Data access method and device, electronic equipment and storage medium

By encrypting and decrypting locally on the object storage service protocol client, the problem that users cannot fully control the data security of the cloud storage platform is solved, local storage and encryption of data is realized, data confidentiality and integrity are enhanced, and key security is ensured.

CN120372674APending Publication Date: 2025-07-25PENG CHENG LAB
View PDF 0 Cites 2 Cited by

Patent Information

Application Number
CN202510329506.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-19
Publication Date
2025-07-25

AI Technical Summary

Technical Problem

The existing cloud storage platform has problems with data security, and users cannot fully control the data, especially when using server-side encryption services, they need to trust cloud service providers.

Method used

Data encryption and decryption are performed locally on the object storage service protocol client, encrypting the encrypted data through the target object key identification, generating data ciphertext and encryption key, and encapsulating it into target data to transmit it to the server to ensure that the data is stored in the local cache area.

Benefits of technology

It realizes users' complete control over data on the cloud, enhances data confidentiality and integrity, prevents data leakage, ensures the security of keys, and improves the encryption and security of data.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120372674A_ABST
    Figure CN120372674A_ABST
Patent Text Reader

Abstract

The invention discloses a data access method and device, electronic equipment and a storage medium, and is applied to an object storage service protocol client, the method comprises the following steps: obtaining a data processing request, the data processing request carrying a data processing type and a target object key identifier; when the data processing type is a write processing type, encrypting the written to-be-encrypted data according to a target preset data key corresponding to the target object key identifier to obtain a first data ciphertext, and encrypting the target preset data key according to the target object key identifier to obtain a first encryption key; and generating target data according to the first data ciphertext and the first encryption key, and transmitting the target data to a data cache region of an object storage service protocol client, so as to write the target data in the data cache region into a server through an object storage service protocol. According to the embodiment of the invention, the data of the user can be locally encrypted, so that the data owner can completely control the data on the cloud.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of computer technology, and in particular, to data access methods, devices, electronic devices, and storage media. Background Art

[0002] With the development and popularization of cloud computing technology, more and more enterprises and individuals store data on cloud platforms. Among them, the Amazon S3 (Simple Storage Service) protocol is widely adopted by many cloud service providers due to its reliability, scalability, and convenience. Existing computing power network applications also widely use storage services based on the S3 protocol to store large model corpus data and training results. The data security issue during the storage of these high-value data on the S3 service platform has become a major concern for data owners.

[0003] An important method to solve the data security problem is to perform encryption and decryption operations on the data. Currently, common cloud storage platforms (including Amazon, Huawei Cloud, etc.) generally provide SSE (Server Side Encryption) services. This service method is that the user or KMS (Key Management Service) provides the key, and finally the server encrypts the data. This method requires the user to trust the cloud service provider and cannot achieve the complete control of the data by the data owner. Summary of the Invention

[0004] Embodiments of this application provide a data access method, device, electronic device, and storage medium, where the user's data is encrypted locally to achieve the complete control of the data on the cloud by the data owner.

[0005] In a first aspect, an embodiment of this application provides a data access method, which is applied to an object storage service protocol client. The data access method includes: Obtain a data processing request, where the data processing request carries a data processing type and a target object key identifier; When the data processing type is a write processing type, encrypt the data to be encrypted for writing according to the target preset data key corresponding to the target object key identifier to obtain a first data ciphertext, and encrypt the target preset data key according to the target object key identifier to obtain a first encryption key; Generate target data according to the first data ciphertext and the first encryption key, and transmit the target data to the data buffer of the object storage service protocol client, so as to write the target data in the data buffer to the server through the object storage service protocol.

[0006] In some embodiments, after obtaining a data processing request, the data access method further includes: When the data processing type is a read processing type, obtain the data to be decrypted from the data cache area of the object storage service protocol client. The data to be decrypted at least includes a second data ciphertext and a second encryption key. The data to be decrypted is stored in the data cache area after being downloaded from the server through the object storage service protocol; Decrypt the second encryption key in the data to be decrypted according to the target object key identifier to obtain a target preset data key, and decrypt the second data ciphertext in the data to be decrypted according to the target preset data key to obtain the data plaintext.

[0007] In some embodiments, encrypting the data to be encrypted written according to the target preset data key corresponding to the target object key identifier to obtain a first data ciphertext includes: Segment the data to be encrypted with a preset segment length to obtain a plurality of data segments; For each of the data segments, perform an encryption operation on the data segment according to a preset encryption algorithm and the target preset data key corresponding to the target object key identifier to obtain an encrypted segment; Connect all the encrypted segments to obtain a first data ciphertext.

[0008] In some embodiments, generating target data according to the first data ciphertext and the first encryption key includes: Record the original length of the data to be encrypted written and the segment information corresponding to the encrypted segment, and generate an encrypted information digest according to the encryption algorithm, the first encryption key, the target object key identifier in the first data ciphertext, the segment information, and the original length; Perform data encapsulation on the first data ciphertext and the encrypted information digest to obtain target data.

[0009] In some embodiments, performing data encapsulation on the first data ciphertext and the encrypted information digest to obtain target data includes: Perform data encapsulation on the first data ciphertext and the encrypted information digest to obtain body information, and generate a file identifier corresponding to the body information; Record the first offset of the first data ciphertext in the data to be encrypted and the second offset of the encrypted information digest in the data to be encrypted; Generate file entry record information according to the first offset, the second offset, and the original length; Encapsulate the file identifier, the subject information, and the file entry record information to obtain target data.

[0010] In some embodiments, obtaining the data to be decrypted from the data buffer of the object storage service protocol client includes: When there is data to be decrypted stored in the data buffer of the object storage service protocol client, obtain the data to be decrypted from the data buffer of the object storage service protocol client; When there is no data to be decrypted stored in the data buffer of the object storage service protocol client, download the data to be decrypted from the server through the object storage service protocol to store the data to be decrypted in the data buffer of the object storage service protocol client, and obtain the data to be decrypted from the data buffer of the object storage service protocol client.

[0011] In some embodiments, decrypting the data ciphertext in the data to be decrypted according to the target preset data key to obtain the data plaintext includes: Determine the third offset of the data ciphertext in the data to be decrypted according to the data processing request; Read the file information of the data to be decrypted to obtain the digest to be decrypted in the file body and the fourth offset in the file tail, where the fourth offset is the offset of the second data ciphertext in the data to be decrypted; Obtain the original information length of the data to be decrypted and the ciphertext length of the data ciphertext in the data to be decrypted; Determine the target data length according to the original information length and the ciphertext length; Parse the digest to be decrypted to obtain the original segment length and the encrypted segment length of the segment to be decrypted in the data to be decrypted; Determine the number range of the data ciphertext according to the original segment length, the third offset, and the target data length; Determine the target decryption range according to the number range, the fourth offset, and the encrypted segment length; Perform a decryption operation on the target decryption range through the target preset data key to obtain the data plaintext.

[0012] In some embodiments, determining the target data length according to the original information length and the ciphertext length includes: When the original information length is greater than or equal to the ciphertext length, determine the ciphertext length as the target data length; When the original information length is less than the ciphertext length, determine the target data length according to the original information length and the third offset.

[0013] In some embodiments, after obtaining a data processing request, the data access method further includes: When the data processing type is a non-read / write type, the data processing request is sent to the server through an object storage service protocol, so that the server performs an access operation corresponding to the data processing request, and a response message returned by the server after performing the access operation is received.

[0014] In a second aspect, an embodiment of the present application provides a data access device, which is applied to an object storage service protocol client; the data access device includes: A file access module, configured to obtain a data processing request, where the data processing request carries a data processing type and a target object key identifier; A data cache module, configured to, when the data processing type is a write processing type, encrypt the data to be encrypted written according to a target preset data key corresponding to the target object key identifier to obtain a first data ciphertext, and encrypt the target preset data key according to the target object key identifier to obtain a first encryption key; A data encryption / decryption module, configured to generate target data according to the first data ciphertext and the first encryption key, and transmit the target data to a data cache area of the object storage service protocol client, so as to write the target data in the data cache area to the server through the object storage service protocol.

[0015] In a third aspect, an embodiment of the present application provides an electronic device, including at least one processor and a memory communicatively connected to the at least one processor; the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor, so that the at least one processor can execute the data access method as described in the first aspect.

[0016] In a fourth aspect, an embodiment of the present application provides a computer-readable storage medium, where the computer-readable storage medium stores computer-executable instructions, and the computer-executable instructions are used to cause a computer to execute the data access method as described in the first aspect.

[0017] The data access method, apparatus, electronic device, and storage medium provided by the embodiments of the present application have at least the following beneficial effects: The data access method of the embodiments of the present application is applied to an object storage service protocol client. When a user needs to access a file, the embodiments of the present application first obtain a data processing request, where the data processing request carries a data processing type and a target object key identifier, facilitating subsequent operations corresponding to different types of data for different data processing types. When the data processing type is a write processing type, the embodiments of the present application perform encryption processing on the written data. Specifically, the data to be encrypted written is encrypted according to the target preset data key corresponding to the target object key identifier, thereby enhancing the confidentiality of the data and ensuring the integrity of the data, obtaining a first data ciphertext, avoiding data leakage, and encrypting the target preset data key according to the target object key identifier to enhance the security of the key, obtaining a first encryption key, implementing encapsulation of the target preset data key, and preventing key leakage. After that, target data is generated according to the first data ciphertext and the first encryption key, that is, the first data ciphertext and the first encryption key are encapsulated as target data, improving the security of the data and preventing data leakage, and the target data is transmitted to the data buffer of the object storage service protocol client, realizing storage of the target data, and the target data can be stored in the local buffer to write the target data in the data buffer to the server through the object storage service protocol, realizing transmission of the target data. The data encryption operations in the embodiments of the present application are all executed on the object storage service protocol client, enabling the user to truly master the ownership of the data, effectively preventing the server from leaking data, and improving the encryption and security of the data. BRIEF DESCRIPTION OF THE DRAWINGS

[0018] Figure 1 is a specific method flowchart of the data access method provided by an embodiment of the present application; Figure 2 is a specific method flowchart of the data access method provided by another embodiment of the present application; Figure 3 is a specific method flowchart of encrypting the data to be encrypted written according to the target preset data key corresponding to the target object key identifier provided by an embodiment of the present application; Figure 4 is a specific method flowchart of generating target data according to the first data ciphertext and the first encryption key provided by an embodiment of the present application; Figure 5 is a specific method flowchart of data encapsulation of the first data ciphertext and the encrypted information digest provided by an embodiment of the present application; Figure 6It is a specific method flowchart for obtaining data to be decrypted from the data buffer of an object storage service protocol client provided by an embodiment of the present application; Figure 7 It is a specific method flowchart for decrypting the data ciphertext in the data to be decrypted according to the target preset data key provided by an embodiment of the present application; Figure 8 It is a specific method flowchart for determining the target data length according to the original information length and the ciphertext length provided by an embodiment of the present application; Figure 9 It is a specific method flowchart for determining the target data length according to the original information length and the ciphertext length provided by an embodiment of the present application; Figure 10 It is a schematic diagram of a data access device provided by an embodiment of the present application; Figure 11 It is a system example diagram of a data access system provided by an example of the present application; Figure 12 It is a schematic diagram of a data segment encryption process provided by an example of the present application; Figure 13 It is a schematic diagram of the structure of a packaging format provided by an example of the present application; Figure 14 It is a schematic diagram of a data segment decryption process provided by an example of the present application; Figure 15 It is a schematic diagram of the structure of an electronic device provided by an embodiment of the present application. Detailed implementation manners

[0019] In order to make the purpose, technical solutions and advantages of the present application clearer, the present application will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application.

[0020] With the development and popularization of cloud computing technology applications, more and more enterprises and individuals store data on cloud platforms. Among them, the Amazon S3 (Simple Storage Service, object storage service) protocol is widely adopted by many cloud service providers due to its reliability, scalability and convenience. Existing computing power network applications also widely use storage services based on the S3 protocol to store large model corpus data and training results. The data security issues during the storage of these high-value data on the S3 service platform have become a major concern for data owners.

[0021] An important method to solve data security problems is to perform encryption and decryption operations on data. Currently, common cloud storage platforms (including Amazon, Huawei Cloud, etc.) generally provide SSE (Server Side Encryption) services. In this service mode, the user or KMS (Key Management Service) provides the key, and finally the server encrypts the data. This method requires the user to trust the cloud service provider and cannot achieve the complete control of the data owner over the data.

[0022] To solve the above problems, this embodiment provides a data access method, device, electronic device, and storage medium, which at least have the following beneficial effects: The data access method of this application embodiment is applied to the object storage service protocol client. When the user needs to access a file, this application embodiment first obtains a data processing request. Among them, the data processing request carries a data processing type and a target object key identifier, which is convenient for subsequent operations corresponding to different data processing types of data. When the data processing type is the write processing type, this application embodiment encrypts the written data. Specifically, the data to be encrypted for writing is encrypted according to the target preset data key corresponding to the target object key identifier, so as to enhance the confidentiality of the data and ensure the integrity of the data, obtaining the first data ciphertext, avoiding the situation of data leakage, and encrypting the target preset data key according to the target object key identifier to enhance the security of the key, obtaining the first encryption key, realizing the encapsulation of the target preset data key, preventing the situation of key leakage. After that, the target data is generated according to the first data ciphertext and the first encryption key, that is, the first data ciphertext and the first encryption key are encapsulated as the target data, improving the security of the data and preventing the situation of data leakage, and the target data is transmitted to the data buffer of the object storage service protocol client to realize the storage of the target data, and the target data can be stored in the local buffer to write the target data in the data buffer to the server through the object storage service protocol to realize the transmission of the target data. The data encryption operations in this application embodiment are all executed on the object storage service protocol client, enabling the user to truly master the ownership of the data, effectively preventing the server from leaking data, and improving the encryption and security of the data.

[0023] Refer to Figure 1 , Figure 1 is the specific method flowchart of the data access method provided by an embodiment of this application. The data access method is applied to but not limited to the object storage service protocol client, and the method includes but is not limited to steps S101 to S103.

[0024] Step S101: Obtain a data processing request, which carries a data processing type and a target object key identifier.

[0025] In step S101 of some embodiments, a user may trigger an access data operation through a terminal or a web page. At this time, the present application embodiment obtains a data processing request, and the data processing request carries a data processing type and a target object key identifier, facilitating subsequent different processing for different types of data.

[0026] In some embodiments, before obtaining the data processing request, the user may also provide relevant access parameters of the server, such as Access Key, Secret Access Key, etc. In addition, the user may also specify that the system mounts the bucket and the directory in the bucket on the server to a specified directory of the local operating system, facilitating subsequent data encryption or decryption operations.

[0027] Step S102: When the data processing type is a write processing type, encrypt the data to be encrypted for writing according to the target preset data key corresponding to the target object key identifier to obtain a first data ciphertext, and encrypt the target preset data key according to the target object key identifier to obtain a first encryption key.

[0028] In step S102 of some embodiments, when the data processing type is a write processing type, the present application embodiment performs an encryption operation on the written data. Specifically, encrypt the data to be encrypted for writing according to the target preset data key corresponding to the target object key identifier to ensure that different ciphertexts can be generated after encrypting the same plaintext, obtaining a first data ciphertext, thereby providing self-descriptiveness and data integrity verification to ensure data confidentiality. In addition, the present application embodiment also encrypts the target preset data key according to the target object key identifier. Specifically, use the target object key identifier and the target preset data key as parameters to call the application programming interface of the key management service, and the key management service completes the encryption of the target preset key to obtain a first encryption key, thereby enhancing the security of the key and providing flexibility and manageability at the same time.

[0029] Step S103: Generate target data according to the first data ciphertext and the first encryption key, and transmit the target data to the data buffer of the object storage service protocol client to write the target data in the data buffer to the server through the object storage service protocol.

[0030] In step S103 of some embodiments, the target data is generated based on the first data ciphertext and the first encryption key to store the necessary information in the encryption process, which can completely record the parameters required for encryption, ensure that the correct parameters can be used to restore the data during subsequent decryption, and transmit the target data to the data buffer of the object storage service protocol client to implement local caching of the target data. Then, the target data in the data buffer is written to the server through the object storage service protocol to achieve data transmission, ensuring that only the encrypted data is stored on the server, enabling users to truly master the ownership of the data and effectively preventing the server from leaking data.

[0031] It should be noted that the object storage service protocol in the embodiments of the present application can be the DNS (Domain Name System) protocol, the HTTP (Hypertext Transfer Protocol), the S3 (Simple Storage Service) protocol, etc. In the embodiments of the present application, the object storage service protocol is the S3 protocol, and the specific protocol selection is not specifically limited in the embodiments of the present application.

[0032] In some embodiments, the data buffer of the object storage service protocol client is in units of file segments (chunks). The size of the file segment (chunk) can be set through configuration. For example, 8MB, 5MB, 10MB, etc., and the embodiments of the present application do not make specific limitations.

[0033] Refer to Figure 2 , Figure 2 is the specific method flowchart of the data access method provided by another embodiment of the present application. The data access method includes but is not limited to steps S201 to S202.

[0034] It should be noted that steps S201 to S202 occur after obtaining the data processing request.

[0035] Step S201, when the data processing type is the read processing type, obtain the data to be decrypted from the data buffer of the object storage service protocol client. The data to be decrypted includes at least the second data ciphertext and the second encryption key, and the data to be decrypted is downloaded from the server through the object storage service protocol and stored in the data buffer.

[0036] Step S202, decrypt the second encryption key in the data to be decrypted according to the target object key identifier to obtain the target preset data key, and decrypt the second data ciphertext in the data to be decrypted according to the target preset data key to obtain the data plaintext.

[0037] In steps S201 to S202 of some embodiments, when the data processing type is the read processing type, the read data needs to be decrypted. Specifically, the data to be decrypted is obtained from the data buffer of the object storage service protocol client. The data to be decrypted at least includes a second data ciphertext and a second encryption key, which facilitates the subsequent decryption operation of the data to be decrypted, realizes the accurate decryption of the data to be decrypted, and all the data to be decrypted is downloaded from the server through the object storage service protocol and then stored in the data buffer, realizing the real-time update of the data in the data buffer for subsequent use, facilitating the subsequent encryption and decryption operations of the data, and accelerating the efficiency of the data encryption and decryption operations. Then, the second encryption key in the data to be decrypted is decrypted according to the target object key identifier. Specifically, the target object key identifier and the second data ciphertext are used as parameters to decrypt the second encryption key to obtain the target preset data key, and the second data ciphertext in the data to be decrypted is decrypted according to the target preset data key to obtain the data plaintext, so as to ensure the security and correctness of the data while ensuring the integrity of the data.

[0038] Refer to Figure 3 , Figure 3 FIG. is a specific method flowchart for encrypting the data to be encrypted according to the target preset data key corresponding to the target object key identifier provided by an embodiment of the present application. The method includes but is not limited to steps S301 to S303.

[0039] Step S301: Segment the data to be encrypted with a preset segment length to obtain multiple data segments.

[0040] Step S302: For each data segment, encrypt the data segment according to a preset encryption algorithm and the target preset data key corresponding to the target object key identifier to obtain an encrypted segment.

[0041] Step S303: Concatenate all the encrypted segments to obtain a first data ciphertext.

[0042] In steps S301 to S303 of some embodiments, during the process of encrypting the data to be encrypted written according to the target preset data key corresponding to the target object key identifier, the embodiments of the present application will perform segmented encryption on the data to be encrypted. Specifically, the embodiments of the present application segment the data to be encrypted with a preset segment length to divide the data to be encrypted into multiple data segments. For each data segment, an encryption operation is performed on the data segment according to the preset encryption algorithm and the target preset data key corresponding to the target object key identifier. Specifically, the embodiments of the present application will select a suitable symmetric encryption algorithm to generate a random initialization vector to ensure that different ciphertexts can be generated after encrypting the same plaintext, and then encrypt the data in the data segment through the target object key identifier and the initialization vector to obtain an encrypted segment, thereby ensuring data confidentiality. In addition, a hash check code corresponding to the data segment will be generated through the Hash-based Message Authentication Code (HMAC) algorithm, which is convenient for verifying whether the decrypted data is complete through the hash check code in the future. In addition, during the process of encrypting the data segment, the embodiments of the present application will also record information such as the original length of each data segment before encryption, the encrypted segment length after encryption, and the hash check code to obtain segment information corresponding to the encrypted segment, thereby enhancing the randomness and security of encryption. After that, all encrypted segments are concatenated to generate a payload, and the payload is used as the first data ciphertext, thereby providing self-descriptiveness and data integrity verification.

[0043] It should be noted that the preset segment length in the embodiments of the present application can be set by the user according to needs. For example, the segment size can be set to 120KB, 150KB, etc. The preset segment length in the embodiments of the present application is 128KB; the encryption algorithm can be set by the user according to needs. For example, AES (Advanced Encryption Standard), SM4 (SM4 Block Cipher), etc. The embodiments of the present application do not make specific limitations.

[0044] Refer to Figure 4 , Figure 4 is a specific method flowchart for generating target data according to the first data ciphertext and the first encryption key provided by an embodiment of the present application. The method includes but is not limited to steps S401 to S402.

[0045] Step S401, record the original length of the data to be encrypted written and the segment information corresponding to the encrypted segment, and generate an encryption information digest according to the encryption algorithm, the first encryption key, the target object key identifier in the first data ciphertext, the segment information, and the original length.

[0046] Step S402: Perform data encapsulation on the first data ciphertext and the encrypted information digest to obtain the target data.

[0047] In steps S401 to S402 of some embodiments, in the process of generating the target data based on the first data ciphertext and the first encryption key, the embodiments of the present application first record the original length of the data to be encrypted written and the segmentation information corresponding to the encryption segments, and also add the necessary information in the encryption process to the encrypted information digest. Specifically, the encrypted information digest is generated according to the encryption algorithm, the first encryption key, the target object key identifier in the first data ciphertext, the segmentation information, and the original length, so as to store the necessary information in the encryption process, be able to completely record the parameters required for encryption, facilitate subsequent decryption operations, and then perform data encapsulation on the first data ciphertext and the encrypted information digest to implement the encapsulation of the encrypted data, obtain the target data, ensure the integrity of the data, and ensure that the correct parameters can be used to restore the data during subsequent decryption.

[0048] It should be noted that the embodiments of the present application can encapsulate the first data ciphertext and the encrypted information digest into a file in a specific format, and save the encapsulated file with the original file name. The embodiments of the present application do not make specific restrictions.

[0049] Refer to Figure 5 , Figure 5 is a specific method flowchart for performing data encapsulation on the first data ciphertext and the encrypted information digest provided by an embodiment of the present application. The data access method includes but is not limited to steps S501 to S504.

[0050] Step S501: Perform data encapsulation on the first data ciphertext and the encrypted information digest to obtain the main body information, and generate a file identifier corresponding to the main body information.

[0051] Step S502: Record the first offset of the first data ciphertext in the data to be encrypted and the second offset of the encrypted information digest in the data to be encrypted.

[0052] Step S503: Generate file entry record information according to the first offset, the second offset, and the original length.

[0053] Step S504: Perform encapsulation on the file identifier, the main body information, and the file entry record information to obtain the target data.

[0054] In steps S501 to S504 of some embodiments, in the process of data encapsulation of the first data ciphertext and the encrypted information digest, the embodiments of the present application first perform data encapsulation on the first data ciphertext and the encrypted information digest to obtain the main body information. Specifically, in the data encapsulation process, the embodiments of the present application use the first data ciphertext as the front part and the encrypted information digest as the rear part, and generate a file identifier corresponding to the main body information. The file identifier can be a magic number, so as to uniquely identify the type of the file. The embodiments of the present application also record the first offset of the first data ciphertext in the data to be encrypted and the second offset of the encrypted information digest in the data to be encrypted, so as to obtain the specific positions of the first data ciphertext and the encrypted information digest in the data to be encrypted, which is convenient for quickly locating the segmented information later. Then, the file entry record information is generated according to the first offset, the second offset and the original length. Through the file entry record information, the reading overhead can be reduced, the access performance can be improved, and the decryption performance can be optimized at the same time. Then, the file identifier, the main body information and the file entry record information are encapsulated to obtain the target data. Specifically, the file identifier is encapsulated as the file header, the main body information is encapsulated as the file body, and the file entry record information is encapsulated as the file tail to obtain the target data, realizing streaming data processing, improving the encryption and decryption processing efficiency, and being beneficial to improving the response speed of the system to the object storage service protocol client's operation of obtaining file information.

[0055] Refer to Figure 6 , Figure 6 FIG. is a specific method flowchart for obtaining the data to be decrypted from the data buffer of the object storage service protocol client provided by an embodiment of the present application. The method includes but is not limited to steps S601 to S602.

[0056] Step S601, when there is data to be decrypted stored in the data buffer of the object storage service protocol client, obtain the data to be decrypted from the data buffer of the object storage service protocol client.

[0057] In step S601 of some embodiments, in the process of obtaining the data to be decrypted from the data buffer of the object storage service protocol client, the embodiments of the present application first need to determine whether there is data to be decrypted stored in the data buffer of the object storage service protocol client. When there is data to be decrypted stored in the data buffer of the object storage service protocol client, the data to be decrypted can be directly obtained from the data buffer of the object storage service protocol client, which can accelerate the data decryption efficiency.

[0058] Step S602: When the data buffer of the object storage service protocol client does not store the data to be decrypted, download the data to be decrypted from the server through the object storage service protocol, so as to store the data to be decrypted into the data buffer of the object storage service protocol client, and obtain the data to be decrypted from the data buffer of the object storage service protocol client.

[0059] In step S602 of some embodiments, when the data buffer of the object storage service protocol client does not store the data to be decrypted, it is necessary to send a request to the server through the object storage service protocol to download the data to be decrypted, so as to store the data to be decrypted into the data buffer, realize real-time update of the data in the data buffer for subsequent use, facilitate subsequent data encryption and decryption operations, accelerate the efficiency of data encryption and decryption operations, and obtain the data to be decrypted from the data buffer of the object storage service protocol client to realize reading of the data to be decrypted.

[0060] Refer to Figure 7 , Figure 7 is a specific method flowchart for decrypting the data ciphertext in the data to be decrypted according to the target preset data key provided by an embodiment of the present application. The method includes but is not limited to steps S701 to S708.

[0061] Step S701: Determine the third offset of the data ciphertext in the data to be decrypted according to the data processing request.

[0062] Step S702: Read the file information of the data to be decrypted to obtain the digest to be decrypted in the file body and the fourth offset in the file tail, where the fourth offset is the offset of the second data ciphertext in the data to be decrypted.

[0063] Step S703: Obtain the original information length of the data to be decrypted and the ciphertext length of the data ciphertext in the data to be decrypted.

[0064] Step S704: Determine the target data length according to the original information length and the ciphertext length.

[0065] Step S705: Parse the digest to be decrypted to obtain the original segment length and the encrypted segment length of the segment to be decrypted in the data to be decrypted.

[0066] Step S706: Determine the number range of the data ciphertext according to the original segment length, the third offset, and the target data length.

[0067] Step S707: Determine the target decryption range according to the number range, the fourth offset, and the encrypted segment length.

[0068] Step S708: Perform a decryption operation on the target decryption range through the target preset data key to obtain the data plaintext.

[0069] In steps S701 to S708 of some embodiments, in the process of decrypting the data ciphertext in the data to be decrypted according to the target preset data key, the embodiment of the present application first determines the third offset of the data ciphertext in the data to be decrypted according to the data processing request, and then reads the file information of the data to be decrypted, that is, reads parts such as the file header, file body, and file tail of the data to be decrypted, so as to obtain the digest to be decrypted in the file body and the fourth offset stored in the file tail, and further can obtain the offset of the second data ciphertext in the data to be decrypted. After that, the original information length of the data to be decrypted and the ciphertext length of the data ciphertext in the data to be decrypted are obtained, which is convenient for subsequent comparison of the original information length and the ciphertext length. The target data length is determined according to the original information length and the ciphertext length to avoid the situation where the ciphertext length exceeds the original information length. Since the decryption digest stores the encryption algorithm, the target object key identifier, the original segment length of each segment to be decrypted, and the original segment length before encryption of each segment to be decrypted, the embodiment of the present application will parse the decryption digest to read the above information, and then determine the number range of the data ciphertext according to the original segment length, the third offset, and the target data length, that is, determine the number range of the segment where the data ciphertext is located in the data to be decrypted. By determining the number range, the data range that needs to be decrypted can be accurately located, avoiding decrypting the entire file. After that, the target decryption range is determined according to the number range, the fourth offset, and the encrypted segment length, that is, the range where the data that the user needs to decrypt is located, reducing unnecessary decryption operations. Then, the target decryption range is decrypted by the target preset data key to obtain the data plaintext, ensuring the integrity of the data while ensuring the security and correctness of the data.

[0070] Refer to Figure 8 , Figure 8 FIG. is a specific method flowchart for determining the target data length according to the original information length and the ciphertext length provided by an embodiment of the present application. The method includes but is not limited to steps S801 to S802.

[0071] Step S801, when the original information length is greater than or equal to the ciphertext length, determine the ciphertext length as the target data length.

[0072] In step S801 of some embodiments, in the process of determining the target data length according to the original information length and the ciphertext length, the embodiment of the present application will compare the original information length of the data to be decrypted and the ciphertext length of the data ciphertext in the data to be decrypted. When the original information length is greater than or equal to the ciphertext length, the ciphertext length can be directly determined as the target data length, which is convenient for subsequent decryption operations on the data ciphertext.

[0073] Step S802: When the length of the original information is less than the length of the ciphertext, determine the length of the target data according to the length of the original information and the third offset.

[0074] In step S802 of some embodiments, when the length of the original information is less than the length of the ciphertext, it indicates that the ciphertext of the data requested by the user for decryption exceeds the length of the original information of the data to be decrypted. At this time, it is necessary to intercept the length of the ciphertext. Specifically, determine the length of the target data according to the length of the original information and the third offset of the data ciphertext in the data to be decrypted. At this time, the length of the target data is the difference between the length of the original information and the third offset, thus avoiding the situation where the user's requested area exceeds the length of the original information.

[0075] Refer to Figure 9 , Figure 9 is a specific method flowchart for determining the length of the target data according to the length of the original information and the length of the ciphertext provided by an embodiment of the present application. The method includes but is not limited to step S901.

[0076] It should be noted that step S901 occurs after obtaining the data processing request.

[0077] Step S901: When the data processing type is a non-read / write type, send the data processing request to the server through the object storage service protocol, so that the server executes the access operation corresponding to the data processing request, and receive the response message returned by the server after executing the access operation.

[0078] In step S901 of some embodiments, when the data processing type is a non-read / write type, for example, the data processing type is a create type, a read directory type, etc., at this time, directly send the data processing request to the server through the object storage service protocol, so that the server executes the access operation corresponding to the data processing request, and receive the response message returned by the server after executing the access operation, thereby realizing efficient data access and improving the efficiency of data access.

[0079] It should be noted that the non-read / write type in the embodiments of the present application is a type used for the structure of the directory or metadata, and this type is used to modify the metadata of the directory, such as directory entries, link counts, sub-item names, etc. The embodiments of the present application do not make specific limitations.

[0080] Refer to Figure 10 , Figure 10 is a schematic diagram of a data access device provided by an embodiment of the present application.

[0081] In some embodiments, the data access device is applied to an object storage service protocol client and includes: A file access module 901, configured to obtain a data processing request, where the data processing request carries a data processing type and a target object key identifier; The data cache module 902 is used to, when the data processing type is the write processing type, encrypt the data to be encrypted written according to the target preset data key corresponding to the target object key identifier to obtain the first data ciphertext, and encrypt the target preset data key according to the target object key identifier to obtain the first encryption key; The data encryption and decryption module 903 is used to generate target data according to the first data ciphertext and the first encryption key, and transmit the target data to the data buffer area, so as to write the target data in the data buffer area to the server through the object storage service protocol.

[0082] In some embodiments, the data cache module 902 is further used to, when the data processing type is the read processing type, obtain the data to be decrypted from the data buffer area of the object storage service protocol client. The data to be decrypted at least includes the second data ciphertext and the second encryption key. The data to be decrypted is stored in the data buffer area after being downloaded from the server through the object storage service protocol.

[0083] The data encryption and decryption module 903 is further used to decrypt the second encryption key in the data to be decrypted according to the target object key identifier to obtain the target preset data key, and decrypt the data ciphertext in the data to be decrypted according to the target preset data key to obtain the data plaintext.

[0084] In some embodiments, the specific implementation manner of the data access device is basically the same as that of the above-mentioned data access method, and will not be elaborated here.

[0085] To more clearly illustrate the above data access method, specific examples are given below for illustration.

[0086] Example 1: The data access system in Example 1 integrates FUSE (Filesystem in Userspace), converts S3 protocol data processing into common file system operations, and integrates data encryption and decryption functions to support streaming data encryption and decryption operations. Existing applications and systems of users do not need to handle complex data encryption and decryption transactions, nor do they need to perform secondary development. They only need to use the common POSIX (Portable Operating System Interface) to access the file system to achieve transparent S3 protocol data encryption and decryption, and the encryption and decryption of data are both processed locally, effectively realizing the complete control of the data owner over the data on the cloud.

[0087] The data access method of the present application will be specifically described below.

[0088] Refer to Figure 11 , Figure 11It is a system example diagram of the data access system provided by an example of this application.

[0089] In some embodiments, the data access system includes, but is not limited to, an S3 protocol client module, a data cache module, a data encryption / decryption module, a key management module, and a file system module.

[0090] Among them, the S3 protocol client module uses the S3 protocol to interact with an OBS (Object Based Storage) server to implement data acquisition and data upload. The data cache module can cache cloud-encrypted data and directory information to speed up data reading and improve the system response speed. The encryption / decryption module is responsible for generating and decrypting encrypted data to implement streaming encryption / decryption of data. The key management module cooperates with an external KMS to be responsible for encrypting and decrypting the data encryption key dataKey. The file system module provides a file system POSIX access interface for user applications based on FUSE and provides corresponding responses to different requests of user applications.

[0091] In some embodiments, before data access, a system initialization operation will be performed. Specifically, the user provides relevant access parameters of the OBS server (such as Access Key and Secret Access Key), as well as relevant parameters of the KMS key management service (API Token).

[0092] The user specifies that the system mounts the bucket and the directory in the bucket (such as s3: / / bucket / dir / ) on the OBS server to a specified directory on the local operating system (such as / mnt).

[0093] After that, the user application accesses the files on the OBS server through the POSIX API interface provided by the file system module, and the file system module provides different processing and responses according to different API requests.

[0094] Specifically, the embodiments of this application perform different operations on different types of requests. The specific process is as follows: For operations such as mkdir and readdir, directly call the S3 protocol client to interact with the OBS service to implement the corresponding functions.

[0095] For data read and data write operations, the data encryption / decryption module performs data encryption or decryption operations.

[0096] In some embodiments, the encryption / decryption module performs encryption or decryption operations on data. When the user application performs a data read operation, the encryption / decryption module reads and decrypts the cloud data through the data caching module and returns the decrypted plaintext. When the user application performs a data write operation, the encryption / decryption module first encrypts the data and then hands it over to the data caching module for processing. Subsequently, the data caching module uploads the data to the corresponding bucket and directory on the OBS server through background asynchronous operations.

[0097] The data caching module provides a data caching mechanism. When processing a read operation, for a relatively small file (e.g., less than 10M bytes, which can be customized), the data caching module directly downloads the entire file to the local cache through the s3 protocol client. For a larger file, the data caching module divides the file into multiple parts and downloads them in parallel.

[0098] Specifically, when the encryption / decryption module requests to read a specific file segment, the data caching module will download the chunk where this segment is located and the subsequent 4 segments (a total of 5 segments, which is equivalent to caching a part of the pre-read content). Each chunk is downloaded through an independent S3 GET request, and multiple requests are sent simultaneously in the embodiments of the present application to obtain different file chunks. Each request will include the data range (Range) of the chunk, informing the S3 server of the area to be downloaded. For example: Range: bytes=0-10485759 / / The first shard (0-10MB); Range: bytes=10485760- 20971519 / / The second shard (10-20MB); Each downloaded file part (chunk) is stored in the local cache. When the user requests again next time, the required content is directly retrieved from the cache.

[0099] For the write operation, the data caching module will first write the data to the local cache and then upload the data to the OBS server through the s3 protocol client using asynchronous operations.

[0100] Finally, the s3 protocol client interacts with the OBS server through the specific S3 protocol to implement operations such as data acquisition and data upload.

[0101] In some embodiments, the user's data is encrypted and decrypted locally. The OBS server only stores the encrypted data. The user truly holds the ownership of the data, effectively preventing the server from leaking data, and there is no need for the user to trust the service provider. Moreover, the user application accesses the data through a standardized file system interface. During the file access process, the application is completely unaware of the data encryption, decryption, and protocol transmission. Existing applications and systems can be directly adapted without large-scale modification, which can not only avoid the technical challenges brought by the upgrade of existing systems but also reduce the system access cost and complexity.

[0102] Example 2: Example 2 is a specific example in which the data encryption and decryption module encrypts the data written by the user application and encapsulates it into a specific format.

[0103] First, the data encryption and decryption module generates a random data encryption key dataKey (target preset data key) for each file to be encrypted. Then, the data is encrypted using a symmetric encryption algorithm (such as AES, SM4 can be selected) with dataKey, and the encrypted payload (the first data ciphertext) is generated after encryption.

[0104] Refer to Figure 12 , Figure 12 which is a schematic diagram of the data segment encryption process provided by an example of this application.

[0105] In some embodiments, the data encryption is performed in fixed segment sizes, and the segment size can be customized, with a default of 128 KB. Each data segment segment is encrypted to generate an encrypted segment encSegment after encryption. encSegment contains the encrypted data and the hash check code of the data plaintext. The hash check code is used to verify whether the content has been tampered with or has an error. Multiple encrypted data segments encSegment are connected to generate the payload.

[0106] Among them, the hash value is generated by taking the data segment segment before encryption and the key as inputs and then through the hmac algorithm.

[0107] The lengths of each data segment and the hash check code are recorded in the segment information segInfo. The content recorded in segInfo includes: the original data length segSize, the encrypted data length encSegSize, and the hash check code of each segment segment. The content of segInfo is as follows: "segInfo":[{" "segSize":131072 "encSegSize":131100, "hash":"NDA3OTY5YjI0M2JjNmIyMGRhM2FlMmMwYmNlNTFhN2Y=", }, { "segSize":131072 "encSegSize":131100, "hash":"ODVhMTU0ZGEyNDNiMmZmZjQ0MzY2ZTY5NzhkODUwNjU=", } After that, the data encryption and decryption module calls the encryption function of the key management module to encrypt the dataKey to obtain the wrapped key (the first encryption key), and at the same time records the user master key identifier KeyId (the target object key identifier) used for encryption.

[0108] The data encryption and decryption module also adds the necessary information in the encryption process to the encryption information digest manifest. The manifest is stored in JSON text format, and the content includes: the encryption algorithm used for encrypting the file (such as AES-256-GCM), the wrapped key wrappedKey generated after encrypting the dataKey, the user master key identifier KeyId used for encrypting the dataKey, the segmentation information segInfo of the file encryption process, and the original length dataSize of the file before encryption.

[0109] Refer to Figure 13 , Figure 13 which is the structural schematic diagram of the encapsulation format provided by an example of this application.

[0110] The data encryption and decryption module encapsulates the payload and the encryption information digest manifest into a file in a specific format, and the encapsulated file is saved with the original file name.

[0111] In some embodiments, the structure of the encapsulation format mainly includes a file header, a file body, and a file entry record. Among them, the file header includes a magic number file for identifying different types of files. The file body contains the encrypted payload and the encryption information digest manifest. The payload is in the front and the manifest is in the back. The file entry record is used to record the offset and file length information of the encapsulated payload and manifest in the current file.

[0112] By encapsulating the data as Figure 13 ​The format can achieve streaming data processing, improve the encryption and decryption processing efficiency, and save the original file length dataSize before file encryption in the manifest, which is beneficial to improving the response speed of the system to the client's operation of obtaining file information.

[0113] In some embodiments, by designing a reasonable encrypted file structure and based on the segmented encryption and decryption method and data caching technology, the encryption and decryption operations can be parallel with data transmission, reducing the latency in the data transmission and processing process and improving the system response speed.

[0114] Example 3: Example 3 is a specific example of the data encryption and decryption module decrypting the data read by the user application.

[0115] In some embodiments, the user application's read access request for file data is random (it can read data at any position), and the request contains the offset offset of the data to be read in the original file and the length length of the data to be read. The data encryption and decryption module decrypts specific data segments and returns the plaintext data requested by the user application.

[0116] The specific data decryption process is as follows: First, the data encryption and decryption module reads the file entry record information from the fileEntry at the end of the encrypted file to obtain the offsets and lengths of the manifest and payload in the file content; then reads the content of the manifest from the encrypted file and parses it to obtain the segment information segInfo of the payload and the wrapped key (the second encryption key) from the manifest.

[0117] After that, the data encryption and decryption module calls the key management module to decrypt the wrapped key to obtain the data encryption key dataKey (the target preset data key); The data encryption and decryption module decrypts specific data segments in the payload using the key dataKey obtained in the previous step according to the encryption algorithm recorded in the manifest file, obtains the plaintext data specified by the user application request, and returns it.

[0118] Refer to Figure 14 , Figure 14 is a schematic diagram of the data segment decryption process provided by an example of this application.

[0119] In some embodiments, during the process of decrypting data, the embodiments of the present application first intercept the length of length to prevent the area requested by the client from exceeding the length dataSize of the original data. If it exceeds the length of the original data, the intercepted length of length is (dataSize–offset).

[0120] Then calculate the corresponding number range segment (N, M) of the segment segment where the data requested by the user is located.

[0121] N = floor(offset / segSize), where floor is rounding down; M = ceil((offset + length) / segSize), where ceil is rounding up; After that, read these segments segment from the encrypted file. Calculate the offset payload_offset and length payload_length of the segment to be decrypted in the encrypted file. Among them, payload_index is the offset of payload in the encrypted file, payload_length is the length of these segments, and encSegSize represents the size of the encrypted segment.

[0122] payload_offset = payload_index + N * encSegSize; payload_length = (M - N + 1) * encSegSize.

[0123] The data encryption and decryption module also uses the data encryption key dataKey to decrypt the encrypted segment data from number N to N+m to obtain the data message before encryption. During the decryption process of each segment, the hash check code of each segment recorded in the manifest is used for verification to ensure the integrity of the data. Then return the plaintext data requested by the user application to the upper-layer application.

[0124] Refer to Figure 15 , Figure 15 is a schematic structural diagram of an electronic device provided by an embodiment of the present application.

[0125] Figure 15Take, for example, that the control processor 1001 and the memory 1002 in the electronic device 1000 can be connected via a bus. As a non-transitory computer-readable storage medium, the memory 1002 can be used to store non-transitory software programs and non-transitory computer-executable programs. In addition, the memory 1002 can include high-speed random access memory and can also include non-transitory memory, such as at least one disk memory, flash memory devices, or other non-transitory solid-state storage devices. In some embodiments, the memory 1002 optionally includes a memory remotely located relative to the control processor 1001, and these remote memories can be connected to the electronic device 1000 via a network. Examples of the above networks include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.

[0126] Those skilled in the art can understand that Figure 15 the device structure shown in does not constitute a limitation on the electronic device 1000, and it may include more or fewer components than shown in the figure, or combine certain components, or have different component arrangements.

[0127] The embodiments of the present application also provide a computer-readable storage medium storing computer-executable instructions, which are executed by one or more control processors, for example, by Figure 15 one of the control processors 1001 in, enabling the above one or more control processors to execute the data access method in the above method embodiments.

[0128] It should be noted that the electronic device in the embodiments of the present application can be a front-end corresponding terminal device or a back-end corresponding background server.

[0129] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separated, that is, they may be located in one place or distributed to multiple network units. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0130] Those of ordinary skill in the art will understand that all or some of the steps and systems disclosed in the above methods can be implemented as software, firmware, hardware, and appropriate combinations thereof. Some physical components or all physical components can be implemented as software executed by a processor, such as a central processing unit, a digital signal processor, or a microprocessor, or can be implemented as hardware, or can be implemented as an integrated circuit, such as an application-specific integrated circuit. Such software can be distributed on a computer-readable medium, which can include a computer storage medium (or non-transitory medium) and a communication medium (or transitory medium). As is well known to those of ordinary skill in the art, the term computer storage medium includes volatile and non-volatile, removable and non-removable media implemented in any method or technology for storing information, such as computer-readable instructions, data structures, program modules, or other data. Computer storage media includes, but is not limited to, RAM, ROM, EEPROM, flash memory or other memory technologies, CD-ROM, digital versatile disks (DVDs) or other optical disk storage, magnetic cassettes, magnetic tape, magnetic disk storage or other magnetic storage devices, or any other medium that can be used to store the desired information and can be accessed by a computer. In addition, it is well known to those of ordinary skill in the art that communication media typically contains computer-readable instructions, data structures, program modules, or other data in a modulated data signal such as a carrier wave or other transmission mechanism, and can include any information delivery medium.

Claims

1. A data access method, characterized in that, Applied to an object storage service protocol client, the data access method includes: Obtain a data processing request, where the data processing request carries a data processing type and a target object key identifier; When the data processing type is a write processing type, encrypt the data to be encrypted for writing according to the target preset data key corresponding to the target object key identifier to obtain a first data ciphertext, and encrypt the target preset data key according to the target object key identifier to obtain a first encryption key; Generate target data based on the first data ciphertext and the first encryption key, and transmit the target data to the data buffer of the object storage service protocol client, so as to write the target data in the data buffer to the server through the object storage service protocol.

2. The data access method according to claim 1, wherein After obtaining the data processing request, the data access method further includes: When the data processing type is a read processing type, obtain the data to be decrypted from the data buffer of the object storage service protocol client, where the data to be decrypted includes at least a second data ciphertext and a second encryption key, and the data to be decrypted is stored in the data buffer after being downloaded from the server through the object storage service protocol; Decrypt the second encryption key in the data to be decrypted according to the target object key identifier to obtain a target preset data key, and decrypt the second data ciphertext in the data to be decrypted according to the target preset data key to obtain the data plaintext.

3. The data access method according to claim 1, wherein The encrypting the data to be encrypted for writing according to the target preset data key corresponding to the target object key identifier to obtain a first data ciphertext includes: Perform data segmentation on the data to be encrypted at a preset segmentation length to obtain a plurality of data segments; For each of the data segments, perform an encryption operation on the data segment according to a preset encryption algorithm and the target preset data key corresponding to the target object key identifier to obtain an encrypted segment; Connect all the encrypted segments to obtain a first data ciphertext.

4. The data access method according to claim 3, wherein The generating the target data based on the first data ciphertext and the first encryption key includes: Record the original length of the data to be encrypted for writing and the segmentation information corresponding to the encrypted segment, and generate an encrypted information digest according to the encryption algorithm, the first encryption key, the target object key identifier in the first data ciphertext, the segmentation information, and the original length; Perform data encapsulation on the first data ciphertext and the encrypted information digest to obtain target data.

5. The data access method according to claim 4, wherein The performing data encapsulation on the first data ciphertext and the encrypted information digest to obtain target data includes: Perform data encapsulation on the first data ciphertext and the encrypted information digest to obtain body information, and generate a file identifier corresponding to the body information; Record the first offset of the first data ciphertext in the data to be encrypted and the second offset of the encrypted information digest in the data to be encrypted; Generate file entry record information according to the first offset, the second offset, and the original length; Encapsulate the file identifier, the subject information, and the file entry record information to obtain target data.

6. The data access method according to claim 2, wherein The obtaining of the data to be decrypted from the data buffer of the object storage service protocol client includes: When there is data to be decrypted stored in the data buffer of the object storage service protocol client, obtain the data to be decrypted from the data buffer of the object storage service protocol client; When there is no data to be decrypted stored in the data buffer of the object storage service protocol client, download the data to be decrypted from the server through the object storage service protocol, store the data to be decrypted in the data buffer of the object storage service protocol client, and obtain the data to be decrypted from the data buffer of the object storage service protocol client.

7. The data access method according to claim 2, wherein The decrypting of the data ciphertext in the data to be decrypted according to the target preset data key to obtain the data plaintext includes: Determine the third offset of the data ciphertext in the data to be decrypted according to the data processing request; Read the file information of the data to be decrypted to obtain the digest to be decrypted in the file body and the fourth offset in the file tail, where the fourth offset is the offset of the second data ciphertext in the data to be decrypted; Obtain the original information length of the data to be decrypted and the ciphertext length of the data ciphertext in the data to be decrypted; Determine the target data length according to the original information length and the ciphertext length; Parse the digest to be decrypted to obtain the original segment length and the encrypted segment length of the segment to be decrypted in the data to be decrypted; Determine the number range of the data ciphertext according to the original segment length, the third offset, and the target data length; Determine the target decryption range according to the number range, the fourth offset, and the encrypted segment length; Perform a decryption operation on the target decryption range through the target preset data key to obtain the data plaintext.

8. The data access method according to claim 7, characterized in that The determining of the target data length according to the original information length and the ciphertext length includes: When the original information length is greater than or equal to the ciphertext length, determine the ciphertext length as the target data length; When the original information length is less than the ciphertext length, determine the target data length according to the original information length and the third offset.

9. The data access method according to claim 1, wherein After obtaining the data processing request, the data access method further includes: When the data processing type is a non-read / write type, send the data processing request to the server through the object storage service protocol, so that the server executes the access operation corresponding to the data processing request, and receive the response message returned by the server after executing the access operation.

10. A data access device, characterized in that Applied to an object storage service protocol client; the data access device includes: A file access module, configured to obtain a data processing request, where the data processing request carries a data processing type and a target object key identifier; A data caching module, configured to, when the data processing type is a write processing type, encrypt the data to be encrypted in the write operation according to a target preset data key corresponding to the target object key identifier, to obtain a first data ciphertext, and encrypt the target preset data key according to the target object key identifier, to obtain a first encryption key; A data encryption and decryption module, configured to generate target data according to the first data ciphertext and the first encryption key, and transmit the target data to a data cache area of the object storage service protocol client, so as to write the target data in the data cache area to a server through the object storage service protocol.

11. An electronic device, characterized in that, It includes at least one processor and a memory for communicatively connecting with the at least one processor; the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor, so that the at least one processor can execute the data access method according to any one of claims 1 to 9.

12. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer-executable instructions for causing a computer to execute the data access method according to any one of claims 1 to 9.

Citation Information

Cited By

  • Security chip encryption design method based on data source

    CN122372329A

  • A data source-based security chip encryption method

    CN122372329B