Enterprise cloud data encryption processing system

By classifying the sensitivity of cloud data and extracting encryption features, adopting cross-combination encryption and holistic single encryption, and building walls between encryption bits, the problem of mismatched cloud data encryption methods is solved, and efficient data encryption and independent storage management are achieved.

CN120671160AInactive Publication Date: 2025-09-19东营利新信息科技有限公司
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202510737104.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-04
Publication Date
2025-09-19
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

Existing cloud data encryption methods are unable to perform targeted encryption for cloud data of different sensitivity levels, resulting in mismatches and poor encryption effects for the same encryption methods. At the same time, adjacent cloud data lacks isolation and protection, making it prone to lateral leakage and loss.

Method used

The encryption features of cloud data are extracted through the data identification module, classified into high-sensitivity and low-sensitivity data, and cross-combination encryption and holistic single encryption methods are adopted. An encryption fence is established between the encryption bits, and a data encryption library is constructed to achieve independent storage and isolated protection.

Benefits of technology

It achieves accurate differentiation and encryption of cloud data of different sensitivities, improves the rationality and security of data encryption, prevents horizontal data leakage, and enhances data independence and stability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120671160A_ABST
    Figure CN120671160A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of data encryption, and discloses an enterprise cloud data encryption processing system. Comprising a data identification module for analyzing sensitive attributes of enterprise cloud data, a data encryption module for encrypting the data, generating a combined ciphertext and a whole-body ciphertext, an encryption library construction module for generating a data encryption library, an exception judgment module for judging whether an exception protection prompt is sent or not, and an encryption bit stripping module, the stripping module is used for stripping a target encryption bit; compared with the prior art, crossed combined encryption and integral single encryption operations can be provided for enterprise cloud data with different sensitive degrees, and an electronic fence with an isolation protection effect can be established between two adjacent pieces of enterprise cloud data in combination with the constructed data encryption library; therefore, the influence of interference attacks on the enterprise cloud data at adjacent positions is effectively avoided, and the independence and stability of the enterprise cloud data in the data encryption library are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of data encryption, and more particularly, to an enterprise cloud data encryption processing system. Background Art

[0002] With the popularization of cloud computing technology, enterprises have begun to migrate more and more key data such as business data, financial data, and production data to the cloud for storage. Due to the sharing and openness of the cloud environment, enterprise cloud data stored in the cloud will face multiple security threats such as irregular malicious interference attacks, making enterprise cloud data prone to leakage and loss. In order to improve the security of enterprise cloud data, it is necessary to encrypt enterprise cloud data.

[0003] Patent application CN114500035A discloses a data encryption system based on a service data sharing cloud platform. This system encrypts data based on its own characteristics. Furthermore, during decryption, the corresponding extraction code must be entered and compared with the item sequence value to restore the original file, achieving the effect of accurate data encryption.

[0004] When encrypting existing cloud data, it uses continuous address allocation to encrypt cloud data to achieve real-time encryption of cloud data and perform overall storage management of the encrypted cloud data. However, the encryption levels corresponding to cloud data of different sensitivity levels are not consistent. The same encryption method cannot be used to perform targeted and reasonable encryption processing on cloud data of different sensitivity levels. At the same time, there is a lack of isolation and protection measures between adjacent cloud data. When a certain cloud data is breached by malicious attacks and leaked or lost, the malicious attack will also penetrate horizontally to the adjacent cloud data, causing the stored cloud data to be prone to large-scale horizontal leakage and loss, thereby reducing the encryption rationality and storage security of enterprise cloud data.

[0005] In view of this, the present invention proposes an enterprise cloud data encryption processing system to solve the above problems. Summary of the Invention

[0006] In order to overcome the above-mentioned defects of the prior art and to achieve the above-mentioned objectives, the present invention provides the following technical solutions: an enterprise cloud data encryption processing system, applied to an encryption server, comprising:

[0007] The data identification module is used to extract the encryption features of enterprise cloud data in the cloud database, analyze the sensitive attributes of the enterprise cloud data based on the encryption features, and classify and summarize the enterprise cloud data;

[0008] The data encryption module is used to perform cross-combination encryption operations on highly sensitive data and overall single encryption operations on less sensitive data, generating combined ciphertext and full ciphertext respectively;

[0009] The encryption library construction module is used to construct a basic encryption library, import the combined ciphertext and the full ciphertext into the encryption bits of the basic encryption library, and establish an encryption fence with on-off nodes between adjacent encryption bits to generate a data encryption library;

[0010] The abnormality determination module is used to collect access data of the encrypted bits in the data encryption library in real time and determine whether to issue an abnormality protection prompt;

[0011] The encryption bit stripping module is used to locate the target encryption bit and the target fence from the data encryption library, and switch the on and off state of the target fence to strip the target encryption bit from the data encryption library.

[0012] Furthermore, the encryption feature extraction method includes:

[0013] Arrange all enterprise cloud data in the cloud database in the order of recording time to generate a cloud data queue;

[0014] Starting from the first enterprise cloud data in the cloud data queue, the key semantics of all enterprise cloud data are identified in sequence using natural language processing technology;

[0015] The key semantics are split into text groups and number groups through word segmentation technology, and the text groups are separated from the key semantics to generate encryption features.

[0016] Furthermore, sensitive attributes include highly sensitive data and less sensitive data. Analysis methods for highly sensitive data and less sensitive data include:

[0017] Identify the standard semantics of property information, customer information, identity information, business information, decision-making information, confidential information, special information, defense information, legal information, and decision-making information in the database one by one, and record the text parts in the standard semantics as marked highly sensitive text;

[0018] When the encryption feature overlaps with the calibrated highly sensitive text, the enterprise cloud data is recorded as highly sensitive data, and A highly sensitive data are obtained;

[0019] When the encryption feature does not overlap with the calibrated high-sensitivity text, the enterprise cloud data is recorded as low-sensitivity data, and B low-sensitivity data are obtained.

[0020] Furthermore, the method for generating the combined ciphertext includes:

[0021] A first encryption model with two encryption channels distributed vertically is constructed, and the two encryption channels are respectively recorded as a logic encryption channel and a content encryption channel in a top-down manner;

[0022] Import A highly sensitive data into the logical encryption channel one by one, identify the highly sensitive fields in the highly sensitive data using regular expressions, and split the highly sensitive fields from the highly sensitive data to generate A highly sensitive data blocks;

[0023] Query the permission levels of the highly sensitive fields in the A highly sensitive data blocks one by one in the database, and set the access logic strategy for the highly sensitive data blocks based on the value of the permission level;

[0024] Combine ABE encryption technology with access logic policy to form a logical password, and use the logical password to logically encrypt highly sensitive data blocks to generate A policy-bound ciphertexts;

[0025] Transfer A policy-bound ciphertexts from the logical encryption channel to the content encryption channel, mark the transfer time, and derive a temporary key from the master key. Attach the transfer time to the temporary key to generate a dynamic key.

[0026] Based on the dynamic key, the SM4 algorithm combined with the dynamic S-box is used to encrypt A policy-bound ciphertexts to generate A content-bound ciphertexts;

[0027] The previous moment before the content-bound ciphertext is generated is recorded as the target moment. The target moment, the algorithm version of the SM4 algorithm, and the recording time of A sensitive data blocks are summarized into ciphertext parameters. The ciphertext parameters are added to the A content-bound ciphertexts to generate A combined ciphertexts.

[0028] Furthermore, the method for generating the entire ciphertext includes:

[0029] Construct a second encryption model with B sub-channels, import the B low-sensitivity data into the B sub-channels one by one, and number the B sub-channels in ascending order;

[0030] Identify low-sensitivity fields in low-sensitivity data using regular expressions, and cut the low-sensitivity fields from the low-sensitivity data to generate B low-sensitivity data blocks;

[0031] At the same time, the ChaCha20 algorithm is used to concurrently encrypt the low-sensitivity data blocks in B sub-channels to generate B initial ciphertexts.

[0032] The generation times of the B initial ciphertexts are queried one by one, the B generation times are combined with the corresponding sub-channel numbers to form B dynamic private keys, and the B dynamic private keys are matched with the B initial ciphertexts one by one to generate B full ciphertexts.

[0033] Furthermore, the encryption bits include deep encryption bits and shallow encryption bits;

[0034] The construction method of the basic encryption library includes:

[0035] Construct a blank database, and create two data layers with inner and outer wrapped distribution in the database. The data layer on the inner side is recorded as the combined layer, and the data layer on the outer side is recorded as the full layer.

[0036] A spaced data bits are set in the combined layer to obtain A deep encryption bits, and B spaced data bits are set in the whole layer to obtain B shallow encryption bits. The database with A deep encryption bits and B shallow encryption bits is recorded as the basic encryption library.

[0037] Furthermore, the encrypted fence includes an inner fence and an outer fence;

[0038] The construction method of the data encryption library includes:

[0039] Import A combined ciphertexts and B full ciphertexts into A deep encryption bits and B shallow encryption bits one by one, and arrange A deep encryption bits and B shallow encryption bits in a circular manner with equal angles;

[0040] A first electronic fence is constructed between two adjacent deep encryption positions, and a control point and two status points are simulated on the first electronic fence to generate an inner fence;

[0041] A second electronic fence is constructed between two adjacent shallow encryption positions, and a control point and two status points are simulated on the second electronic fence to generate an outer fence;

[0042] The open state and the closed state are set at the two status points of the inner wall and the outer wall respectively, and the control point is adjusted to the open state to form an on-off node, prompting the basic encryption library to be converted into a data encryption library.

[0043] Furthermore, the access data includes the super-authority access value, key validity period, and encryption stability coefficient;

[0044] The methods for determining whether to issue an abnormal protection prompt include:

[0045] When the super-authority access value is greater than the access calibration value, the super-authority access value is recorded as an abnormal value;

[0046] When the key validity period is greater than the validity calibration value, the key validity period is recorded as an abnormal value;

[0047] When the encrypted stability coefficient is less than the stable calibration value, the encrypted stability coefficient is recorded as an abnormal value;

[0048] Count the number of abnormal values ​​on the encryption bit. If the number of abnormal values ​​is 0 or 1, it is determined that no abnormal protection prompt will be issued.

[0049] When the number of abnormal values ​​is 2 or 3, it is determined that an abnormality protection prompt is issued.

[0050] Furthermore, the target encryption bit is a deep encryption bit or a shallow encryption bit for determining whether an abnormal protection prompt is issued;

[0051] The target wall is the inner wall or outer wall located on both sides of the target encryption position.

[0052] Furthermore, the on-off state includes an on state and a blocking state;

[0053] Methods for stripping the target encryption bits include:

[0054] When the target encryption position is a deep encryption position, the inner walls on both sides of the target encryption position are recorded as target walls;

[0055] When the target encryption position is a shallow encryption position, the outer walls on both sides of the target encryption position are recorded as target walls;

[0056] Adjusting the on / off node on the target wall from an on state to a off state, thereby causing the on / off state of the target wall to switch from a conducting state to a blocking state;

[0057] In the blocking state, the enterprise cloud data in the target encryption bit is compressed and aggregated into a data packet, and the data packet is stripped from the data encryption library as a whole.

[0058] The technical effects and advantages of the enterprise cloud data encryption processing system of the present invention are as follows:

[0059] 1. The present invention can provide an operating basis for different encryption methods for enterprise cloud data with different sensitivities, thereby accurately distinguishing between cross-combination encryption and overall single encryption of enterprise cloud data, avoiding the problems of mismatched encryption mechanisms and poor encryption effects caused by the use of the same encryption method for enterprise cloud data with different sensitivities.

[0060] 2. The present invention can not only independently and accurately store and manage the encrypted enterprise cloud data, but also establish an electronic fence with isolation and protection between two adjacent encrypted enterprise cloud data. When a certain enterprise cloud data is leaked or lost due to an interference attack, the enterprise cloud data that has been interfered with can be separated separately, thereby effectively avoiding the impact of the interference attack on the enterprise cloud data in the adjacent location, and improving the independence and stability of the enterprise cloud data in the data encryption library. BRIEF DESCRIPTION OF THE DRAWINGS

[0061] Figure 1A schematic diagram of a module of an enterprise cloud data encryption processing system provided in the first embodiment of the present invention;

[0062] Figure 2 A flowchart of an enterprise cloud data encryption processing method provided in Example 2 of the present invention. DETAILED DESCRIPTION

[0063] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of the present invention.

[0064] Example 1: Please refer to Figure 1 As shown, the enterprise cloud data encryption processing system described in this embodiment is applied to an encryption server and includes:

[0065] The data identification module extracts the encryption features of enterprise cloud data in the cloud database, analyzes the sensitive attributes of the enterprise cloud data based on the encryption features, and classifies and summarizes the enterprise cloud data;

[0066] A cloud database is a database based on cloud computing technology used to store various types of enterprise data, achieving effective storage and management of enterprise data. At the same time, all data about the enterprise stored in the cloud database is called enterprise cloud data.

[0067] Since the structures and types of enterprise cloud data are diverse, and the meanings expressed by enterprise cloud data of different types and structures, as well as the specific encryption processing measures in the encryption process are inconsistent, in order to accurately identify the meaning of each enterprise cloud data and meet the subsequent encryption operations on the enterprise cloud data, it is necessary to extract the encryption features of the enterprise cloud data so that the encryption features can directly and accurately represent the specific meaning and type of the enterprise cloud data.

[0068] The encryption feature extraction methods include:

[0069] Arrange all enterprise cloud data in the cloud database in the order of recording time to generate a cloud data queue;

[0070] Starting with the first enterprise cloud data in the cloud data queue, natural language processing technology is used to identify the key semantics of all enterprise cloud data in sequence. Key semantics are used to concisely represent the true meaning of enterprise cloud data, which can accurately, concisely, and reasonably represent complex enterprise cloud data.

[0071] The key semantics are split into text groups and number groups through word segmentation technology, and the text groups are separated from the key semantics to generate encryption features.

[0072] After obtaining the encryption characteristics of enterprise cloud data, the encryption characteristics can be used as the basis for judging the specific structure and type of enterprise cloud data. Based on the specific meaning of the encryption characteristics, it can provide an analysis basis for whether the enterprise cloud data is sensitive internal data of the enterprise, and the sensitive attributes can be used as the final result of the sensitive analysis.

[0073] Sensitive attributes include highly sensitive data and low-sensitivity data; among them, highly sensitive data refers to data within the enterprise, such as property, identity, and customers, which should not be made public and require highly encrypted protection processing; low-sensitivity data refers to data within the enterprise, such as annual reports and introductions, which can be made public and require general encryption protection processing.

[0074] Analysis methods for highly sensitive data and less sensitive data include:

[0075] Identify the standard semantics of property information, customer information, identity information, business information, decision-making information, confidential information, special information, defense information, legal information, and decision-making information in the database one by one, and record the text parts in the standard semantics as marked highly sensitive text;

[0076] Conduct overlap analysis between the encryption features of enterprise cloud data and the calibrated highly sensitive text;

[0077] When the encryption feature overlaps with the calibrated highly sensitive text, it means that the content of the enterprise cloud data involves information that should not be made public within the enterprise. In this case, the enterprise cloud data is recorded as highly sensitive data, and A highly sensitive data are obtained.

[0078] When there is no overlap between the encryption feature and the calibrated high-sensitivity text, it means that the content of the enterprise cloud data does not involve information that should not be made public in the enterprise, and the enterprise cloud data is recorded as low-sensitivity data, and B low-sensitivity data are obtained.

[0079] After analyzing the sensitive attributes of enterprise cloud data, the enterprise cloud data can be classified and aggregated according to the different sensitive attributes to ensure that enterprise cloud data with the same sensitive attributes can be accurately aggregated together;

[0080] Specifically, enterprise cloud data with high-sensitivity attributes and enterprise cloud data with low-sensitivity attributes are distinguished to obtain high-sensitivity sets and low-sensitivity sets, and the enterprise cloud data in the high-sensitivity sets and the low-sensitivity sets are arranged in sequence according to the chronological order of recording time, thereby achieving the aggregation effect of high-sensitivity data and low-sensitivity data, ensuring that enterprise cloud data with different sensitive attributes can be accurately and quickly distinguished and aggregated.

[0081] The data encryption module performs cross-combination encryption operations on highly sensitive data and overall single encryption operations on less sensitive data, generating combined ciphertext and full ciphertext respectively;

[0082] After enterprise cloud data is differentiated and aggregated, encryption operations can be performed on highly sensitive data and less sensitive data according to their sensitive attributes.

[0083] Specifically, when enterprise cloud data is highly sensitive data, the enterprise cloud data at this time involves key information within the enterprise that should not be disclosed to the outside. The enterprise cloud data needs to be kept confidential to a high degree to avoid leakage of key information in the enterprise cloud data. Therefore, combined encryption operations are required for highly sensitive data.

[0084] Combined encryption operations are used to perform cross-type encryption processing on highly sensitive data. Multiple encryption operations can be cross-applied to highly sensitive data, performing complex and reasonable high-performance encryption operations on highly sensitive data. After the cross-type combined encryption operations are performed on the highly sensitive data, the highly sensitive data will be converted into combined ciphertext.

[0085] It should be noted that the combined ciphertext is the ciphertext information formed after a cross-combination encryption operation is performed on highly sensitive data. At this time, the data information contained in the combined ciphertext can be consistent with the data information contained in the highly sensitive data, so as to ensure that the combined ciphertext can convert the open and transparent highly sensitive data into non-public and opaque encrypted data information.

[0086] Specifically, the method for generating the combined ciphertext includes:

[0087] A first encryption model is constructed with two encryption channels distributed vertically and horizontally. The two encryption channels are labeled as a logical encryption channel and a content encryption channel, respectively, from top to bottom. The first encryption model is used to perform combined encryption on highly sensitive data. The logical encryption channel and the content encryption channel are structures used to satisfy combined encryption operations, thereby achieving a cross-combination effect of the two encryption methods: logical encryption and content encryption.

[0088] Import A highly sensitive data into the logical encryption channel one by one, identify the highly sensitive fields in the highly sensitive data using regular expressions, and split the highly sensitive fields from the highly sensitive data to generate A highly sensitive data blocks;

[0089] The permission levels of the highly sensitive fields in the database of A highly sensitive data blocks are queried one by one, and the access logic strategy for the highly sensitive data blocks is set based on the value of the permission level. The permission level is used to indicate the access rights pre-calibrated for the highly sensitive fields. The larger the access rights value, the higher the access rights required to access the highly sensitive data. The access logic strategy is a strategy formulated based on the value of the permission level, which is used to provide a numerical basis for the access rights level of the subsequent combined ciphertext.

[0090] Combine ABE encryption technology with access logic policy to form a logical command, and use the logical command to logically encrypt highly sensitive data blocks to generate A policy-bound ciphertexts. ABE encryption technology is used to encrypt the attribute base of highly sensitive data. When combined with access logic policy, it can form a policy-bound ciphertext that can logically encrypt highly sensitive data.

[0091] Transfer A policy-bound ciphertexts from the logical encryption channel to the content encryption channel, mark the transfer time, and derive a temporary key from the master key. Attach the transfer time to the temporary key to generate a dynamic key.

[0092] Based on the dynamic key, the SM4 algorithm combined with the dynamic S-box is used to encrypt A policy-bound ciphertexts to generate A content-bound ciphertexts. The SM4 algorithm of the dynamic S-box uses dynamically generated S-boxes to increase the complexity of the cryptographic algorithm and improve encryption security. As a conventional technology in the field, it is not an innovation of this application and is not described in detail here.

[0093] The previous moment before the content-bound ciphertext is generated is recorded as the target moment. The target moment, the algorithm version of the SM4 algorithm, and the recording time of A sensitive data blocks are summarized into ciphertext parameters. The ciphertext parameters are added to the A content-bound ciphertexts to generate A combined ciphertexts.

[0094] It should be noted that the combined ciphertext can perform double cross encryption on highly sensitive data, so that the highly sensitive data has a combined encryption effect in terms of logical strategy and content form, thereby ensuring that the highly sensitive data can maintain a high degree of confidentiality.

[0095] When enterprise cloud data is low-sensitivity data, it does not involve key information within the enterprise that should not be disclosed externally. The enterprise cloud data does not require a high degree of confidentiality operations, so a single encryption operation is required for the low-sensitivity data.

[0096] A single encryption operation is used to perform an overall single-mode encryption processing operation on low-sensitivity data. Specific encryption operations can be cross-applied to low-sensitivity data to perform accurate and reasonable encryption operations on low-sensitivity data. After a single encryption operation is performed on low-sensitivity data, the low-sensitivity data will be converted into full ciphertext.

[0097] It should be noted that the whole ciphertext is the ciphertext information formed after a single encryption operation is performed on the low-sensitivity data. At this time, the data information contained in the whole ciphertext can be consistent with the data information contained in the low-sensitivity data, so as to ensure that the whole ciphertext can convert the open and transparent low-sensitivity data into semi-open and transparent encrypted data information.

[0098] Specifically, the method for generating the entire ciphertext includes:

[0099] Construct a second encryption model with B sub-channels, and import the B low-sensitivity data into the B sub-channels one by one, and number the B sub-channels in ascending order. The second encryption model is used to perform single encryption on low-sensitivity data. The sub-channel is used to satisfy the structure of the overall single encryption operation, ensuring that all low-sensitivity data can be encrypted synchronously and in parallel.

[0100] Identify low-sensitivity fields in low-sensitivity data using regular expressions, and cut the low-sensitivity fields from the low-sensitivity data to generate B low-sensitivity data blocks;

[0101] At the same time, the ChaCha20 algorithm is used to concurrently encrypt the low-sensitivity data blocks in the B sub-channels to generate B initial ciphertexts. The ChaCha20 algorithm is a stream cipher that encrypts data by generating an infinite stream of pseudo-random bytes. As a conventional technology in the field, it is not an innovation of this application and is not described in detail here.

[0102] The generation times of the B initial ciphertexts are queried one by one, the B generation times are combined with the corresponding sub-channel numbers to form B dynamic private keys, and the B dynamic private keys are matched with the B initial ciphertexts one by one to generate B full ciphertexts.

[0103] It should be noted that the whole ciphertext can perform overall single concurrent mode encryption processing on low-sensitivity data, so that the low-sensitivity data has a consistent encryption effect, thereby ensuring that the low-sensitivity data can maintain reasonable confidentiality.

[0104] The encryption library construction module builds a basic encryption library, imports the combined ciphertext and the full ciphertext into the encryption bits of the basic encryption library, and establishes an encryption fence with on-off nodes between adjacent encryption bits to generate a data encryption library;

[0105] The basic encryption library refers to an encryption library without any blanks in the ciphertext, so that the basic encryption library can be used as a database for the integrated storage of combined ciphertext and full ciphertext, and can lay the foundation for the construction of subsequent data encryption libraries;

[0106] When building the basic encryption library, it is necessary to mark the encryption bit in the basic encryption library so that the encryption bit can be used as the import location of the combined ciphertext and the whole ciphertext, and ensure that the position status of the combined ciphertext and the whole ciphertext in the basic encryption library is relatively independent;

[0107] Specifically, the encryption bits include deep encryption bits and shallow encryption bits; wherein the deep encryption bits are used to limit the import position of the combined ciphertext, and the shallow encryption bits are used to limit the import position of the entire ciphertext.

[0108] When constructing a basic encryption library, first construct a blank database, then establish two data layers with inner and outer wrapped distributions in the database, record the data layer on the inner side as the combination layer, and record the data layer on the outer side as the whole layer, then set A spaced data bits in the combination layer to obtain A deep encryption bits, set B spaced data bits in the whole layer to obtain B shallow encryption bits, and finally record the database with deep encryption bits and shallow encryption bits as the basic encryption library.

[0109] After building the basic encryption library, the combined ciphertext and the full ciphertext can be imported into the corresponding encryption bits, and an encryption wall can be established between the encryption bits where the data has been imported. This allows the encryption wall to isolate and protect the enterprise cloud data in the two adjacent encryption bits, preventing the enterprise cloud data in adjacent encryption bits from being mixed and crossed with each other, thereby ensuring the independent stability of the enterprise cloud data in the encryption bits and ultimately forming a data encryption library.

[0110] The encryption fence includes an inner fence and an outer fence; wherein, the inner fence is an electronic fence used to provide isolation protection for deep encryption bits, and the outer fence is an electronic fence used to provide isolation protection for shallow encryption bits.

[0111] The construction method of the data encryption library includes:

[0112] Importing A combined ciphertexts and B full ciphertexts into A deep encryption bits and B shallow encryption bits one by one, and then arranging A deep encryption bits and B shallow encryption bits in an equiangular circular arrangement. This equiangular circular arrangement can arrange the deep encryption bits and shallow encryption bits in an orderly circular arrangement, thereby providing a structural foundation for the subsequent establishment of an encryption wall between two adjacent encryption bits.

[0113] A first electronic fence is constructed between two adjacent deep encryption points. A control point and two status points are simulated on the first electronic fence to generate an inner wall. The control point is the point that can switch the state of the encryption wall, and the status point is the point used to provide status for the encryption wall. The two status points are located on both sides of the control point, achieving a symmetrical distribution effect.

[0114] A second electronic fence is constructed between two adjacent shallow encryption positions, and a control point and two status points are simulated on the second electronic fence to generate an outer fence;

[0115] The open state and the closed state are set at the two status points of the inner wall and the outer wall respectively, and the control point is adjusted to the open state to form an on-off node, prompting the basic encryption library to be converted into a data encryption library.

[0116] It should be noted that by constructing an encryption wall between the encryption bits, the encrypted data in two adjacent encryption bits can be independently stored and protected to prevent the encrypted data in adjacent encryption bits from being cross-mixed. At the same time, by utilizing the real-time on-off control effect of the on-off node, when the encrypted data in a certain encryption bit is attacked or otherwise negatively affected and data leakage occurs, the connection between the adjacent encryption bits can be cut off in time, thereby avoiding the encrypted data in the adjacent encryption bits from being affected by the negative impact, thereby ensuring the independence and security of the encrypted data in the data encryption library.

[0117] The abnormality judgment module collects the access data of the encrypted bits in the data encryption library in real time and determines whether to issue an abnormality protection prompt;

[0118] After the data encryption library is built, all enterprise cloud data in the database that needs to be encrypted has implemented the corresponding encryption operations, which can not only improve the storage security of enterprise cloud data, but also facilitate the related cloud computing of enterprise cloud data by managers within the enterprise.

[0119] When the encrypted enterprise cloud data is stored in the data encryption library, the enterprise cloud data will be affected by interference and attacks from various aspects, which may cause the enterprise cloud data stored in the data encryption library to be lost, leaked, and other negative effects. In order to accurately understand whether the enterprise cloud data in the data encryption library has abnormal phenomena under interference attacks, it is necessary to collect and analyze the relevant negative interference attack data on the encryption bits in the data encryption library, and record the relevant negative interference attack data as access data;

[0120] Access data includes super-authority access value, key validity period and encryption stability coefficient;

[0121] Among them, the super-authority access value refers to the number of access records received by the encryption bit in the data encryption library that exceeds the preset access rights, which can indicate the probability of an abnormality occurring in the encryption bit. The larger the super-authority access value, the higher the probability of an abnormality occurring in the encryption bit. The super-authority access value is obtained after querying the permission management system.

[0122] The key aging duration refers to the length of time that the encryption key in the data encryption library remains in the aging state. It can be used to indicate the probability of anomalies occurring in the encryption bits. The longer the key aging duration, the higher the probability of anomalies occurring in the encryption bits. The key aging duration is obtained by querying the key management system.

[0123] The encryption stability coefficient refers to the numerical value of the encryption stability performance of the encryption bit in the data encryption library at the current moment, which can be used to indicate the probability of anomalies occurring in the encryption bit. The larger the encryption stability coefficient, the higher the probability of anomalies occurring in the encryption bit. The encryption stability coefficient is obtained by querying the encryption management system.

[0124] After obtaining the super-authorized access value, key validity period, and encryption stability coefficient, the super-authorized access value, key validity period, and encryption stability coefficient can be analyzed and compared. Based on the results of the analysis and comparison, a conclusion can be drawn on the current status of the encryption bits in the data encryption library. In addition, in the event of a high probability of anomalies in the encryption bits, an abnormality protection prompt can be issued in a timely manner.

[0125] The methods for determining whether to issue an abnormal protection prompt include:

[0126] Compare the super-privilege access value, key validity period and encryption stability coefficient with the corresponding calibration values ​​respectively;

[0127] When the super-privileged access value is greater than the access calibration value, it means that the number of access records exceeding the corresponding access rights in the encryption bit is large, and the super-privileged access value is recorded as an abnormal value; the access calibration value refers to the maximum value of the super-privileged access value when it is not recorded as an abnormal value;

[0128] When the key aging duration is greater than the aging calibration value, it means that the span of time in the encrypted bits that exceeds the corresponding key aging duration is large, and the key aging duration is recorded as an abnormal value; the aging calibration value refers to the maximum value of the key aging duration that is not recorded as an abnormal value;

[0129] When the encryption stability coefficient is less than the stability calibration value, it means that the encryption stability performance value in the encryption bit is low, and the encryption stability coefficient is recorded as an abnormal value; the stability calibration value refers to the minimum value of the encryption stability coefficient when it is not recorded as an abnormal value;

[0130] Count the number of abnormal values ​​on the encryption bit. When the number of abnormal values ​​is 0 or 1, it means that the security performance of the encryption bit is high and the probability of abnormal phenomena is low. In this case, it is determined that no abnormal protection prompt will be issued;

[0131] When the number of abnormal values ​​is 2 or 3, it means that the security performance of the encryption bit is low and the probability of abnormal phenomena is high, and it is determined that an abnormal protection prompt will be issued.

[0132] The encryption bit stripping module, if an abnormal protection prompt is issued, locates the target encryption bit and target wall from the data encryption library, switches the on / off state of the target wall, and strips the target encryption bit from the data encryption library;

[0133] When an abnormal protection prompt is issued, it means that there is a high probability that the encryption bits in the data encryption library will be leaked, lost, or confused. In this case, abnormal protection processing needs to be performed on the encryption bits that issued the abnormal protection prompt. Before performing abnormal protection processing, the corresponding target encryption bits need to be determined.

[0134] Specifically, the target encryption bit is the deep encryption bit or shallow encryption bit that determines whether an exception protection prompt is issued and requires exception protection processing. The number of target encryption bits is not unique and may be one or more.

[0135] The target fence is an inner fence or an outer fence located on both sides of the target encryption bit and needs to be switched between on and off states. The number of target walls is not unique. For example, when the number of target encryption bits is N, the number of target walls may be 2N or 2N+1.

[0136] After locating the target encryption bit and the target wall, the enterprise cloud data in the target encryption bit can be processed accordingly for abnormal protection, and the abnormal protection measures of the target encryption bit can be combined with the target wall to accurately remove the target encryption bit from the data encryption library.

[0137] When stripping the encrypted data from the encryption database, it is necessary to first adjust the on / off state of the target wall so that the on / off nodes in the target wall can be switched between the on and off states, thereby laying the foundation for stripping the target encrypted data.

[0138] The on-off state is used to specifically represent the real-time conduction and blocking conditions of the target wall. Specifically, the on-off state includes the conduction state and the blocking state.

[0139] Methods for stripping the target encryption bits include:

[0140] When the target encryption position is a deep encryption position, the inner walls on both sides of the target encryption position are recorded as target walls;

[0141] When the target encryption position is a shallow encryption position, the outer walls on both sides of the target encryption position are recorded as target walls;

[0142] Adjusting the on / off node on the target wall from an on state to a off state, thereby causing the on / off state of the target wall to switch from a conducting state to a blocking state;

[0143] In the blocking state, the enterprise cloud data in the target encryption bit is compressed and aggregated into a data packet, and the data packet is stripped from the data encryption library as a whole.

[0144] Regardless of whether it is enterprise cloud data in deep encryption bits or shallow encryption bits, the stripping methods used when stripping it from the data encryption library are consistent, which can achieve fast and accurate stripping of enterprise cloud data in the target encryption bits, and prevent interference attacks on the target encryption bits from affecting the enterprise cloud data in the adjacent encryption bits, thereby ensuring the stability and security of enterprise cloud data in encrypted storage and management.

[0145] In this embodiment, by extracting the encryption characteristics of enterprise cloud data, different encryption methods can be used for enterprise cloud data of different sensitivities, thereby accurately distinguishing between cross-combination encryption and overall single encryption for enterprise cloud data. This achieves adaptive encryption for enterprise cloud data, avoids the problems of mismatched encryption mechanisms and poor encryption effects that arise when the same encryption method is used for enterprise cloud data of different sensitivities, and improves the rationality of enterprise cloud data encryption operations.

[0146] By building a data encryption library with an encryption wall, it is possible to independently and accurately store and manage the encrypted enterprise cloud data, and at the same time, it is possible to establish an electronic fence with isolation and protection between two adjacent encrypted enterprise cloud data, maintaining the independence of the enterprise cloud data in the data encryption library. When a certain enterprise cloud data is leaked or lost due to an interference attack, the enterprise cloud data that has been interfered with can be separated separately, thereby effectively avoiding the impact of the interference attack on the enterprise cloud data in the adjacent location, improving the independence and stability of the enterprise cloud data in the data encryption library, and achieving efficient, independent and accurate encryption processing of the enterprise cloud data.

[0147] Example 2: Please refer to Figure 2 As shown, for parts not described in detail in this embodiment, please refer to the description of Embodiment 1. A method for encrypting and processing enterprise cloud data is provided, which is applied to an encryption server and implemented based on an enterprise cloud data encryption processing system, including:

[0148] S1: Extract the encryption features of enterprise cloud data in the cloud database, analyze the sensitive attributes of the enterprise cloud data based on the encryption features, and classify and summarize the enterprise cloud data;

[0149] S2: Perform cross-combination encryption operations on highly sensitive data and overall single encryption operations on less sensitive data to generate combined ciphertext and full ciphertext respectively;

[0150] S3: Build a basic encryption library, import the combined ciphertext and the full ciphertext into the encryption bits of the basic encryption library, and establish an encryption fence with on-off nodes between adjacent encryption bits to generate a data encryption library;

[0151] S4: collect access data of the encryption bits in the data encryption library in real time and determine whether to issue an abnormal protection prompt;

[0152] S5: If an abnormal protection prompt is issued, locate the target encryption bit and the target wall from the data encryption library, switch the on / off state of the target wall, and strip the target encryption bit from the data encryption library.

[0153] The above description is only a specific embodiment of the present invention, but the scope of protection of the present invention is not limited thereto. Any technician familiar with this technical field can easily think of changes or replacements within the technical scope disclosed by the present invention, which should be covered by the scope of protection of the present invention.

Claims

1. An enterprise cloud data encryption processing system, applied to an encryption server, characterized in that: include: The data identification module is used to extract the encryption features of enterprise cloud data in the cloud database, analyze the sensitive attributes of the enterprise cloud data based on the encryption features, and classify and summarize the enterprise cloud data; The data encryption module is used to perform cross-combination encryption operations on highly sensitive data and overall single encryption operations on less sensitive data, generating combined ciphertext and full ciphertext respectively; The encryption library construction module is used to construct a basic encryption library, import the combined ciphertext and the full ciphertext into the encryption bits of the basic encryption library, and establish an encryption fence with on-off nodes between adjacent encryption bits to generate a data encryption library; The abnormality determination module is used to collect access data of the encrypted bits in the data encryption library in real time and determine whether to issue an abnormality protection prompt; The encryption bit stripping module is used to locate the target encryption bit and the target fence from the data encryption library, and switch the on and off state of the target fence to strip the target encryption bit from the data encryption library.

2. The enterprise cloud data encryption processing system according to claim 1, characterized in that: The encryption feature extraction methods include: Arrange all enterprise cloud data in the cloud database in the order of recording time to generate a cloud data queue; Starting from the first enterprise cloud data in the cloud data queue, the key semantics of all enterprise cloud data are identified in sequence using natural language processing technology; The key semantics are split into text groups and number groups through word segmentation technology, and the text groups are separated from the key semantics to generate encryption features.

3. The enterprise cloud data encryption processing system according to claim 2, characterized in that: Sensitive attributes include highly sensitive data and low-sensitivity data. The analysis methods for highly sensitive data and low-sensitivity data include: Identify the standard semantics of property information, customer information, identity information, business information, decision-making information, confidential information, special information, defense information, legal information, and decision-making information in the database one by one, and record the text parts in the standard semantics as marked highly sensitive text; When the encryption feature overlaps with the calibrated highly sensitive text, the enterprise cloud data is recorded as highly sensitive data, and A highly sensitive data are obtained; When the encryption feature does not overlap with the calibrated high-sensitivity text, the enterprise cloud data is recorded as low-sensitivity data, and B low-sensitivity data are obtained.

4. The enterprise cloud data encryption processing system according to claim 3, characterized in that: The methods for generating combined ciphertext include: A first encryption model with two encryption channels distributed vertically is constructed, and the two encryption channels are respectively recorded as a logic encryption channel and a content encryption channel in a top-down manner; Import A highly sensitive data into the logical encryption channel one by one, identify the highly sensitive fields in the highly sensitive data using regular expressions, and split the highly sensitive fields from the highly sensitive data to generate A highly sensitive data blocks; Query the permission levels of the highly sensitive fields in the A highly sensitive data blocks one by one in the database, and set the access logic strategy for the highly sensitive data blocks based on the value of the permission level; Combine ABE encryption technology with access logic policy to form a logical password, and use the logical password to logically encrypt highly sensitive data blocks to generate A policy-bound ciphertexts; Transfer A policy-bound ciphertexts from the logical encryption channel to the content encryption channel, mark the transfer time, and derive a temporary key from the master key. Attach the transfer time to the temporary key to generate a dynamic key. Based on the dynamic key, the SM4 algorithm combined with the dynamic S-box is used to encrypt A policy-bound ciphertexts to generate A content-bound ciphertexts; The previous moment before the content-bound ciphertext is generated is recorded as the target moment. The target moment, the algorithm version of the SM4 algorithm, and the recording time of A sensitive data blocks are summarized into ciphertext parameters. The ciphertext parameters are added to the A content-bound ciphertexts to generate A combined ciphertexts.

5. The enterprise cloud data encryption processing system according to claim 4, characterized in that: The method for generating the whole ciphertext includes: Construct a second encryption model with B sub-channels, import the B low-sensitivity data into the B sub-channels one by one, and number the B sub-channels in ascending order; Identify low-sensitivity fields in low-sensitivity data using regular expressions, and cut the low-sensitivity fields from the low-sensitivity data to generate B low-sensitivity data blocks; At the same time, the ChaCha20 algorithm is used to concurrently encrypt the low-sensitivity data blocks in B sub-channels to generate B initial ciphertexts. The generation times of the B initial ciphertexts are queried one by one, the B generation times are combined with the corresponding sub-channel numbers to form B dynamic private keys, and the B dynamic private keys are matched with the B initial ciphertexts one by one to generate B full ciphertexts.

6. The enterprise cloud data encryption processing system according to claim 5, characterized in that: The encryption bits include deep encryption bits and shallow encryption bits; The construction method of the basic encryption library includes: Construct a blank database, and create two data layers with inner and outer wrapped distribution in the database. The data layer on the inner side is recorded as the combined layer, and the data layer on the outer side is recorded as the whole layer. A spaced data bits are set in the combined layer to obtain A deep encryption bits, and B spaced data bits are set in the whole layer to obtain B shallow encryption bits. The database with A deep encryption bits and B shallow encryption bits is recorded as the basic encryption library.

7. The enterprise cloud data encryption processing system according to claim 6, characterized in that: The encrypted fence includes the inner fence and the outer fence; The construction method of the data encryption library includes: Import A combined ciphertexts and B full ciphertexts into A deep encryption bits and B shallow encryption bits one by one, and arrange A deep encryption bits and B shallow encryption bits in a circular manner with equal angles; A first electronic fence is constructed between two adjacent deep encryption positions, and a control point and two status points are simulated on the first electronic fence to generate an inner fence; A second electronic fence is constructed between two adjacent shallow encryption positions, and a control point and two status points are simulated on the second electronic fence to generate an outer fence; The open state and the closed state are set at the two status points of the inner wall and the outer wall respectively, and the control point is adjusted to the open state to form an on-off node, prompting the basic encryption library to be converted into a data encryption library.

8. The enterprise cloud data encryption processing system according to claim 7, characterized in that: Access data includes super-authority access value, key validity period and encryption stability coefficient; The methods for determining whether to issue an abnormal protection prompt include: When the super-authority access value is greater than the access calibration value, the super-authority access value is recorded as an abnormal value; When the key validity period is greater than the validity calibration value, the key validity period is recorded as an abnormal value; When the encrypted stability coefficient is less than the stable calibration value, the encrypted stability coefficient is recorded as an abnormal value; Count the number of abnormal values ​​on the encryption bit. If the number of abnormal values ​​is 0 or 1, it is determined that no abnormal protection prompt will be issued. When the number of abnormal values ​​is 2 or 3, it is determined that an abnormality protection prompt is issued.

9. The enterprise cloud data encryption processing system according to claim 8, characterized in that: The target encryption bit is a deep encryption bit or a shallow encryption bit for determining whether an abnormal protection prompt is issued; The target wall is the inner wall or outer wall located on both sides of the target encryption position.

10. The enterprise cloud data encryption processing system according to claim 9, characterized in that: The on-off state includes the on state and the blocking state; Methods for stripping the target encryption bits include: When the target encryption position is a deep encryption position, the inner walls on both sides of the target encryption position are recorded as target walls; When the target encryption position is a shallow encryption position, the outer walls on both sides of the target encryption position are recorded as target walls; Adjusting the on / off node on the target wall from an on state to a off state, thereby causing the on / off state of the target wall to switch from a conducting state to a blocking state; In the blocking state, the enterprise cloud data in the target encryption bit is compressed and aggregated into a data packet, and the data packet is stripped from the data encryption library as a whole.

Citation Information

Patent Citations

  • Data encryption system based on service data sharing cloud platform

    CN114500035A