bad block in the ciphertext block. The bad block corresponds to the two original data blocks before and after it. Obtain the first original data block among the two original data blocks through a decoding operation, and obtain the second original data block among the two original data blocks through an inverse decoding operation. Perform a binary operation on the obtained two original data blocks to obtain the reconstructed ciphertext block, and replace the bad block with the reconstructed ciphertext block to complete the reconstruction operation.
[0026] Further, the data protection method can only tolerate single hard disk failures. The data protection method is optimized by grouping for tolerating multiple hard disk failures. After optimization, multiple check blocks are added at different positions of the stripe, and the entire stripe is divided into multiple groups.
[0027] Further, the encoding operation, decoding operation, update operation, check operation, and reconstruction operation of the optimized data protection method are carried out simultaneously in multiple groups.
[0028] Compared with the prior art, the present invention can achieve the following beneficial effects:
[0029] 1. A data security protection method based on the fusion of encryption algorithm and erasure code proposed by the present invention, by fusing the encryption mode and erasure code, not only ensures the confidentiality of the array using the encryption mode, but also ensures the reliability of the array through erasure code technology, avoiding the performance loss caused by separate encryption or processing in traditional methods, improving the efficiency of data processing, and at the same time making the algorithm selection more flexible for the given array, significantly enhancing the performance of processes such as encoding, updating, and reconstruction.
[0030] 2. A data security protection method based on the fusion of encryption algorithm and erasure code proposed by the present invention reduces the data expansion rate that simultaneously meets the conditions of reliability and confidentiality, can effectively reduce data redundancy and space occupation, and improves the utilization efficiency of storage resources.
[0031] 3. A data security protection method based on the fusion of encryption algorithm and erasure code proposed by the present invention adopts the optimized ECB encryption mode, namely the EUCB encryption mode, and avoids the problem that the ciphertext is easily attacked due to the repetition of the plaintext in the traditional ECB mode through joint operations, enhancing the confidentiality of the data.
[0032] 4. A data security protection method based on the fusion of encryption algorithm and erasure code proposed by the present invention can perform grouping expansion optimization for tolerating multiple hard disk failures by dividing the entire stripe into multiple groups by adding multiple check blocks. When a hard disk fails, data reconstruction can be carried out with the help of key blocks, check blocks, and specific operation methods to ensure the integrity and availability of the data, reduce the risk of data loss, and enhance the reliability of data storage.
[0033] 5. The operations performed by different groups of the optimized data protection method proposed by the present invention do not interfere with each other. When encoding, decoding, updating, and verifying are performed simultaneously, the speed is faster than that without grouping, the average data waiting time is shortened, especially for the data at the end of the stripe when not grouped originally; moreover, when different groups fail simultaneously, reconstruction can be performed simultaneously, improving the overall operation efficiency of the system and the flexibility in dealing with failures. BRIEF DESCRIPTION OF THE DRAWINGS
[0034] Figure 1 It is a flowchart of a data security protection method based on the fusion of encryption algorithm and erasure code proposed by the present invention.
[0035] Figure 2 It is a single - stripe encoding process of a data security protection method based on the fusion of encryption algorithm and erasure code provided by an embodiment of the present invention.
[0036] Figure 3 It is a multi - stripe encoding process of a data security protection method based on the fusion of encryption algorithm and erasure code provided by an embodiment of the present invention.
[0037] Figure 4 It is a single - stripe decoding process of a data security protection method based on the fusion of encryption algorithm and erasure code provided by an embodiment of the present invention.
[0038] Figure 5 It is a single - stripe updating process of a data security protection method based on the fusion of encryption algorithm and erasure code provided by an embodiment of the present invention.
[0039] Figure 6 It is a single - stripe verification process of a data security protection method based on the fusion of encryption algorithm and erasure code provided by an embodiment of the present invention.
[0040] Figure 7 It is a single - stripe reconstruction process of a data security protection method based on the fusion of encryption algorithm and erasure code provided by an embodiment of the present invention.
[0041] Figure 8 It is a single - stripe encoding process of the optimized data protection method provided by an embodiment of the present invention.
[0042] Figure 9 It is a single - stripe decoding, updating, verification, and reconstruction process of the optimized data protection method provided by an embodiment of the present invention.
[0043] In the figure, TEE is the trusted execution environment, M is the key block, and K is the number of stripe blocks of a single stripe. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0044] The following further describes the specific embodiments of the present invention in conjunction with the accompanying drawings. The technical solutions in the embodiments of the present invention are clearly and completely described. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.
[0045] In combination with Figure 1 , the present invention proposes a data security protection method based on the fusion of encryption algorithms and erasure codes, including the following steps:
[0046] Step S1: Divide a single stripe into K stripe blocks of the same size. The first K - 1 stripe blocks are all data blocks of the original data, and the Kth stripe block is a check block;
[0047] Step S2: Use Intel SGX technology to build an isolated execution area on the CPU, defined as the key management area. The code and data running in this area are protected from external attacks at the physical and logical levels;
[0048] Step S3: Introduce a key block M with the same data volume as each data block into the key management area; the key block M is not smaller than the data volume of the data block, which is for the consideration of the confidentiality of the original data to reduce the exposed original data bit positions; it is not larger than the data volume of the data block, which is for the consideration of computing performance to reduce unnecessary operations of redundant bits of the key.
[0049] Step S4: Perform specific data protection operations on the basis of the optimized ECB encryption mode, specifically including encoding operations, decoding operations, update operations, check operations, and reconstruction operations.
[0050] Furthermore, in step S4, the optimized ECB encryption mode performs a joint operation on two adjacent data blocks, using the previous original data block as the key block for the next original data block, reducing the problem of ciphertext repetition caused by plaintext repetition in the ECB encryption mode and having stronger confidentiality.
[0051] Furthermore, in combination with Figure 2 , in step S4, a stripe is divided into 8 stripe blocks and 7 original data blocks are stored. The stripe block order is represented by letters. The single - stripe encoding operation is:
[0052] Perform a binary operation on the key block M and the first data block A to obtain the ciphertext block MA and write it into the first data block of the new stripe. The operation satisfies that the data volume of the ciphertext block MA, the key block M, and the first data block A is the same and can perform an inverse operation. Then perform a binary operation on the first data block A and the second data block B to obtain the ciphertext block AB and write it into the second data block of the new stripe. And so on, until the data block G performs a binary operation with the key block M to obtain the ciphertext block GM and write it into the check block of the new stripe, completing the encoding process of this stripe. The ciphertext block GM is the redundant data of this stripe, and the key block M is equivalent to the common redundant data of each stripe. The redundancy of the key block M can be basically ignored.
[0053] The encoded data N of the i-th stripe block i-c is
[0054]
[0055] where M is the key block, n is the number of stripe blocks in a single stripe, N i-p is the original data of the i-th stripe block from the start to the end of encoding, and N (i-1)-p is the original data of the (i - 1)-th stripe block from the start to the end of encoding.
[0056] Furthermore, in combination with Figure 3 , in step S4, when extending the single-stripe encoding operation to a multi-stripe encoding operation, the data and check information are evenly distributed in the form of stripes on all hard disks. Each hard disk stores part of the data and parity check information. In this way, when reading and writing data, multiple hard disks can be operated simultaneously, avoiding overloading a single hard disk, thereby achieving load balancing.
[0057] Furthermore, in combination with Figure 4 , in step S4, a stripe is divided into 8 stripe blocks and stores 7 original data blocks. The stripe block order is represented by letters. The decoding operation is as follows: perform a binary operation on the key block M and the ciphertext block MA to obtain the first data block A, and then perform a binary operation on the first data block and the ciphertext block AB to obtain the second data block B, and so on, until the data block G is obtained, completing the decoding process. The reverse decoding operation is as follows: perform a binary operation on the verification block GM and the key block M to obtain the data block G, and so on, until the first data block A is obtained, completing the reverse decoding operation. The computational performance of the above two directions of decoding operations is the same. Select the decoding or reverse decoding according to the position of the ciphertext block to be accurately decoded in the stripe.
[0058] Furthermore, in combination with Figure 5, in step S4, a strip is divided into 8 strip blocks and 7 original data blocks are stored. The strip blocks are represented by letters. The update operation is as follows: Determine the position of the original data block to be updated. Suppose the original data block C is to be changed to data block X. Obtain the previous data block B of the original data block through decoding operation, and obtain the next data block D of the original data block through reverse decoding operation. Perform binary operations with the updated data block X in sequence to obtain two updated ciphertext blocks BX and XD. Replace the corresponding pre-updated ciphertext blocks with the updated ciphertext blocks to complete the update operation.
[0059] Further, in combination with Figure 6 , in step S4, a strip is divided into 8 strip blocks and 7 original data blocks are stored. The strip blocks are represented by letters. The verification operation is as follows: Perform a binary operation on the ciphertext block MA and the key block M to obtain the first data block A, and then perform a binary operation on the ciphertext block AB and the first data block A to obtain the second data block B, and so on until the data block G is obtained. Perform a binary operation on the data block G and the key block M, and compare the obtained ciphertext block with the ciphertext block GM to complete the verification operation.
[0060] Further, in combination with Figure 7 , in step S4, a strip is divided into 8 strip blocks and 7 original data blocks are stored. The reconstruction operation is as follows: Determine the position of the bad block in the ciphertext block. Suppose the bad block is the ciphertext block BC, and the two original data blocks B and C corresponding to the bad block. Obtain the original data block B through decoding operation, and obtain the original data block C through reverse decoding operation. Perform a binary operation on the obtained two original data blocks to obtain the reconstructed ciphertext block BC. Replace the bad block with the reconstructed ciphertext block BC to complete the reconstruction operation.
[0061] Further, the data protection method can only tolerate single hard disk failure. Perform grouped expansion optimization on the data protection method to tolerate multiple hard disk failures. The optimized data protection method adds multiple check blocks at different positions of the strip blocks, divides the entire strip into multiple groups. In combination with Figure 8 and Figure 9 , a strip is divided into 8 strip blocks and 7 original data blocks are stored. Suppose the number of tolerable hard disks is 2, then add a check block in the middle of 6 data blocks, and divide the entire strip into groups A - C and D - F.
[0062] Further, in combination with Figure 8 and Figure 9 , the encoding operation, decoding operation, update operation, verification operation, and reconstruction operation of the optimized data protection method are carried out simultaneously in multiple groups;
[0063] Taking the encoding operation as an example, generally speaking, suppose the key block is M, the system width is k, the number of tolerable hard disk failures is s, and the i-th strip block from the start to the end of encoding is Ni (1 ≤ i ≤ n, i ∈ N), the original data of the i-th stripe is N i-p , the original data of the (i - 1)-th stripe is N (i-1)-p , the encoded data of the i-th stripe is N i-c ; when the i-th stripe is the s-th parity block in the corresponding stripe, this stripe is represented as the original data of this stripe is When the (i + 1)-th stripe is the next data block immediately following the s-th parity block in the corresponding stripe, this stripe is the original data of this stripe is the encoded data is If it is not a parity block or not the next data block immediately following a parity block, s is not reflected;
[0064] When the stripe is not a parity block and not the next data block immediately following a parity block, there is:
[0065]
[0066] When the stripe is a parity block and the next data block immediately following a parity block, there is:
[0067]
[0068] Setting up groups increases the reliability of the data. The actions to be performed by the two groups do not interfere with each other. Theoretically, the optimized data protection method is faster when performing encoding, decoding, updating, and verification operations simultaneously compared to not grouping, and the average waiting time of each data is shortened, especially for the data at the end of the stripe when not grouped; if failures occur simultaneously in different groups, reconstruction can be carried out simultaneously.
[0069] Combined with Figures 2 to 7 , the following gives a specific embodiment of a data security protection method based on the fusion of encryption algorithms and erasure codes:
[0070] Let M = 0x209, N 1-p = 0x26d, N 2-p = 0x30a, N 3-p = 0x84c, N 4-p = 0x107, N 5-p = 0x521, N 6-p = 0x632, N 7-p = 0x468;
[0071] Encoding operation:
[0072] When i = 1, then N 1-c = M ⊕ N 1-p = 0x209 ⊕ 0x26d = 0x64;
[0073] When i = 2, then N 2-c = N 2-p ⊕ N 1-p = 0x30a ⊕ 0x26d = 0x167;
[0074] When i = 3, then N 3-c = N 3-p ⊕ N 2-p = 0x84c ⊕ 0x30a = 0xb46;
[0075] When i = 4, then N 4-c = N 4-p ⊕ N 3-p = 0x107 ⊕ 0x84c = 0x94b;
[0076] When i = 5, then N 5-c = N 5-p ⊕ N 4-p = 0x521 ⊕ 0x107 = 0x426;
[0077] When i = 6, then N 6-c = N 6-p ⊕ N 5-p = 0x632 ⊕ 0x521 = 0x313;
[0078] When i = 7, then N 7-c = N 7-p ⊕ N 6-p = 0x468 ⊕ 0x632 = 0x25a;
[0079] When i = 8, then N 8-c = N 7-p ⊕ M = 0x468 ⊕ 0x209 = 0x661.
[0080] Decoding operation:
[0081] Assume we want to read N 5-p , then the following steps:
[0082] Given M, then N 7-p = M ⊕ N 8-c = 0x661 ⊕ 0x209 = 0x468;
[0083] Given N 7-p , then N 6-p = N 7-p ⊕ N 7-c = 0x468 ⊕ 0x25a = 0x632;
[0084] Given N 6-p , then N 5-p = N 6-p ⊕ N 6-c= 0x632 ⊕ 0x313 = 0x521. Update operation:
[0085] Assume we want to update N 3-p to 0x394, then the following steps are:
[0086] Read N 2-p , N 4-p ;
[0087] When i = 3, then N 3-c = N 3-p ⊕ N 2-p = 0x394 ⊕ 0x30a = 0x9e;
[0088] When i = 4, then N 4-c = N 4-p ⊕ N 3-p = 0x107 ⊕ 0x394 = 0x293.
[0089] Verification operation:
[0090] Given M, then N 1-p = M ⊕ N 1-c = 0x209 ⊕ 0x64 = 0x26d;
[0091] Given N 1-p , then N 2-p = N 1-p ⊕ N 2-c = 0x26d ⊕ 0x167 = 0x30a;
[0092] Given N 2-p , then N 3-p = N 2-p ⊕ N 3-c = 0x30a ⊕ 0xb46 = 0x84c;
[0093] Given N 3-p , then N 4-p = N 3-p ⊕ N 4-c = 0x84c ⊕ 0x94b = 0x107;
[0094] Given N 4-p , then N 5-p = N 4-p ⊕ N 5-c = 0x107 ⊕ 0x426 = 0x521;
[0095] Given N 5-p , then N 6-p = N 5-p ⊕ N 6-c = 0x521 ⊕ 0x313 = 0x632;
[0096] Given N 6-p , then N 7-p = N 6-p ⊕ N 7-c = 0x632 ⊕ 0x25a = 0x468;
[0097] If N 7-p ⊕ M = N 8-c , then the data is complete;
[0098] If N 7-p ⊕ M ≠ N 8-c , then the data is incomplete.
[0099] Reconstruction operation:
[0100] Suppose we want to reconstruct N 4-c , then the following steps are as follows:
[0101] Given M, then N 1-p = M ⊕ N 1-c = 0x209 ⊕ 0x64 = 0x26d;
[0102] Given N 1-p , then N 2-p = N 1-p ⊕ N 2-c = 0x26d ⊕ 0x167 = 0x30a;
[0103] Given N 2-p , then N 3-p = N 2-p ⊕ N 3-c = 0x30a ⊕ 0xb46 = 0x84c;
[0104] Thus, we get N 3-p ;
[0105] Given M, then N 7-p = M ⊕ N 8-c = 0x661 ⊕ 0x209 = 0x468;
[0106] Given N 7-p , then N 6-p = N 7-p ⊕ N 7-c = 0x468 ⊕ 0x25a = 0x632;
[0107] Given N 6-p , then N 5-p = N 6-p ⊕ N 6-c = 0x632 ⊕ 0x313 = 0x521;
[0108] Given N 5-p , then N 4-p= N 5-p ⊕ N 5-c = 0x521 ⊕ 0x426 = 0x107;
[0109] Thus, N is obtained 4-p ;
[0110] N 4-c = N 4-p ⊕ N 3-p = 0x107 ⊕ 0x84c = 0x94b.
[0111] Combined with Figure 8 and Figure 9 , the following gives a specific embodiment of an optimized data protection method based on the fusion of encryption algorithms and erasure codes:
[0112] Let M = 0x209, N 1-p = 0x26d, N 2-p = 0x30a, N 3-p = 0x84c, N 5-p = 0x521, N 6-p = 0x632, N 7-p = 0x468, and the 4th and 8th stripes are parity stripes;
[0113] Encoding operation:
[0114] When i = 1, then N 1-c = M ⊕ N 1-p = 0x209 ⊕ 0x26d = 0x64;
[0115] When i = 2, then N 2-c = N 2-p ⊕ N 1-p = 0x30a ⊕ 0x26d = 0x167;
[0116] When i = 3, then N 3-c = N 3-p ⊕ N 2-p = 0x84c ⊕ 0x30a = 0xb46;
[0117] When i = 4, s = 1, N 41 -c = N 3-p ⊕ M = 0x84c ⊕ 0x209 = 0xa45;
[0118] When i = 5, N 51+1 -c = M ⊕ N 51+1 -p = 0x209 ⊕ 0x521 = 0x728;
[0119] When i = 6, then N 6-c = N 6-p ⊕ N 5-p= 0x632 ⊕ 0x521 = 0x313;
[0120] When i = 7, then N 7-c = N 7-p ⊕ N 6-p = 0x468 ⊕ 0x632 = 0x25a;
[0121] When i = 8, s = 2, N 82 -c = N 7-p ⊕ M = 0x468 ⊕ 0x209 = 0x661.
[0122] Decoding operation:
[0123] Assume we want to read N 5-p , then the following steps are involved:
[0124] Given M, then N 5-p = M ⊕ N 5-c = 0x209 ⊕ 0x728 = 0x521.
[0125] Update operation:
[0126] Assume we want to update N 3-p to 0x394, N 6-p to 0x884, then the following steps are involved:
[0127] Read out N 2-p , N 5-p , N 7-p ;
[0128] When i = 3, then N 3-c = N 3-p ⊕ N 2-p = 0x394 ⊕ 0x30a = 0x9e;
[0129] When i = 4, then N 4-c = M ⊕ N 3-p = 0x209 ⊕ 0x394 = 0x19d;
[0130] Meanwhile:
[0131] When i = 6, then N 6-c = N 6-p ⊕ N 5-p = 0x884 ⊕ 0x521 = 0xda5;
[0132] When i = 7, then N 7-c = N 7-p ⊕ N 6-p = 0x468 ⊕ 0x884 = 0xcec.
[0133] Verification operation:
[0134] Given M, then N 1-p = M ⊕ N 1-c = 0x209 ⊕ 0x64 = 0x26d;
[0135] Given N 1-p , then N 2-p = N 1-p ⊕ N 2-c = 0x26d ⊕ 0x167 = 0x30a;
[0136] Given N 2-p , then N 3-p = N 2-p ⊕ N 3-c = 0x30a ⊕ 0xb46 = 0x84c;
[0137] Get N 3-p ⊕ M;
[0138] Given M, then N 5-p = M ⊕ N 5-c = 0x209 ⊕ 0x728 = 0x521;
[0139] Given N 5-p , then N 6-p = N 5-p ⊕ N 6-c = 0x521 ⊕ 0x313 = 0x632;
[0140] Given N 6-p , then N 7-p = N 6-p ⊕ N 7-c = 0x632 ⊕ 0x25a = 0x468;
[0141] Get N 7-p ⊕ M;
[0142] If N 3-p ⊕ M = N 4-c And N 7-p ⊕ M = N 8-c , then the data is complete; otherwise, the data is incomplete. Reconstruction operation:
[0143] Assume that N 1-c 、N 6-c need to be reconstructed, then there are the following steps:
[0144] Reconstruct N 1-c :
[0145] Given M, then N 3-p = M ⊕ N 4-c = 0x209 ⊕ 0xa45 = 0x84c;
[0146] Given N3-p , then N 2-p = N 3-p ⊕ N 3-c = 0x84c ⊕ 0xb46 = 0x30a;
[0147] Given N 2-p , then N 1-p = N 2-p ⊕ N 2-c = 0x30a ⊕ 0x167 = 0x26d;
[0148] Thus, N 1-p ;
[0149] Then N 1-c = N 1-p ⊕ M = 0x26d ⊕ 0x209 = 0x64.
[0150] Reconstruct N 6-c :
[0151] Given M, then N 5-p = M ⊕ N 5-c = 0x209 ⊕ 0x728 = 0x521;
[0152] Thus, N 5-p ;
[0153] Given M, then N 7-p = M ⊕ N 8-c = 0x661 ⊕ 0x728 = 0x468;
[0154] Given N 7-p , then N 6-p = N 7-p ⊕ N 7-c = 0x468 ⊕ 0x25a = 0x632;
[0155] Thus, N 6-p ;
[0156] Then N 6-c = N 6-p ⊕ N 5-p = 0x632 ⊕ 0x521 = 0x313.
[0157] The above are only the preferred embodiments of the present application, and the present invention is not limited to the above examples. It can be understood that other improvements and changes directly derived or associated by those skilled in the art without departing from the spirit and concept of the present invention should be considered to be included within the protection scope of the present invention.
Claims
1. A data security protection method based on the integration of encryption algorithms and erasure codes, characterized in that It includes the following steps: Step S1: Divide a single strip into K strip blocks of the same size. The first K - 1 strip blocks are data blocks of the original data, and the Kth strip block is a check block; Step S2: Use Intel SGX technology to build an isolated execution area on the CPU, defined as the key management area; Step S3: Introduce a key block M with the same data volume as each data block into the key management area; Step S4: Perform specific data protection operations based on the optimized ECB encryption mode, specifically including encoding operations, decoding operations, update operations, check operations, and reconstruction operations.
2. The data security protection method based on the fusion of encryption algorithm and erasure code according to claim 1, characterized in that, In step S4, the optimized ECB encryption mode performs a combined operation on two adjacent data blocks, using the previous original data block as the key block for the next original data block.
3. A data security protection method based on the fusion of encryption algorithms and erasure codes according to claim 1, characterized in that, In step S4, using letters to represent the order of strip blocks, the single-strip encoding operation is as follows: Perform a binary operation on the key block M and the first data block A to obtain the ciphertext block MA and write it into the first data block of the new strip. The operation satisfies that the data volume of the ciphertext block MA is the same as that of the key block M and the first data block A and can perform an inverse operation; Then perform a binary operation on the first data block A and the second data block B to obtain the ciphertext block AB and write it into the second data block of the new strip; And so on, until the (K - 1)th data block performs a binary operation with the key block M to obtain a ciphertext block and write it into the check block of the new strip, completing the encoding process of this strip; the ciphertext block obtained by performing a binary operation on the (K - 1)th data block and the key block M is the redundant data of this strip; The encoded data N of the i-th strip i-c is Among them, M is the key block, n is the number of strip blocks in a single strip, and N i-p is the original data of the i-th strip block from the start to the end of encoding, and N (i-1)-p is the original data of the (i - 1)-th strip block from the start to the end of encoding.
4. A data security protection method based on the fusion of encryption algorithms and erasure codes according to claim 1, characterized in that, In step S4, when extending the single-strip encoding operation to a multi-strip encoding operation, the data and check information are evenly distributed on all hard disks in the form of strips, and each hard disk stores part of the data and parity check information.
5. A data security protection method based on the fusion of encryption algorithms and erasure codes according to claim 1, characterized in that, In step S4, using letters to represent the order of strip blocks, the decoding operation is as follows: Perform a binary operation on the key block M and the ciphertext block MA to obtain the first data block A, and then perform a binary operation on the first data block and the ciphertext block AB to obtain the second data block B, and so on, until the (K - 1)th data block is obtained, completing the decoding process; The reverse decoding operation is as follows: Perform a binary operation on the verification block and the key block M to obtain the (K - 1)th data block, and so on, until the first data block A is obtained, completing the reverse decoding operation; The computational performance of the above two directions of decoding operations is the same. Select decoding or reverse decoding according to the position of the ciphertext block that needs to be accurately decoded in the strip.
6. A data security protection method based on the fusion of encryption algorithms and erasure codes according to claim 1, characterized in that, In step S4, using letters to represent the order of strip blocks, the update operation is as follows: Determine the position of the original data block that needs to be updated, obtain the previous data block of this original data block through the decoding operation, obtain the next data block of this original data block through the reverse decoding operation, perform binary operations with the updated data block in turn to obtain two updated ciphertext blocks, and replace the corresponding pre-updated ciphertext blocks with the updated ciphertext blocks to complete the update operation.
7. A data security protection method based on the fusion of encryption algorithms and erasure codes according to claim 1, characterized in that, In the step S4, the strip order is represented by letters, and the verification operation is as follows: the first data block A is obtained by performing a binary operation on the ciphertext block MA and the key block M, then the second data block B is obtained by performing a binary operation on the ciphertext block AB and the first data block A, and so on until the (K - 1)-th data block is obtained. The (K - 1)-th data block is subjected to a binary operation with the key block M, and the obtained ciphertext block is compared with the ciphertext block directly obtained by performing a binary operation on the (K - 1)-th data block and the key block M to complete the verification operation.
8. A data security protection method based on the fusion of encryption algorithms and erasure codes according to claim 1, characterized in that, In the step S4, the reconstruction operation is as follows: determine the position of the bad block in the ciphertext block. The bad block corresponds to the two original data blocks before and after it. The previous original data block among the two original data blocks is obtained through a decoding operation, and the latter original data block among the two original data blocks is obtained through an inverse decoding operation. The obtained previous and latter original data blocks are subjected to a binary operation to obtain the reconstructed ciphertext block, and the bad block is replaced with the reconstructed ciphertext block to complete the reconstruction operation.
9. A data security protection method based on the fusion of encryption algorithms and erasure codes according to claim 1, characterized in that The data protection method can only tolerate single hard disk failures. The data protection method is optimized by grouping to tolerate multiple hard disk failures. Multiple check blocks are added at different positions of the strips in the optimized data protection method, and the entire stripe is divided into multiple groups.
10. A data security protection method based on the fusion of encryption algorithms and erasure codes according to claim 1, characterized in that, The encoding operation, decoding operation, update operation, verification operation, and reconstruction operation of the optimized data protection method are carried out simultaneously in multiple groups.