Data storage method and device based on extended attributes, equipment and medium

By employing layered encryption and dynamic compression technologies, combined with a B-tree index structure and intelligent caching mechanisms, the efficiency and security issues in extended attribute storage are resolved, improving query performance and data security, making it suitable for large-scale data storage environments.

CN120872918AActive Publication Date: 2025-10-31SHANDONG LANGCHAO YUNTOU INFORMATION TECH CO LTD
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202511404094.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-09-29
Publication Date
2025-10-31
Estimated Expiration
2045-09-29

AI Technical Summary

Technical Problem

Existing extended attribute storage solutions have bottlenecks in storage efficiency, query performance, and data security, especially with large data volumes, leading to wasted storage space, decreased query performance, and the risk of sensitive data leakage.

Method used

Layered encryption technology is used to encrypt extended attribute data. Combined with dynamic compression algorithm and B-tree index structure, query path and caching mechanism are optimized, and intelligent key management system and multi-threaded parallel processing technology are utilized.

Benefits of technology

It improves the efficiency and security of extended attribute storage, enhances query performance, reduces storage space usage and the risk of sensitive data leakage, and is suitable for large-scale data storage environments.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120872918A_ABST
    Figure CN120872918A_ABST
Patent Text Reader

Abstract

The invention discloses a data storage method and device based on extended attributes, equipment and a medium, and relates to the technical field of computers. Comprising the steps of performing hierarchical encryption processing on extended attribute data based on an attribute type of the extended attribute data to obtain corresponding encrypted extended attribute data; determining a corresponding data compression algorithm based on the data type of the encrypted extended attribute data, and dynamically compressing the encrypted extended attribute data based on the data compression algorithm to obtain to-be-stored data; and storing the to-be-stored data in a preset storage space so as to execute access and query operations on the data in the preset storage space by utilizing a preset index structure when receiving access and query requests for the data in the preset storage space. Therefore, the storage efficiency, the data security and the query performance of the extended attribute storage can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of computer technology, and in particular to a data storage method, apparatus, device, and medium based on extended attributes. Background Technology

[0002] Extended attributes, a crucial feature of file systems, allow users or the system to attach arbitrary forms of metadata to files, directories, and other objects. Unlike traditional file attributes (such as filename, size, and modification time), the greatest advantage of extended attributes lies in their flexibility. They can store various types of additional data, such as file security markers, access control information, encryption status, and file tags. Due to their flexibility and scalability, extended attributes are widely used in modern operating systems, especially in systems supporting large-scale data storage, cloud computing, and network file systems. Through these extended attributes, file systems can not only provide additional information storage but also enhance file management and security control capabilities. For example, in network file systems, extended attributes can be used to store network-shared information and version control data; in cloud storage environments, extended attributes can be used to record file metadata and access control lists. These application scenarios demonstrate the importance of extended attributes in modern storage systems.

[0003] While extended attributes offer powerful functionality, existing extended attribute storage and management mechanisms face a series of technical bottlenecks as data volume and the number of attributes increase. First, existing extended attribute storage schemes perform poorly in terms of storage efficiency. When the number of extended attributes is large, existing storage structures, such as directly embedding extended attributes into inodes, easily lead to wasted space. Especially when storing large amounts of attributes, a single storage structure often struggles to meet these demands, resulting in insufficient storage space utilization and even affecting the scalability of the file system. Second, existing extended attribute storage schemes also have significant performance bottlenecks. Extended attributes often involve frequent query, update, and delete operations. When processing a large number of extended attributes, traditional linear storage methods cannot provide efficient query performance, especially when data volume increases dramatically, query and access performance drops significantly. Furthermore, frequent disk access to extended attributes increases I / O overhead, further impacting overall performance. Especially when storing large amounts of attribute data in the file system, each query or modification of an extended attribute requires more disk time, leading to slower system response and performance degradation. More seriously, with the increasing prominence of information security issues, extended attributes may involve a large amount of sensitive data (such as security tags, user permissions, encryption keys, etc.). Many existing file systems do not encrypt extended attributes when storing them, leading to the risk of sensitive data leakage. Without effective encryption, malicious users can obtain data that should not be disclosed by accessing the file's extended attributes, thereby compromising the security of the file system. Furthermore, existing technologies mostly lack flexible and efficient key management mechanisms for encrypted extended attribute data. File systems typically use relatively simple encryption schemes or rely on external security modules (such as HSMs, or Hardware Security Modules) for encryption, resulting in complexity and insecurity in key management and use.

[0004] As can be seen from the above, improving the storage efficiency, data security, and query performance of extended attribute storage is an urgent problem to be solved. Summary of the Invention

[0005] In view of this, the purpose of this invention is to provide a data storage method, apparatus, device, and medium based on extended attributes, which can improve the storage efficiency, data security, and query performance of extended attribute storage. The specific solution is as follows:

[0006] In a first aspect, this application provides a data storage method based on extended attributes, comprising:

[0007] The extended attribute data is subjected to layered encryption based on the attribute type to obtain the corresponding encrypted extended attribute data; the attribute type includes user-defined extended attributes, system extended attributes, and security attributes.

[0008] Based on the data type of the encrypted extended attribute data, a corresponding data compression algorithm is determined, and the encrypted extended attribute data is dynamically compressed based on the data compression algorithm to obtain the data to be stored; the data type includes text data, binary data, and structured data; the data to be stored includes attribute name, the size of the attribute value before and after compression, and data compression algorithm information;

[0009] The data to be stored is stored in a preset storage space so that when an access and query request for the data in the preset storage space is received, access and query operations are performed on the data in the preset storage space using a preset index structure.

[0010] Optionally, the step of performing layered encryption processing on the extended attribute data based on the attribute type of the extended attribute data to obtain corresponding encrypted extended attribute data includes:

[0011] The target encryption algorithm is determined from the preset encryption algorithms based on the attribute type of the extended attribute data, and the corresponding encryption key is generated by the preset key management system based on the attribute type; the preset encryption algorithms include symmetric encryption algorithms, asymmetric encryption algorithms, and hash encryption algorithms;

[0012] The extended attribute data is encrypted using the target encryption algorithm and the encryption key to obtain encrypted extended attribute data.

[0013] Optionally, after determining the corresponding data compression algorithm based on the data type of the encrypted extended attribute data, the method further includes:

[0014] The data compression algorithm is adjusted based on the data access frequency, data size, and current load of the encrypted extended attribute data.

[0015] Optionally, after storing the data to be stored in the preset storage space, the method further includes:

[0016] An index corresponding to the data to be stored is created using a preset index structure, and the data in the preset storage space is managed based on the index; the index includes the name, attribute value type, attribute value length, and storage location of the data to be stored.

[0017] Optionally, the step of using a preset index structure to perform access and query operations on the data in the preset storage space includes:

[0018] The query path is determined using a preset index structure and a query path optimization mechanism, and the data in the preset storage space is queried based on the query path.

[0019] The data in the preset storage space that meets the preset caching conditions is cached using a preset index structure and an intelligent caching mechanism, so that access operations can be performed on the cached data; the preset caching conditions are that the number of historical accesses is greater than a preset access number threshold.

[0020] Optionally, storing the data to be stored in a preset storage space includes:

[0021] For data to be stored that meets the preset storage conditions, sparse storage technology is used to store the data to be stored in the preset storage space;

[0022] For continuously stored data to be stored, a data block merging mechanism is used to store the data to be stored into a preset storage space.

[0023] Optionally, the data storage method based on extended attributes further includes:

[0024] During the data decryption process, a preset message verification code is used to verify the data integrity of the encrypted extended attribute data.

[0025] Secondly, this application provides a data storage device based on extended attributes, comprising:

[0026] The data encryption module is used to perform layered encryption processing on the extended attribute data based on the attribute type of the extended attribute data to obtain the corresponding encrypted extended attribute data; the attribute type includes user-defined extended attributes, system extended attributes, and security attributes;

[0027] The data compression module is used to determine the corresponding data compression algorithm based on the data type of the encrypted extended attribute data, and to dynamically compress the encrypted extended attribute data based on the data compression algorithm to obtain data to be stored; the data type includes text data, binary data, and structured data; the data to be stored includes attribute name, the size of the attribute value before and after compression, and data compression algorithm information;

[0028] The data storage module is used to store the data to be stored in a preset storage space so that when an access and query request for the data in the preset storage space is received, the module can use a preset index structure to perform access and query operations on the data in the preset storage space.

[0029] Thirdly, this application provides an electronic device, comprising:

[0030] Memory, used to store computer programs;

[0031] A processor is used to execute the computer program to implement the aforementioned data storage method based on extended attributes.

[0032] Fourthly, this application provides a computer-readable storage medium for storing a computer program, wherein the computer program, when executed by a processor, implements the aforementioned data storage method based on extended attributes.

[0033] This application provides a data storage method based on extended attributes. First, the extended attribute data is subjected to layered encryption based on its attribute type to obtain corresponding encrypted extended attribute data. The attribute types include user-defined extended attributes, system extended attributes, and security attributes. Then, a corresponding data compression algorithm is determined based on the data type of the encrypted extended attribute data, and the encrypted extended attribute data is dynamically compressed using the data compression algorithm to obtain data to be stored. The data types include text data, binary data, and structured data. The data to be stored includes attribute names, the size of attribute values ​​before and after compression, and data compression algorithm information. Finally, the data to be stored is stored in a preset storage space so that when an access and query request for data in the preset storage space is received, access and query operations can be performed on the data in the preset storage space using a preset index structure.

[0034] As can be seen from the above, this application significantly reduces storage space usage by introducing dynamic compression technology and selecting appropriate compression algorithms based on the characteristics of extended attribute data. The hierarchical encryption method based on attribute types effectively protects the security of sensitive data by applying encryption algorithms of different strengths to different types of extended attribute data. Furthermore, the query path optimization mechanism and intelligent caching mechanism through a pre-defined index structure significantly improve the query and access performance of extended attributes. Therefore, it enhances the storage efficiency, data security, and query performance of extended attribute storage. Attached Figure Description

[0035] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on the provided drawings without creative effort.

[0036] Figure 1 This is a flowchart of a data storage method based on extended attributes disclosed in this application;

[0037] Figure 2 This is a schematic diagram of a data storage device based on extended attributes disclosed in this application;

[0038] Figure 3 This is a structural diagram of an electronic device disclosed in this application. Detailed Implementation

[0039] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0040] Extended attributes, as an important feature of file systems, allow users or systems to attach arbitrary forms of metadata to objects such as files and directories. Unlike traditional file attributes (such as filename, size, and modification time), the greatest advantage of extended attributes lies in their flexibility. They can store various types of additional data, such as file security markers, access control information, encryption status, and file tags. Due to their flexibility and scalability, extended attributes are widely used in modern operating systems, especially in supporting large-scale data storage, cloud computing, and network file systems. Extended attributes provide file systems with great flexibility and scalability, but existing technologies still have significant shortcomings in terms of storage efficiency, query performance, security, and support for big data environments. Therefore, this application discloses a data storage scheme based on extended attributes, which can improve the storage efficiency, data security, and query performance of extended attribute storage.

[0041] See Figure 1 As shown in the figure, this application discloses a data storage method based on extended attributes, including:

[0042] Step S11: Perform layered encryption processing on the extended attribute data based on the attribute type of the extended attribute data to obtain the corresponding encrypted extended attribute data.

[0043] In this embodiment, extended attributes are divided into multiple categories based on their attribute type and sensitivity, and different encryption algorithms and encryption strengths are applied to each category. This layered encryption strategy can balance encryption strength and performance overhead according to the actual needs of the data, thereby ensuring data confidentiality while avoiding storage bloat and computational overhead caused by excessive encryption. The attribute types include, but are not limited to, user-defined extended attributes, system extended attributes, and security attributes. Specifically, the layered encryption processing of the extended attribute data based on its attribute type to obtain corresponding encrypted extended attribute data can include:

[0044] The target encryption algorithm is determined from preset encryption algorithms based on the attribute type of the extended attribute data, and a corresponding encryption key is generated based on the attribute type using a preset key management system. For user-defined extended attributes (such as attributes of type "user."), these attributes generally contain information of low sensitivity (such as user comments, tags, personalized settings, etc.). Therefore, in some specific implementations, a symmetric encryption algorithm (AES-128 encryption algorithm; AES, or Advanced Encryption Standard) can be used for encryption. The AES-128 encryption algorithm has high security, and due to its short key length, it has high computational efficiency, making it suitable for protecting low-sensitivity data. For system-generated extended attributes (such as attributes of type "system."), these attributes contain operating system configuration, log information, or file system metadata, which are highly sensitive but not absolutely sensitive data. Therefore, in some specific implementations, AES-192 or AES-256 can be used as the encryption algorithm. The AES-256 algorithm has stronger security, is suitable for protecting moderately sensitive data, and can resist stronger attacks. For file security attributes (such as attributes of type `security.`), these attributes contain critical and sensitive data such as file access control information, encrypted file identifiers, and permission policies. In some specific implementations, the AES-256 encryption algorithm can be used in conjunction with HMAC-SHA-256 (HMAC stands for Hash-based Message Authentication Code; SHA stands for Secure Hash Algorithm) for encryption protection to ensure the confidentiality and integrity of the data. HMAC-SHA-256 provides a message authentication code that can effectively prevent data tampering.

[0045] The encryption and decryption process for extended attributes must ensure performance while maintaining uncompromised data security. When encrypting extended attributes, the appropriate encryption algorithm (e.g., AES-128, AES-256) is first determined based on the attribute type. A random key is generated for each type of extended attribute for data encryption. The key management system is responsible for generating, distributing, and storing keys. For symmetric encryption algorithms (e.g., AES), encryption keys are managed according to attribute categories to ensure key security. The value of the extended attribute is encrypted using the selected encryption algorithm and key. The attribute length information is also encrypted during the encryption process to prevent side-channel attacks. The encrypted attribute value is stored along with its metadata (e.g., attribute name, original size, etc.). The metadata itself is also encrypted to prevent its leakage. Furthermore, when an extended attribute needs to be read, the corresponding encrypted data block is first located in the file system using the attribute name. The corresponding decryption key is obtained from the key management system based on the attribute type. For encrypted file system metadata, the key is also dynamically provided by the key management system. The obtained key and the selected decryption algorithm (e.g., AES decryption algorithm) are used to decrypt the value of the extended attribute. The decryption process restores the original attribute values ​​and ensures that the decrypted data is completely consistent with the data stored at the time.

[0046] It is important to note that the aforementioned smart key management system can perform operations such as key generation, distribution, storage, updating, and revocation. All encryption keys are randomly generated and their length conforms to the requirements of the encryption algorithm. Keys are generated through a hardware security module and stored internally, ensuring that keys are never exposed in plaintext. The smart key management system manages the key lifecycle, including key creation, updating, revocation, and expiration. Each encryption operation is bound to a key version number to trace the key's historical usage records when needed. When a key is deemed insecure or expired, the smart key management system automatically updates the key and re-encrypts all extended attributes encrypted with that key to ensure system security. Furthermore, the smart key management system supports a key revocation mechanism; if a key is leaked, its usage is immediately revoked, and a new key is used in its place.

[0047] Furthermore, to ensure the data integrity of extended attributes during storage and transmission, this application also incorporates HMAC for message authentication. Specifically, during data decryption, a preset message verification code is used to verify the data integrity of the encrypted extended attribute data. That is, each encrypted extended attribute value is appended with an HMAC based on SHA-256 to ensure data integrity and prevent replay attacks. HMAC can effectively prevent data from being tampered with during storage and transmission. If an HMAC verification failure is detected during decryption, it indicates that the data has been tampered with, and the system will refuse to provide the value of that extended attribute. At the same time, HMAC authentication ensures that the data has not been tampered with and can verify the source of the data, preventing attackers from using old data for replay attacks.

[0048] It is worth mentioning that, considering the potential performance bottlenecks during encryption and decryption, this invention employs several optimization measures during the encryption process to ensure that encryption does not excessively impact the file system's responsiveness. Specific optimization measures include: supporting hardware acceleration (such as the CPU's built-in AES-NI instruction set) to speed up the encryption and decryption process. Hardware acceleration can significantly reduce CPU utilization and latency, improving the execution efficiency of encryption operations. For encryption and decryption of large-scale extended attributes, this invention supports multi-threaded parallel processing, distributing encryption operations across multiple CPU cores, thereby improving processing speed and reducing the performance burden of encryption and decryption. For frequently accessed extended attributes, encrypted data is stored in a high-speed cache, reducing the decryption overhead during each read.

[0049] Step S12: Determine the corresponding data compression algorithm based on the data type of the encrypted extended attribute data, and dynamically compress the encrypted extended attribute data based on the data compression algorithm to obtain the data to be stored.

[0050] In this embodiment, the most suitable compression algorithm is automatically selected based on the characteristics of different data types. These data types include, but are not limited to, text data, binary data, and structured data. Specifically, for extended attributes primarily composed of text (such as tags, categories, etc.), in some implementations, the LZ77 or LZ78 algorithm can be selected for compression. This algorithm is suitable for text data with obvious repetitive patterns; by finding repeating string patterns, it can efficiently reduce storage space. The advantage of this algorithm is its high compression ratio, while also offering fast compression and decompression speeds for regular text data, suitable for the performance requirements of file systems. For extended attributes involving binary data (such as encrypted file signatures), in some implementations, compression algorithms such as Zlib or Snappy can be used. Zlib provides a good balance between compression ratio and performance, suitable for data that needs frequent access in file systems, especially in scenarios with high decompression speed requirements, where Snappy's efficient decompression features will be fully utilized. For structured data (such as JSON, XML, or custom data structures; JSON stands for JavaScript Object Notation; XML stands for eXtensible Markup Language), in some implementations, efficient compression algorithms such as Brotli or LZ4 can be used. The Brotli algorithm boasts a high compression ratio and fast decompression speed, making it suitable for processing complex structured data. It maintains high decompression performance while reducing storage space usage. In other words, this embodiment dynamically selects a suitable compression algorithm, adjusting the storage method according to the specific data characteristics of the extended attributes to maximize storage efficiency.

[0051] Furthermore, considering that frequent access to extended attributes may lead to excessive compression and decompression overhead, this embodiment designs an adaptive compression ratio and performance balance mechanism. Specifically, after determining the corresponding data compression algorithm based on the data type of the encrypted extended attribute data, it may further include: for extended attributes with low access frequency, a higher compression ratio is used to save storage space and minimize disk space occupation; while for extended attributes with frequent access, a lower compression ratio algorithm or no data compression is selected to avoid performance loss caused by frequent compression and decompression. For small extended attribute data (such as simple tagging information within a few hundred bytes), since the time cost of compression and decompression is high, the original data can be stored directly; while for large extended attribute data (such as data greater than 1MB), this invention will choose to store it after compression to reduce storage space occupation. The compression strategy is dynamically adjusted according to the system load. Under high load, the system will prioritize the use of low compression ratio algorithms to reduce the impact on CPU and I / O performance; while under low load, the system will tend to use algorithms with higher compression ratios to improve storage efficiency.

[0052] Step S13: Store the data to be stored in a preset storage space so that when an access and query request for the data in the preset storage space is received, the data in the preset storage space can be accessed and queried using a preset index structure.

[0053] In this embodiment, the data to be stored is stored in the preset storage space according to a specific data format. The data to be stored includes attribute names, the size of attribute values ​​before and after compression, and data compression algorithm information.

[0054] Furthermore, to address the issue of low query efficiency in extended attribute storage, this embodiment introduces a B-tree (Balanced Tree)-based index structure to store extended attribute data and metadata. Specifically, after storing the data to be stored in a preset storage space, the process may further include: creating a B-tree index for each file's extended attributes. This index contains metadata such as the extended attribute name, attribute value type, attribute value length, and attribute value storage location. When an extended attribute is stored in the file system, its index information is first generated and inserted into the B-tree. The file system can then directly locate the storage block where the extended attribute is located through the B-tree index, significantly accelerating the query process. As the file system performs add, delete, modify, and query operations, the number of extended attributes changes. To maintain the efficiency of the B-tree index, a dynamic balancing mechanism is employed to ensure that the index remains balanced after each insertion or deletion operation. At the physical storage level, a multi-level B-tree index structure ensures that each level on the storage medium corresponds to a subtree, thereby shortening the access path and accelerating the extended attribute lookup process. Through this multi-level indexing mechanism, this embodiment can maintain high query efficiency when storing a large number of extended attributes.

[0055] In this embodiment, the query efficiency of extended attributes is further improved by optimizing the query path and caching mechanism. Specifically, the step of using a preset index structure to perform access and query operations on data in the preset storage space may include: determining a query path based on a query path optimization mechanism using the preset index structure, and querying data in the preset storage space based on the query path; caching data in the preset storage space that meets preset caching conditions using an intelligent caching mechanism based on the preset index structure, so as to perform access operations on the cached data; the preset caching condition is that the number of historical accesses is greater than a preset access threshold. In one specific implementation, the query path can be dynamically adjusted according to the file's access history and the access frequency of extended attributes. For frequently accessed extended attributes, the system will prioritize using shorter query paths for retrieval, reducing unnecessary I / O operations. In the case of multi-level indexes, the system can intelligently select the optimal query path, avoiding unnecessary hierarchical traversal, thereby further improving query efficiency.

[0056] In this embodiment, to further optimize storage space utilization efficiency, the present invention introduces sparse storage technology during the storage process. Specifically, storing the data to be stored into a preset storage space can include: for data whose size meets preset storage conditions, storing the data to be stored into the preset storage space using sparse storage technology; for contiguous data to be stored, storing the data to be stored into the preset storage space using a data block merging mechanism. That is, for extremely small extended attributes (such as file markers, status bits, etc.), this embodiment avoids occupying too much space by using sparse storage. For contiguous small blocks of data, the present invention further optimizes the storage layout and reduces storage fragmentation through a data block merging mechanism (similar to the write merging algorithm of SSDs).

[0057] It is worth noting that the performance of extended attribute queries and accesses is closely related to disk I / O operations; frequent disk read / write operations can significantly degrade system performance. Therefore, this embodiment reduces the number of disk accesses per query by supporting batch query functionality. When the file system needs to query multiple extended attributes simultaneously, this invention constructs a one-time batch query request, merging all queries into a single disk access operation, thereby reducing the number of disk accesses and lowering latency. To address potential disk I / O waiting issues during queries, this embodiment introduces read-ahead and prefetch mechanisms. When the system issues a query request, the read-ahead mechanism loads relevant data blocks from the disk into memory in advance, avoiding waiting during the query process. The prefetch mechanism, based on the user's access pattern, preloads extended attribute data blocks expected to be accessed, thereby reducing disk I / O operations during queries. In high-concurrency access scenarios, multiple query requests may be initiated simultaneously. This embodiment designs an I / O priority scheduling mechanism to dynamically adjust the disk access order based on the urgency of different query requests and the importance of the data. For example, for system management-related extended attributes, the system prioritizes their query requests; while for low-priority user-defined extended attributes, the system can delay their access, reducing latency for high-priority tasks. This embodiment allows multiple query requests to be executed simultaneously and distributes query tasks across multiple processing cores for parallel execution through a multi-threaded mechanism. This significantly improves the throughput of extended attribute queries, especially in large-scale data storage and high-concurrency scenarios, fully utilizing multi-core CPU computing power and shortening query response time. When performing complex query operations, this embodiment supports parallel traversal of the B-tree index. By distributing different subtrees of the B-tree index to multiple threads for simultaneous processing, the speed of index queries can be greatly improved. Furthermore, during query result sorting and aggregation, the system utilizes multi-threading to process the results in parallel, thereby accelerating the generation of query return results.

[0058] As can be seen from the above, the attribute-type-based hierarchical encryption method adopted in this application effectively protects the security of sensitive data by applying encryption algorithms of different strengths to different types of extended attribute data, avoiding performance overhead and storage bloat caused by encryption operations. The encryption strength of attribute data can be dynamically adjusted according to its importance and sensitivity, thereby reducing unnecessary consumption of computing resources while ensuring data security. The hierarchical encryption mechanism ensures that extended attributes of different attribute types use appropriate encryption methods according to needs, achieving a relatively ideal balance between system performance and data protection. In addition, while performing encrypted storage, the efficiency of data access is maintained, reducing the performance impact of encryption, especially in high-concurrency access scenarios, it can still guarantee the query and access speed of encrypted extended attributes. By introducing dynamic compression technology, appropriate compression algorithms are selected according to the characteristics of extended attribute data, significantly reducing the occupation of storage space. The compression strategy can be dynamically adjusted according to factors such as attribute type, data content, and access frequency, optimizing the utilization of storage space. Especially in large-scale data storage environments, it can effectively reduce the demand for storage media, reduce hardware investment and operating costs. By combining data block and compression technologies, efficient use of storage space is ensured without affecting the access performance of extended attribute data. By introducing a B-tree index structure, optimizing query paths, employing intelligent caching mechanisms, and utilizing parallel query technology, the query and access performance of extended attributes is significantly improved, effectively reducing disk I / O operations and increasing data retrieval speed. Furthermore, this embodiment supports parallel processing of multiple extended attributes through parallel query technology, fully utilizing the computing resources of multi-core processors, thereby further enhancing query throughput and processing capabilities. Particularly in high-concurrency environments, it significantly improves system query efficiency. In summary, this embodiment significantly improves the efficiency of extended attribute storage, data security, and query performance through dynamic compression, layered encryption, optimized storage structure, and enhanced query performance.

[0059] See Figure 2 As shown in the figure, this application discloses a data storage device based on extended attributes, including:

[0060] The data encryption module 11 is used to perform layered encryption processing on the extended attribute data based on the attribute type of the extended attribute data to obtain the corresponding encrypted extended attribute data; the attribute type includes user-defined extended attributes, system extended attributes, and security attributes;

[0061] The data compression module 12 is used to determine the corresponding data compression algorithm based on the data type of the encrypted extended attribute data, and to dynamically compress the encrypted extended attribute data based on the data compression algorithm to obtain the data to be stored; the data type includes text data, binary data and structured data; the data to be stored includes attribute name, the size of the attribute value before and after compression, and data compression algorithm information;

[0062] The data storage module 13 is used to store the data to be stored in a preset storage space so that when an access and query request for the data in the preset storage space is received, the access and query operations in the preset storage space are performed using a preset index structure.

[0063] In some specific embodiments, the data encryption module 11 may specifically include:

[0064] The target encryption algorithm determination unit is used to determine the target encryption algorithm from the preset encryption algorithms based on the attribute type of the extended attribute data, and to generate the corresponding encryption key based on the attribute type using the preset key management system; the preset encryption algorithms include symmetric encryption algorithms, asymmetric encryption algorithms, and hash encryption algorithms;

[0065] The data encryption unit is used to encrypt the extended attribute data using the target encryption algorithm and the encryption key to obtain encrypted extended attribute data.

[0066] In some specific embodiments, the data storage module 13 may specifically include:

[0067] The query path optimization unit is used to determine the query path based on the query path optimization mechanism using a preset index structure, and to query the data in the preset storage space based on the query path;

[0068] The data caching unit is used to cache data in the preset storage space that meets the preset caching conditions based on a preset index structure and an intelligent caching mechanism, so as to perform access operations on the cached data; the preset caching conditions are that the number of historical accesses is greater than a preset access number threshold.

[0069] The first data storage unit is used to store the data to be stored into a preset storage space using sparse storage technology, provided that the data size meets the preset storage conditions.

[0070] The second data storage unit is used to store the continuously stored data into a preset storage space using a data block merging mechanism.

[0071] In some specific embodiments, the data storage device based on extended attributes may further include:

[0072] A data compression algorithm adjustment unit is used to adjust the data compression algorithm based on the data access frequency, data size, and current load of the encrypted extended attribute data.

[0073] The data management unit is used to create an index corresponding to the data to be stored using a preset index structure, and to manage the data in the preset storage space based on the index; the index includes the name, attribute value type, attribute value length, and storage location of the data to be stored;

[0074] The data decryption unit is used to verify the data integrity of the encrypted extended attribute data using a preset message verification code during the data decryption process.

[0075] Furthermore, embodiments of this application also disclose an electronic device, Figure 3 This is a structural diagram of an electronic device 20 according to an exemplary embodiment. The content of the diagram should not be construed as limiting the scope of this application. Specifically, the electronic device 20 may include: at least one processor 21, at least one memory 22, a power supply 23, a communication interface 24, an input / output interface 25, and a communication bus 26. The memory 22 stores a computer program, which is loaded and executed by the processor 21 to implement the relevant steps in the extended attribute-based data storage method disclosed in any of the foregoing embodiments. Furthermore, the electronic device 20 in this embodiment may specifically be an electronic computer.

[0076] In this embodiment, the power supply 23 is used to provide operating voltage for each hardware device on the electronic device 20; the communication interface 24 can create a data transmission channel between the electronic device 20 and external devices, and the communication protocol it follows can be any communication protocol applicable to the technical solution of this application, and is not specifically limited here; the input / output interface 25 is used to acquire external input data or output data to the outside world, and its specific interface type can be selected according to specific application needs, and is not specifically limited here.

[0077] In addition, the memory 22, as a carrier for resource storage, can be a read-only memory, random access memory, disk or optical disk, etc. The resources stored thereon can include operating system 221, computer program 222, etc., and the storage method can be temporary storage or permanent storage.

[0078] The operating system 221 is used to manage and control the various hardware devices on the electronic device 20 and the computer program 222, which may be Windows Server, Netware, Unix, Linux, etc. In addition to including a computer program capable of performing the extended attribute-based data storage method executed by the electronic device 20 as disclosed in any of the foregoing embodiments, the computer program 222 may further include a computer program capable of performing other specific tasks.

[0079] Furthermore, this application also discloses a computer-readable storage medium for storing a computer program; wherein, when the computer program is executed by a processor, it implements the aforementioned data storage method based on extended attributes. Specific steps of this method can be found in the corresponding content disclosed in the foregoing embodiments, and will not be repeated here.

[0080] The various embodiments in this specification are described in a progressive manner, with each embodiment focusing on its differences from other embodiments. Similar or identical parts between embodiments can be referred to interchangeably. For the apparatus disclosed in the embodiments, since it corresponds to the method disclosed in the embodiments, the description is relatively simple; relevant parts can be referred to in the method section.

[0081] Those skilled in the art will further recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of both. To clearly illustrate the interchangeability of hardware and software, the components and steps of the various examples have been generally described in terms of functionality in the foregoing description. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.

[0082] The steps of the methods or algorithms described in conjunction with the embodiments disclosed herein can be implemented directly by hardware, a software module executed by a processor, or a combination of both. The software module can be located in random access memory (RAM), main memory, read-only memory (ROM), electrically programmable ROM, electrically erasable programmable ROM, registers, hard disk, removable disk, CD-ROM, or any other form of storage medium known in the art.

[0083] Finally, it should be noted that in this document, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.

[0084] The technical solutions provided in this application have been described in detail above. Specific examples have been used to illustrate the principles and implementation methods of this application. The descriptions of the above embodiments are only for the purpose of helping to understand the methods and core ideas of this application. At the same time, for those skilled in the art, there will be changes in the specific implementation methods and application scope based on the ideas of this application. Therefore, the content of this specification should not be construed as a limitation of this application.

Claims

1. A data storage method based on extended attributes, characterized in that, include: The extended attribute data is subjected to hierarchical encryption based on the attribute type of the extended attribute data to obtain the corresponding encrypted extended attribute data. The attribute types include user-defined extended attributes, system extended attributes, and security attributes; Based on the data type of the encrypted extended attribute data, a corresponding data compression algorithm is determined, and the encrypted extended attribute data is dynamically compressed based on the data compression algorithm to obtain the data to be stored; the data type includes text data, binary data, and structured data; the data to be stored includes attribute name, the size of the attribute value before and after compression, and data compression algorithm information; The data to be stored is stored in a preset storage space so that when an access and query request for the data in the preset storage space is received, access and query operations are performed on the data in the preset storage space using a preset index structure.

2. The data storage method based on extended attributes according to claim 1, characterized in that, The method of performing layered encryption on the extended attribute data based on the attribute type to obtain the corresponding encrypted extended attribute data includes: The target encryption algorithm is determined from the preset encryption algorithms based on the attribute type of the extended attribute data, and the corresponding encryption key is generated by the preset key management system based on the attribute type; the preset encryption algorithms include symmetric encryption algorithms, asymmetric encryption algorithms, and hash encryption algorithms; The extended attribute data is encrypted using the target encryption algorithm and the encryption key to obtain encrypted extended attribute data.

3. The data storage method based on extended attributes according to claim 1, characterized in that, After determining the corresponding data compression algorithm based on the data type of the encrypted extended attribute data, the method further includes: The data compression algorithm is adjusted based on the data access frequency, data size, and current load of the encrypted extended attribute data.

4. The data storage method based on extended attributes according to claim 1, characterized in that, After storing the data to be stored in the preset storage space, the method further includes: An index corresponding to the data to be stored is created using a preset index structure, and the data in the preset storage space is managed based on the index; the index includes the name, attribute value type, attribute value length, and storage location of the data to be stored.

5. The data storage method based on extended attributes according to claim 1, characterized in that, The method of using a preset index structure to perform access and query operations on data in the preset storage space includes: The query path is determined using a preset index structure and a query path optimization mechanism, and the data in the preset storage space is queried based on the query path. The data in the preset storage space that meets the preset caching conditions is cached using a preset index structure and an intelligent caching mechanism, so that access operations can be performed on the cached data; the preset caching conditions are that the number of historical accesses is greater than a preset access number threshold.

6. The data storage method based on extended attributes according to claim 1, characterized in that, The step of storing the data to be stored into a preset storage space includes: For data to be stored that meets the preset storage conditions, sparse storage technology is used to store the data to be stored in the preset storage space; For continuously stored data to be stored, a data block merging mechanism is used to store the data to be stored into a preset storage space.

7. The data storage method based on extended attributes according to any one of claims 1 to 6, characterized in that, Also includes: During the data decryption process, a preset message verification code is used to verify the data integrity of the encrypted extended attribute data.

8. A data storage device based on extended attributes, characterized in that, include: The data encryption module is used to perform layered encryption processing on the extended attribute data based on the attribute type of the extended attribute data to obtain the corresponding encrypted extended attribute data; the attribute type includes user-defined extended attributes, system extended attributes, and security attributes; The data compression module is used to determine the corresponding data compression algorithm based on the data type of the encrypted extended attribute data, and to dynamically compress the encrypted extended attribute data based on the data compression algorithm to obtain data to be stored; the data type includes text data, binary data, and structured data; the data to be stored includes attribute name, the size of the attribute value before and after compression, and data compression algorithm information; The data storage module is used to store the data to be stored in a preset storage space so that when an access and query request for the data in the preset storage space is received, the module can use a preset index structure to perform access and query operations on the data in the preset storage space.

9. An electronic device, characterized in that, include: Memory, used to store computer programs; A processor for executing the computer program to implement the data storage method based on extended attributes as described in any one of claims 1 to 7.

10. A computer-readable storage medium, characterized in that, Used to store computer programs, wherein the computer programs, when executed by a processor, implement the data storage method based on extended attributes as described in any one of claims 1 to 7.

Citation Information

Patent Citations

  • Encrypted file access method and device, equipment and storage medium

    CN119670130A

  • Dynamic compression method and device for unstructured encrypted data, medium and product

    CN119690352A

  • Encryption method and device for unstructured data, storage medium and program product

    CN119691778A

  • Convergent Intelligence Fabric for Multi-Domain Orchestration of Distributed Agents with Hierarchical Memory Architecture and Quantum-Resistant Trust Mechanisms

    US20250259085A1