Information security data storage method and system

By splitting and encrypting smart home appliance data on a cloud server, and combining it with device information for dynamic storage and migration, the security and anti-attack issues of smart home storage solutions are solved, achieving highly secure and reliable data storage and access.

CN120602157BActive Publication Date: 2025-12-23SHENZHEN XIROS TECHNOLOGY CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510769617.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-06-10
Publication Date
2025-12-23
Estimated Expiration
2045-06-10

AI Technical Summary

Technical Problem

Existing smart home information storage solutions suffer from a single storage structure, centralized data that is vulnerable to attack, and a lack of dynamic fragmentation encryption, self-detection, and risk-driven data migration mechanisms, resulting in security blind spots and a high risk of sensitive data leakage.

Method used

The data collected by smart home appliances is split into sub-data slices by cloud servers, and then encrypted and transformed for storage in combination with device information. The storage status is monitored in real time, migration priority is dynamically calculated, and data migration is carried out using a secure transmission protocol. The data is then decrypted and recovered in collaboration with the devices.

Benefits of technology

It achieves multi-source heterogeneous, dynamic, and random distributed data stealth storage, reduces the risk of single-point leakage, improves the security and concealment of physical data distribution, enhances anti-attack and operational resilience, and ensures secure control over data access.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120602157B_ABST
    Figure CN120602157B_ABST
Patent Text Reader

Abstract

The application discloses an information security data storage method and system, and relates to the technical field of electronic information.The method transmits complete data D collected by a smart home appliance device to a cloud server for preprocessing, adopts XOR exclusive or encryption, a SHA-512 hash function and a large prime modulus algorithm for data fragmentation, generates a plurality of sub-data pieces Dz, combines local system time T of the smart home appliance device, a device key K, true random number R and other information, and calculates a storage position L of each sub-data piece Dz.Based on the storage position, the sub-data pieces are dynamically encrypted and transformed to form encrypted data E, which is distributed and stored in a plurality of smart home appliance devices, thereby constructing a multi-source heterogeneous and dynamically random distributed data invisible storage system.The method effectively reduces the risk of single-point leakage and improves the physical distribution security and concealment of data at the device level.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the field of electronic information technology, in particular to an information security data storage method and system. BACKGROUND

[0002] Information security belongs to the sub-field of network information security storage, in particular, a distributed encryption storage and dynamic stealth distribution method applied to a smart home system. In the current smart home scenario, devices such as smart speakers, cameras, door locks, refrigerators, lighting systems, etc. continuously collect high-sensitivity data such as user voice, image, behavior trajectory and use preference, and the storage security of such data in the cloud or local end directly affects the user privacy protection ability and system attack resistance. Therefore, how to improve the anti-attack ability, distribution security and dynamic concealment of data storage without relying on special encryption hardware has become an important research direction of smart home information security.

[0003] The existing smart home information storage scheme at the present stage generally has the defects of single storage structure, centralized data and vulnerability to attack. Most systems use the method of uploading smart device data to the cloud platform for centralized storage, which is convenient to manage, but once the cloud server is attacked, it may lead to large-scale sensitive data leakage. At the same time, although part of the local storage scheme can avoid cloud dependence, since the data is not dynamically sharded or encrypted distributed, the attacker only needs to break through a single device to access the complete data content. Moreover, the existing system does not have a self-detection and risk-driven data migration mechanism after storage, and cannot automatically adjust the data layout according to the device risk state, thereby forming a security blind area. SUMMARY

[0004] In view of the deficiencies of the prior art, the present application provides an information security data storage method and system, which solves the problems mentioned in the background art.

[0005] To achieve the above purpose, the present application is realized by the following technical scheme: comprising the following steps:

[0006] S1, a cloud server is constructed and integrated with smart home appliances, complete data D collected by the smart home appliances is transmitted to the cloud server, the complete data D is split into a plurality of sub-data pieces Dz in the cloud server, and the storage information of the smart home appliances is extracted;

[0007] S2, calculating the storage location L based on the storage information, and extracting the sub-data piece Dz and the storage location L combined with the storage information, encrypting and transforming the stored data to obtain encrypted data E, and dynamically and stealthily storing and encrypting the sub-data piece Dz;

[0008] S3. During the data storage process, the storage status data of the smart home appliance is periodically detected and extracted. Based on the storage status data, the data migration priority Q is calculated, and the migration threshold F1 is set to compare and evaluate the migration with the migration priority Q. The migration status is judged, and the sub-data fragment Dz stored in the source smart home appliance is deleted.

[0009] S4. When a user requests data, several smart home appliances work together to concatenate keys, calculate the decryption key KD, and decrypt the data based on the decryption key KD to recover the complete data D.

[0010] Preferably, S1 includes S11 and S12;

[0011] S11. Construct a cloud server by using a WIFI wireless communication network and the secure transmission protocol TLS1.3 to integrate smart home appliances with the cloud server, and number the storage units of the smart home appliances from 0 to M-1.

[0012] Then, the complete data D is collected in real time through smart home appliances, and the complete data D is transmitted to the cloud server every 24 hours. In the cloud server, XOR encryption, SHA-512 hash light and large prime number modulo technology are used to construct the data segmentation formula, and the complete data D of the video data is segmented into several sub-data segments Dz.

[0013] Sub-data slice Dz is processed and output using the following data slice formula;

[0014]

[0015] In the formula, Dz i S represents the sub-data slice of the i-th slice of the complete data D. i H represents the random seed for the i-th slice. SHA-512 This refers to the SHA-512 hash function, which outputs a fixed 512-bit random number. This indicates the XOR encryption operation, mod indicates modulo, and P indicates a large prime number.

[0016] S12. After splitting the complete data D, the stored information is extracted in real time through the built-in devices of the smart home appliances; the stored information includes the local system time T of the j-th smart home appliance. j The device key K for the j-th smart home appliance j Storage occupancy rate U of the i-th smart home appliance j The true random number R of the j-th smart home appliance j Total storage capacity M of smart home appliances;

[0017] The local system time T of the j-th smart home appliance j Convert to string format.

[0018] Preferably, S2 includes S21 and S22;

[0019] S21. Extract the local system time T of the j-th smart home appliance from the stored information. j The device key K for the j-th smart home appliance j And the true random number R of the j-th smart home appliance j The system dynamically calculates and outputs the storage location L of the sub-data fragment Dz on the smart home appliance, and based on the output storage location L, sends the sub-data fragment Dz from the cloud server to different smart home appliances for dynamic invisible storage.

[0020] The storage location L is calculated and output using the following algorithm formula;

[0021]

[0022] In the formula, L Dzi,j This represents the sub-data fragment Dz of the i-th fragment of the complete data D. i Storage location of the j-th smart home appliance, H SHA-256 This indicates the SHA-256 hash function, which outputs a fixed 256-bit random number.

[0023] Preferably, S22, the sub-data slice Dz based on the i-th slice of the complete data D. i Storage location L of the j-th smart home appliance Dzi,j Combined with the device key K of the j-th smart home appliance j Perform encryption transformation, obtain the encrypted data E after encryption transformation, and store it in the corresponding smart home appliance;

[0024] The encrypted data E is encrypted using the following formula;

[0025]

[0026] In the formula, E Dzi,j This represents the sub-data fragment Dz of the i-th fragment of the complete data D. i The encrypted data E after encryption transformation in the j-th smart home appliance.

[0027] Preferably, S3 includes S31, S32 and S33;

[0028] S31. During the data storage process, the intrusion detection system (IDS) and operation monitoring logs of the smart home appliance are run in real time through the API application interface to detect the storage status data of the smart home appliance in the past 24 hours.

[0029] The stored status data includes the number of abnormal events detected in the j-th smart home appliance in the past 24 hours (Nalerts). j The CPU load of the jth smart home appliance is abnormal compared to normal. j The CPU computing power C of the jth smart home appliance j The network transmission rate N of the jth smart home appliance j And the storage utilization rate U of the jth smart home appliance j ;

[0030] The migration priority Q is calculated based on the storage state data, and the sub-data fragment Dz of the i-th partition of the data integrity data D is used to measure the migration priority. i Migration status;

[0031] The migration priority Q is calculated and output using the following algorithm formula;

[0032]

[0033] In the formula, Q Di The migration priority of the sub-data fragments in the i-th fragment of the complete data D is represented by log, 24 represents the detection time, and Δt is the value of Δt. j This represents the time interval between the last migration of the j-th smart home appliance.

[0034] Preferably, in step S32, based on the user setting a migration threshold F1 according to the type of smart home appliance, the migration threshold F1 is then compared with the migration priority Q of the sub-data slice of the i-th slice of the complete data D. Di The migration comparison and evaluation assesses the implementation of the migration strategy. The specific evaluation content is as follows:

[0035] When the migration priority Q of the i-th sub-data fragment of the complete data D is... Di >When the migration threshold F1 is reached, it indicates that the current smart home appliance storage is abnormal, and the data migration strategy is triggered at this time;

[0036] When the migration priority Q of the i-th sub-data fragment of the complete data D is... Di If the value is less than or equal to the migration threshold F1, it indicates that the current smart home appliance storage is normal, and no migration is required.

[0037] Preferably, in step S33, the data migration strategy uses the secure transport protocol TLS 1.3 to migrate the sub-data fragment Dz of the i-th fragment of the current smart device's complete data D. i The data is transmitted to the cloud server, where the storage location L is recalculated and encrypted. This process transforms the i-th fragment of the complete data D into its sub-data fragment Dz. iStore the data to a new storage location L, and then, using a secure erase method, delete the complete data D of the source smart home appliance device, including the sub-data fragment Dz of the i-th fragment. i ;

[0038] The secure erase method erases the complete data D stored in the source smart home appliance after migration through a three-stage write operation, specifically the sub-data fragment Dz of the i-th fragment. i ;

[0039] The first time, write all zeros and clear the data characteristic bits;

[0040] The second time, write all 1s to overwrite the boundary instruction;

[0041] Third, random data is written to prevent pattern inference and reconstruction analysis;

[0042] Finally, perform a final check to verify the integrity of the rewrite, delete the stored table entries, and refresh the cache and persistent logs.

[0043] Preferably, S4 includes S41 and S42;

[0044] S41. When a user requests data, the encrypted data E stored in all smart home appliances and the device key K of the j-th smart home appliance must be collected. j Perform key concatenation and calculate to obtain the decryption key KD;

[0045] The decryption key KD is calculated and output using the following algorithm formula;

[0046]

[0047] In the formula, N represents the total number of smart home appliances. This represents the XOR encryption operation summation symbol, which will perform XOR encryption operations sequentially from the first smart home appliance to the Nth smart home appliance.

[0048] Preferably, in step S42, data decryption is performed based on the decryption key KD and the original key Kor; the concatenation formula is:

[0049]

[0050] In the formula, Drecovered represents the decrypted data, and Koriginal represents the original key. The logical symbol represents "if and only if", which in the formula means that the complete data D can be successfully recovered only if the calculated decryption key KD is exactly the same as the original key Koriginal.

[0051] If the calculated decryption key KD is the same as the original key Koriginal, then the data is recovered;

[0052] If the calculated decryption key KD is not the same as the original key Koriginal, the decryption fails, and the data remains secure.

[0053] An information security data storage system, comprising a data sharding module, a data stealth storage and dynamic encryption module, a data migration module, and a data access and joint decryption module.

[0054] The data sharding module transmits the complete data D collected by the smart home appliance device to the cloud server by constructing a cloud server and integrating with the smart home appliance device, splits the complete data D into a plurality of sub-data pieces Dz in the cloud server, and extracts the storage information of the smart home appliance device;

[0055] The data stealth storage and dynamic encryption module calculates the storage location L based on the storage information, extracts the sub-data piece Dz, and combines the storage information to encrypt and transform the stored data, obtains the encrypted data E after encryption and transformation processing, and dynamically stores and encrypts the sub-data piece Dz;

[0056] The data migration module detects and extracts the storage state data of the smart home appliance device at regular intervals during data storage, calculates the data migration priority Q based on the storage state data, sets the migration threshold F1 and the migration priority Q for migration comparison and evaluation, judges the migration situation, and deletes the source storage sub-data piece Dz;

[0057] The data access and joint decryption module performs key splicing, calculates the decryption key KD, and decrypts the data based on the decryption key KD to restore the complete data D through the cooperation of a plurality of smart home appliance devices when the user requests data.

[0058] The present application provides an information security data storage method and system.

[0059] (1) The method transmits the complete data D collected by the smart home appliance device to the cloud server for preprocessing, and uses XOR encryption, SHA-512 hash function, and large prime modulus algorithm for data sharding to generate a plurality of sub-data pieces Dz, combines the local system time T, device key K, and true random number R of the smart home appliance device, and calculates the storage location L of each sub-data piece Dz. Based on the storage location, the sub-data piece is dynamically encrypted and transformed to form encrypted data E, which is distributed and stored in a plurality of smart home appliance devices, thereby constructing a multi-source heterogeneous, dynamic random distributed data stealth storage system. This method effectively reduces the risk of single-point leakage and improves the physical distribution security and concealment of data at the device level.

[0060] (2) The method extracts the storage state data of each smart home appliance within the past 24 hours in real time based on the intrusion detection system IDS and the operation monitoring log of the smart home appliance. Further, the migration priority Q corresponding to each sub-data piece Dz is calculated by combining the detection time and the time difference from the last migration, and compared dynamically with the migration threshold F1 set by the user to accurately determine whether to trigger the migration operation. When migration is needed, the sub-data piece Dz is securely transmitted to the cloud through the TLS1.3 security protocol, and then distributed to the new device after being re-allocated to a new storage location. At the same time, the data on the original device is completely removed using the three-erasure method. The above process realizes the dynamic risk assessment and safe adaptive migration of the data storage path, greatly enhancing the attack resistance and operation resilience of the storage system.

[0061] (3) The method uses a multi-device collaborative decryption mechanism when the user requests to access the data. The encrypted data E stored in each smart home appliance is concatenated with the corresponding device key K to form a joint decryption key KD, which is compared and verified with the original key Koriginal. Only when all device keys participate in the calculation and the concatenation logic is correct, the complete data D can be successfully recovered; otherwise, the data will remain un-decryptable. This mechanism fully utilizes the device distribution characteristics and key separation principle to prevent attackers from attempting to decrypt the data through a single device or a small amount of data, thereby ensuring the integrity and confidentiality of the data recovery process and significantly enhancing the security control capability of user data access. BRIEF DESCRIPTION OF DRAWINGS

[0062] Figure 1 A schematic diagram of the steps of the information security data storage method of the present application;

[0063] Figure 2 A schematic diagram of the flow of the information security data storage system of the present application;

[0064] Figure 3 A schematic diagram of the data flow of the information security data storage method of the present application;

[0065] Figure 4 A live schematic diagram of the information security data storage method of the present application. DETAILED DESCRIPTION

[0066] The technical solutions in the embodiments of the present application will be described clearly and completely below with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, not all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative labor are within the scope of protection of the present application.

[0067] Embodiment 1

[0068] Please refer to Figure 1 , Figure 3 and Figure 4 , the present application provides a kind of information security data storage method, to realize above object, the present application is realized by the following technical scheme: including the following steps:

[0069] S1, construct cloud server and integrate with intelligent household appliances equipment, complete data D collected by intelligent household appliances equipment is transmitted to cloud server, complete data D is split into several sub data pieces Dz in cloud server, and the storage information of intelligent household appliances equipment is extracted;

[0070] S2, based on storage information, calculate storage location L, and extract sub data piece Dz and storage location L combined storage information, encrypt and transform the data stored, obtain the encrypted data E after encryption and transformation processing, dynamically invisible storage and encryption transformation are carried out to sub data piece Dz;

[0071] S3, in the process of data storage, the storage state data of intelligent household appliances equipment is detected and extracted again, based on storage state data, calculate data migration priority Q, and set migration threshold F1 and migration priority Q are compared and evaluated, judge migration situation, and delete the sub data piece Dz stored in source intelligent household appliances equipment;

[0072] S4, when user requests data, through several intelligent household appliances equipment cooperation, key splicing is carried out, decryption key KD is calculated, and data decryption is carried out based on decryption key KD, and complete data D is recovered.

[0073] In this embodiment, the method realizes the safe storage, dynamic migration and efficient decryption of data through the cooperative work of the cloud server and the smart home appliance. In the data storage process, the smart home appliance first collects complete data D and uploads it to the cloud server. The server performs sharding on the complete data D to form multiple sub-data pieces Dz, and calculates the storage location L based on the storage information of the device. Then, the sub-data pieces Dz are encrypted and transformed to form encrypted data E, which is stored in multiple smart home appliances based on the dynamic stealth storage mechanism, thereby improving the security and stealth of the data. During data storage, the system will regularly extract the storage state data of the smart home appliance and calculate the data migration priority Q based on the state data. At the same time, the migration threshold F1 is set and compared with the migration priority Q to determine whether the data migration operation needs to be performed, ensuring that the data can be transferred to other devices in time when the device storage pressure is too high or the security risk increases, and the sub-data pieces Dz in the original device are completely deleted, further enhancing the dynamic security and sustainability of data storage. In the data recovery stage, when the user requests data, the decryption key KD is calculated by multiple smart home appliances, and the complete key is generated by key splicing, which is finally used to decrypt the data and recover the complete data D. This method not only ensures the high-strength encrypted storage of data, but also improves the anti-attack ability and data privacy protection level of the system through dynamic migration and distributed storage strategy, avoiding the risk of single-point storage leakage, and strengthening access control through collaborative key management mechanism to ensure that data can only be decrypted and accessed in the case of multi-device authorization and cooperation, thereby significantly improving the data storage security, privacy and stability of the overall system of smart home appliances.

[0074] Embodiment 2

[0075] See Figure 1 , Figure 3 and Figure 4 , in particular: S1 includes S11 and S12;

[0076] S11, the cloud server is constructed through WIFI wireless communication network, using secure transmission protocol TLS1.3, integrating smart home appliances with cloud server, and numbering the storage units of smart home appliances, wherein the numbering is from 0 to M-1;

[0077] Then the smart home appliance collects complete data D (such as Table 1) in real time, and sets to transmit the complete data D to the cloud server every 24 hours. In the cloud server, the data sharding formula is constructed by using XOR encryption, SHA-512 hash light and large prime number modulo technology, the complete data D of the video data is sharded, and the complete data D is split into several sub-data pieces Dz;

[0078] The sub-data piece Dz is processed and output by the following data piece formula:

[0079]

[0080] In the formula, Dz i represents the sub-data piece of the i-th piece of the complete data D, S i represents the random piece seed of the i-th piece, takes a random number, and is automatically obtained by the internal random number generator TRNG of the smart home appliance device, SHA-512 represents the SHA-512 hash function, and outputs a fixed 512-bit random number, represents the XOR encryption operation, mod represents the modulo operation, the formula represents the modulo P operation on the hash calculation result, which is used to limit the value range of the data piece and enhance security, P represents a large prime number, which is used to select a large enough prime number P for the modulo operation to ensure that the data piece is not repeated, and P = 2 is selected, for example. 521 -1 (prime number), which improves security,

[0081] XOR encryption operation: used to increase data confusion, so that even if an attacker obtains the sub-data piece Dz i of the i-th piece of the complete data D, he cannot infer the complete data D.

[0082] Only the random piece seed S i of the i-th piece is known, and the data can be decrypted.

[0083] Table 1: Type table of complete data D collected by smart home appliance device

[0084] Smart home appliances Complete data D Smart speaker Store user voice data, avoid single device leak user conversation content Smart camera Protect monitoring video, even if the camera is attacked, hackers cannot get the complete video Smart door lock Store family member access records, prevent intruders from stealing family access information Smart refrigerator Store shopping records and food preference data, prevent data leakage to third parties Smart lighting system Record house lighting usage habits, prevent attackers from analyzing family activity patterns

[0085] S12, after splitting the complete data D, the built-in device of the smart home appliance device is used to extract and store information in real time; the stored information includes the local system time T j of the j-th smart home appliance device, the device key K j of the j-th smart home appliance device, the storage occupancy rate U j of the i-th smart home appliance device, the true random number R j of the j-th smart home appliance device, and the total capacity M of the storage space of the smart home appliance device.

[0086] The local system time T j of the j-th smart home appliance device is converted into a string format

[0087] wherein the local system time T j of the j-th smart home appliance device is extracted by the local system time of the smart home appliance device.

[0088] Device key K of the jth smart home appliance j Generated by the security chip TPM / TEE of the smart home appliance

[0089] Storage space total capacity M of the smart home appliance and storage occupancy rate U of the ith smart home appliance j Obtained by querying the current storage usage through the smart home appliance file system API

[0090] True random number R of the jth smart home appliance j Generated by the true random number generator TRNG inside the smart home

[0091] In this embodiment, the method establishes a secure connection with the smart home appliance through the cloud server via the WIFI wireless communication network, and uses the TLS1.3 secure transmission protocol to ensure the confidentiality and integrity of the data during transmission. The storage units of all smart home appliances are numbered for efficient data fragmentation and management. The smart home appliance regularly collects complete data D and uses XOR encryption, SHA-512 hashing and large prime modulus technology for data fragmentation to generate multiple sub-data pieces Dz through the data fragmentation formula, thereby enhancing the randomness and security of the data, so that even if part of the data is leaked, the attacker cannot guess the complete data content. At the same time, after the data is split, the smart home appliance will extract the storage information in real time, including the local system time Tj, the device key Kj, the storage occupancy rate Uj, the true random number Rj and the storage space total capacity M, etc. These key information are obtained through the device security chip TPM / TEE, the true random number generator TRNG and the file system API, to ensure the authenticity and non-tamperability of the data. By converting the local system time Tj into a string format, the uniformity and traceability of the data identification are improved. This method not only improves the data storage security of the smart home appliance, but also reduces the risk of data leakage through data fragmentation, XOR encryption and distributed storage strategy, while preventing hackers from obtaining complete data through a single device. In addition, through dynamic monitoring and intelligent management of the device storage state, the utilization efficiency of storage resources is improved, the stability of the system and the data privacy protection ability are enhanced, providing a more efficient and secure solution for smart home data security storage and management

[0092] Embodiment 3

[0093] Please refer to Figure 1 , Figure 3 and Figure 4 , in particular: S2 includes S21 and S22;

[0094] S21, extracting the local system time T of the jth smart home appliance in the storage information j , the device key K of the jth smart home appliancej And the true random number R of the j-th smart home appliance j The system dynamically calculates and outputs the storage location L of the sub-data fragment Dz on the smart home appliance, and based on the output storage location L, sends the sub-data fragment Dz from the cloud server to different smart home appliances for dynamic invisible storage.

[0095] The storage location L is calculated and output using the following algorithm formula;

[0096]

[0097] In the formula, L Dzi,j This represents the sub-data fragment Dz of the i-th fragment of the complete data D. i Storage location of the j-th smart home appliance, H SHA-256 This represents the SHA-256 hash function, which outputs a fixed 256-bit random number to ensure the security of the data storage location L. In the formula, mod M means ensuring that the storage location L is always within the available space of the smart home appliance.

[0098] The meaning of the formula is that, due to the local system time T of the j-th smart home appliance... j And the true random number R of the j-th smart home appliance j The location of the data is constantly changing. Even if the current storage location is discovered, it is impossible to predict where the data will be stored in the future. Furthermore, the storage location depends on the device key K of the j-th smart home appliance. j Attackers cannot restore the storage address on unauthorized devices;

[0099] Specific examples,

[0100] Assume the total storage capacity M of the smart home appliances is 1000 storage blocks.

[0101] The local system time T of the jth smart home appliance j It was converted to a string format, generating "1710888831";

[0102] The device key K for the j-th smart home appliance j The generated value is "87912348712984712394712394";

[0103] The truly random number R of the j-th smart home appliance j The generated value is "32048712398471298347192837".

[0104] The final complete data D, the sub-data fragment Dz of the i-th fragment. i Storage location L of the next smart home appliance Dzi,jThe output result of the above formula is 49, indicating the sub-data piece Dz of the i-th fragment of the complete data D i is stored in the 49th storage block of the smart home appliance device.

[0105] S22, based on the sub-data piece Dz of the i-th fragment of the complete data D i is stored in the storage location L of the j-th smart home appliance device Dzi,j , combined with the device key K of the j-th smart home appliance device j , and the encrypted data E after the encryption transformation is obtained and stored in the corresponding smart home appliance device;

[0106] The encrypted data E is encrypted by the following formula:

[0107]

[0108] In the formula, E Dzi,j represents the sub-data piece Dz of the i-th fragment of the complete data D i in the j-th smart home appliance device after the encryption transformation.

[0109] In this embodiment, the method extracts the local system time T j of the j-th smart home appliance device, the device key K j of the j-th smart home appliance device, and the true random number R j of the j-th smart home appliance device from the storage information, and calculates the sub-data piece Dz of the i-th fragment of the complete data D based on these dynamic variables i is stored in the storage location L of the j-th smart home appliance device Dzi,j . The storage location is calculated by the SHA-256 hash function, so that the data storage address has randomness and unpredictability, and even if the attacker masters the current storage location, it is impossible to predict the future data storage location. At the same time, since the calculation of the storage location depends on the device key K of the j-th smart home appliance device j , it is ensured that unauthorized devices cannot reproduce the storage address, thereby further enhancing the data security. Subsequently, the cloud server stores the sub-data piece Dz of the i-th fragment of the complete data D according to the calculated storage location L iThe dynamic distribution to different smart home appliances realizes invisible storage and avoids single device from becoming attack target. The stored data is encrypted and transformed based on storage location L and device key K to generate encrypted data E, which is stored in corresponding smart home appliance. Through the encryption mechanism, even if the attacker obtains the stored data, the data cannot be decrypted on unauthorized device, further improving the data protection capability. The implementation of the method effectively realizes the distributed dynamic storage and invisible encryption among smart home appliances, improves the data security, privacy and attack resistance, optimizes the storage resource allocation, improves the stability and reliability of the system, and provides an efficient and secure solution for smart home data storage

[0110] Embodiment 4

[0111] Please refer to Figure 1 、 Figure 3 and Figure 4 , in particular: S3 includes S31, S32 and S33;

[0112] S31, in the data storage process, through API application interface, real-time running of intrusion detection system IDS and running monitoring log of smart home appliance, detecting the storage state data of smart home appliance in the past 24 hours;

[0113] The storage state data includes the number of abnormal events Nalerts of the jth smart home appliance detected in the past 24 hours j , CPU load abnormal normal ratio Cabnormal of the jth smart home appliance j , CPU computing capacity C of the jth smart home appliance j , network transmission rate N of the jth smart home appliance j and storage utilization rate U of the jth smart home appliance j ;

[0114] Based on the storage state data, the migration priority Q is calculated and output, and the migration condition of the sub-data piece Dz of the i-th piece of complete data D is measured i ;

[0115] The migration priority Q is calculated and output through the following algorithm formula;

[0116]

[0117] In the formula, Q Di represents the migration priority of the sub-data piece of the i-th piece of complete data D, log represents the logarithmic function, the logarithmic function log is used to smooth the data and prevent the abnormal value from being too large to cause score distortion, 24 represents the detection time, and△t j represents the last migration time interval of the jth smart home appliance,

[0118] This indicates the anomaly detection score.

[0119] S32. Based on the user's setting of a migration threshold F1 according to the type of smart home appliance, the migration threshold F1 is then compared with the migration priority Q of the sub-data slice of the i-th slice of the complete data D. Di The migration comparison and evaluation assesses the implementation of the migration strategy. The specific evaluation content is as follows:

[0120] When the migration priority Q of the i-th sub-data fragment of the complete data D is... Di >When the migration threshold F1 is reached, it indicates that the current smart home appliance storage is abnormal, and the data migration strategy is triggered at this time;

[0121] When the migration priority Q of the i-th sub-data fragment of the complete data D is... Di If the value is less than or equal to the migration threshold F1, it indicates that the current smart home appliance storage is normal, and no migration is required.

[0122] S33. The data migration strategy uses the secure transport protocol TLS 1.3 to migrate the sub-data fragment Dz of the i-th fragment of the current smart device's complete data D. i The data is transmitted to the cloud server, where the storage location L is recalculated and encrypted. This process transforms the i-th fragment of the complete data D into its sub-data fragment Dz. i Store the data to a new storage location L, and then, using a secure erase method, delete the complete data D of the source smart home appliance device, including the sub-data fragment Dz of the i-th fragment. i ;

[0123] The secure erase method erases the complete data D stored in the source smart home appliance after migration through a three-stage write operation, specifically the sub-data fragment Dz of the i-th fragment. i ;

[0124] The first time, write all zeros and clear the data characteristic bits;

[0125] The second time, write all 1s to overwrite the boundary instruction;

[0126] Third, random data is written to prevent pattern inference and reconstruction analysis;

[0127] Finally, perform a final check to verify the integrity of the rewrite, delete the stored table entries, and refresh the cache and persistent logs.

[0128] In this embodiment, the method extracts the storage state data in the past 24 hours, and calculates the migration priority Q of the sub-data piece based on these parameters. By smoothing the abnormal detection score through the logarithmic function log, the influence of abnormal values on the score is prevented, making the calculation of the migration priority Q more stable. At the same time, the user can set the migration threshold F1 according to the type of smart home appliance, and compare it with the calculated migration priority Q Di When the migration priority Q Di exceeds F1, the data migration strategy is triggered, otherwise the data remains unchanged. At the same time, the data migration adopts the TLS1.3 secure transmission protocol to ensure the security of transmission, and re-calculates the storage location L and performs encryption transformation on the cloud server to ensure the privacy and security of the stored data. At the same time, after the migration is completed, the data on the source device is securely erased using the three-write method, including writing all 0s, all 1s and random data, to prevent data recovery, and finally through integrity verification, deleting storage table entries, flushing cache and persisting logs, the original storage traces are completely eliminated. Through the implementation of this method, not only the storage security of smart home appliances is improved, preventing data from being illegally stolen or tampered with, but also the reliability of data storage is improved, ensuring that data can be migrated and protected in time in abnormal environments, thereby optimizing the overall security performance and data management capability of the smart home system.

[0129] Embodiment 5

[0130] Please refer to Figure 1 , Figure 3 and Figure 4 , in detail: S4 includes S41 and S42;

[0131] S41, when the user requests data, the encrypted data E of all smart home appliances and the device key K j of the jth smart home appliance are spliced to calculate the decryption key KD;

[0132] The decryption key KD is calculated and output by the following algorithm formula;

[0133]

[0134] In the formula, N represents the total number of smart home appliances, XOR denotes the XOR encryption operation summation symbol, which is sequentially operated on the first smart home appliance to the Nth smart home appliance.

[0135] S42, based on the decryption key KD and the original key Kor data decryption; the splicing formula is:

[0136]

[0137] In the formula, Drecovered represents the decrypted data, Koriginal represents the original key, represents the logic symbol if and only if, and the formula indicates that only when the calculated decryption key KD is completely consistent with the original key Koriginal, the complete data D can be successfully recovered;

[0138] If the calculated decryption key KD is the same as the original key Koriginal, the data is recovered;

[0139] If the calculated decryption key KD is not the same as the original key Koriginal, the decryption fails and the data remains secure.

[0140] In this embodiment, the method realizes the secure decryption and recovery of data by calculating the decryption key KD through the cooperation of smart home appliances. At the same time, when the user requests data, the encrypted data E stored by all smart home appliances is extracted, and the device key K j is calculated by XOR operation. This method ensures the dynamic nature and distributed characteristics of the decryption key, so that even if part of the device is attacked, it is difficult for hackers to obtain the complete decryption key. At the same time, further comparison is made between the decryption key KD and the original key Kor. If they are completely consistent, the complete data D is successfully decrypted and recovered; if they are not consistent, the decryption fails and the data remains encrypted, ensuring information security. This method realizes secure data access in the smart home environment through distributed key splicing and strict key matching mechanism, prevents single-point attacks, improves data privacy protection capability, and enhances the anti-attack ability of the system and the reliability of data recovery, thereby greatly improving the security and stability of smart home appliances in the process of data storage and access.

[0141] Embodiment 6

[0142] Please refer to Figure 1 and Figure 2 An information security data storage system, comprising a data sharding module, a data stealth storage and dynamic encryption module, a data migration module, and a data access and joint decryption module;

[0143] The data sharding module transmits the complete data D collected by the smart home appliance to the cloud server by constructing the cloud server and integrating with the smart home appliance, splits the complete data D into a plurality of sub-data pieces Dz in the cloud server, and extracts the storage information of the smart home appliance;

[0144] The data stealth storage and dynamic encryption module calculates the storage position L based on the stored information, extracts the sub-data piece Dz, combines the storage position L with the stored information, encrypts and transforms the stored data, obtains the encrypted data E after the encryption and transformation processing, and dynamically stores and encrypts the sub-data piece Dz;

[0145] The data migration module detects and extracts the storage state data of the intelligent household appliance device in a timely manner during the data storage process, calculates the data migration priority Q based on the storage state data, sets the migration threshold F1, compares and evaluates the migration priority Q and the migration threshold F1, judges the migration condition, and deletes the source storage sub-data piece Dz.

[0146] The data access and joint decryption module cooperates with a plurality of intelligent household appliance devices to splice the key, calculate the decryption key KD, and decrypt the data based on the decryption key KD to restore the complete data D when the user requests the data.

[0147] Although the embodiments of the present application have been shown and described, it can be understood by those skilled in the art that various changes, modifications, replacements and variations can be made to the embodiments without departing from the principles and spirits of the present application.

Claims

1. An information security data storage method, characterized by: It comprises the following steps: S1, constructing a cloud server and integrating with smart home appliances, transmitting complete data D collected by smart home appliances to the cloud server, splitting the complete data D into several sub-data pieces Dz in the cloud server, and extracting storage information of the smart home appliances; S2, calculating the storage location L based on the storage information, and extracting the sub-data piece Dz combined with the storage location L and the storage information, encrypting and transforming the stored data to obtain encrypted data E after encryption and transformation processing, and dynamically storing and encrypting the sub-data piece Dz; S3, during the data storage process, the storage state data of the smart home appliance is detected and extracted, and based on the storage state data, the data migration priority Q is calculated, and the migration threshold F1 is set to compare and evaluate the migration priority Q, judge the migration situation, and delete the sub-data piece Dz stored in the source smart home appliance; S4, when the user requests data, through the cooperation of several smart home appliances, the decryption key KD is calculated, and the data is decrypted based on the decryption key KD to restore the complete data D.

2. The information security data storage method of claim 1, wherein: S1 includes S11 and S12; S11, the cloud server is constructed through WIFI wireless communication network, using secure transmission protocol TLS1.3, integrating the smart home appliances with the cloud server, and numbering the storage units of the smart home appliances, wherein the numbering is from 0 to M-1; Then collect the complete data D in real time through the smart home appliances, and set to transmit the complete data D to the cloud server every 24 hours, and use XOR encryption, SHA-512 hash light and large prime modulus technology to construct data fragmentation formula in the cloud server, and perform fragmentation processing on the complete data D of the video data, and split the complete data D into several sub-data pieces Dz; The sub-data piece Dz is processed and output through the following data fragmentation formula; ; where Dz i denotes the i-th fragment of the complete data D i denotes the random fragment seed of the i-th fragment H SHA-512 denotes the SHA-512 hash function, which outputs a fixed 512-bit random number, denotes the XOR encryption operation, mod denotes the modulo operation, and P denotes a large prime number; S12, after splitting the complete data D, the storage information is extracted in real time by the built-in device of the smart home appliance; the storage information includes the local system time T of the jth smart home appliance of the smart home appliance j , the device key K of the jth smart home appliance j , the storage occupancy rate U of the ith smart home appliance j , the true random number R of the jth smart home appliance j , and the total capacity M of the storage space of the smart home appliance; The local system time T of the j-th smart home appliance j Convert to string format.

3. The information security data storage method of claim 2, wherein: S2 includes S21; S21, extracting the local system time T of the jth smart home appliance in the stored information j , the device key K of the jth smart home appliance j , and the true random number R of the jth smart home appliance j , dynamically calculating the output storage location L of the data piece Dz on the jth smart home appliance, and sending the data piece Dz from the cloud server to the different smart home appliances based on the output storage location L for dynamic invisible storage. The storage location L is calculated and output through the following algorithm formula; ; In the formula, L Dzi,j represents the sub-data piece Dz of the i-th fragment of the complete data D i In the storage location of the j-th smart home appliance, H SHA-256 represents the SHA-256 hash function, which fixes the output of 256-bit random numbers.

4. The information security data storage method of claim 3, wherein: S2 also includes S22; S22, sub data piece Dz based on the i-th fragment of the complete data D i at the storage location L of the j-th smart home appliance Dzi,j combined with the device key K of the j-th smart home appliance j encrypted and transformed, to obtain encrypted data E after encryption and transformation processing, and stored in the corresponding smart home appliance The encrypted data E is encrypted and processed through the following formula; ; In the formula, E Dzi,j represents the sub-data piece Dz of the i-th fragment of the complete data D i encrypted data E after the encryption transformation processing in the j-th smart home appliance 5. The information security data storage method of claim 4, wherein: S3 includes S31; S31, during the data storage process, the intrusion detection system IDS of the smart home appliance is run in real time through the API application program interface, and the storage state data of the smart home appliance in the past 24 hours is detected; The storage state data includes the number of abnormal events Nalerts of the jth smart home appliance device detected in the past 24 hours j , the CPU load abnormality normal ratio Cabnormal of the jth smart home appliance device j , the CPU computing power C of the jth smart home appliance device j , the network transmission rate N of the jth smart home appliance device j , and the storage utilization rate U of the jth smart home appliance device j ; Based on the storage state data to calculate the output migration priority Q, to measure the data integrity data D the i-th sub-data piece Dz of the data piece D i Migration case; The migration priority Q is calculated and output through the following algorithm formula; ; In the formula, Q Dzi represents the migration priority of the sub-data piece of the i-th fragment of the complete data D, log represents a logarithmic function, 24 represents a detection time, and Δt j represents the last migration time interval of the j-th smart home appliance.

6. The information security data storage method of claim 5, wherein: S3 also includes S32; S32, based on the user according to the intelligent household electrical appliances type, set migration threshold F1, and then migrate threshold F1 and complete data D i-th fragment of the sub-data piece migration priority Q Dzi , migration comparison and evaluation, judge the migration strategy execution, the specific evaluation content is as follows; When the migration priority Q of the sub-data piece of the i-th fragment of the complete data D is greater than the migration threshold F1 Dzi The migration threshold F1 indicates that the current smart home appliance storage is abnormal, and the data migration strategy is triggered at this time. When the migration priority Q of the sub-data piece of the i-th fragment of the complete data D Dzi ≤ migration threshold F1, it indicates that the current smart home appliance storage is normal, and migration is not required at this time.

7. The information security data storage method of claim 6, wherein: S3 also includes S33; S33. The data migration strategy uses the secure transport protocol TLS 1.3 to migrate the sub-data fragment Dz of the i-th fragment of the current smart device's complete data D. i The data is transmitted to the cloud server, where the storage location L is recalculated and encrypted. This process transforms the i-th fragment of the complete data D into its sub-data fragment Dz. i Store the data to a new storage location L, and then, using a secure erase method, delete the complete data D of the source smart home appliance device, including the sub-data fragment Dz of the i-th fragment. i ; The security erasing method, through the three-time writing method, erases the sub-data piece Dz of the complete data D of the i-th piece stored in the source smart home appliance device after the migration i ; First, write all 0, clear the data characteristic bit; Second, write all 1, cover the boundary instruction; Third, write random data to prevent pattern inference and reconstruction analysis; Finally, execute the integrity check again, delete the storage table item, refresh the cache and persistent log.

8. The information security data storage method of claim 7, wherein: S4 includes S41; S41, when the user requests data, the stored encrypted data E of all smart home devices and the device key K of the jth smart home device need to be provided j , the key splicing is performed, and the decryption key KD is calculated and obtained; The decryption key KD is calculated and output through the following algorithm formula; ; In the formula, N represents the total number of smart home appliances, represents XOR exclusive or encryption operation summation symbol, and the XOR exclusive or encryption operation will be sequentially performed from the first smart home appliance to the Nth smart home appliance.

9. The information security data storage method of claim 8, wherein: S4 also includes S42; S42, based on the decryption key KD and the original key Kor, data decryption is performed; The splicing formula is: ; wherein Drecovered represents the decrypted data, Koriginal represents the original key, represents the logical symbol if and only if, and the formula means that the complete data D can be successfully recovered only if the calculated decryption key KD is identical to the original key Koriginal; If the calculated decryption key KD is the same as the original key Koriginal, the data is restored; If the decryption key KD is calculated to be different from the original key Koriginal, the decryption fails, and the data remains safe.

10. An information security data storage system applied to the information security data storage method of any one of claims 1-9, characterized in that: The data access and joint decryption module calculates the decryption key KD based on the decryption key KD and performs data decryption to restore the complete data D when the user requests data. The data sharding module transmits the complete data D collected by the smart home appliance device to the cloud server by constructing the cloud server and integrating with the smart home appliance device, splits the complete data D into a plurality of sub-data pieces Dz in the cloud server, and extracts the storage information of the smart home appliance device. The data access and joint decryption module calculates the decryption key KD based on the decryption key KD and performs data decryption to restore the complete data D when the user requests data. The data access and joint decryption module calculates the decryption key KD based on the decryption key KD and performs data decryption to restore the complete data D when the user requests data. ​

Citation Information

Patent Citations

  • Data processing system based on quantum network cloud host

    CN117240440A

  • End-to-end TCP monitoring during application migration

    US20250071142A1