A cloud storage-based archive management method and system
By constructing a dynamic authorization mechanism in emergency situations, real-time collection and evaluation of access data, and generation of dynamic access keys and behavior audit chains, the problems of delayed access and broken decryption chains in emergency management archive systems have been solved. This has enabled rapid response and security compliance in archive access, and improved the system's controllability and traceability.
Patent Information
- Application Number
- CN202511139433.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-14
- Publication Date
- 2026-02-10
- Estimated Expiration
- 2045-08-14
AI Technical Summary
The existing emergency management record system lacks a dynamic authorization mechanism in emergency situations, resulting in delayed response to permission calls, opaque call paths, and broken decryption chains. This makes it difficult to achieve rapid response and security compliance, and also lacks traceability, affecting the timeliness of instruction implementation and the traceability of responsibility.
By collecting emergency status and terminal access data in real time, a data set for file retrieval is constructed, an access fingerprint consistency score and an emergency behavior response index are obtained, a comprehensive risk score is generated, dynamic access key authorization verification is performed, and an authorization trajectory sub-chain and decryption behavior restriction function are constructed to form a complete data audit chain, enabling full-process traceability recording and compliance assessment of access behavior.
It achieves full-process controllability and traceability of file access behavior, improves the security and rapid response capability of file retrieval operations in emergency situations, dynamically identifies risk characteristics in access behavior, solves the problem of non-audit authorization in traditional systems, and enhances the flexibility and security resilience of access strategies.
Smart Images

Figure CN121037029B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of archives management technology, specifically to an archives management method and system based on cloud storage. Background Technology
[0002] Against the backdrop of the increasing cloudification of digital government and emergency response systems, cloud-based archive management systems are becoming the main technical support path for the retrieval and access control of government archives. Especially in the emergency management system, instruction-type archives not only involve requirements for retrieval speed, but also require a series of controllable and traceable mechanisms such as identity verification, access records, and behavior tracking. As the requirements for real-time and compliance of data retrieval in the emergency response process increase, the archive system urgently needs to build an archive management model that can support efficient retrieval and achieve accurate authorization and complete auditing in a "cloud-based multi-terminal access" environment.
[0003] In most current emergency management archive systems, access permissions rely heavily on static configuration, which involves pre-setting access identity groups and fixed decryption paths during system deployment. This lacks a dynamic authorization mechanism based on operator behavior, terminal status, and response time. While this approach is simple to configure and easy to manage, it can lead to problems such as delayed access response, opaque access paths, and broken decryption chains in scenarios requiring rapid access to classified information during emergencies. This results in critical archives being difficult to access in a timely manner due to delayed access review processes. Furthermore, some access behaviors lack traceability, creating security and compliance risks and severely impacting the timeliness of instruction implementation and accountability.
[0004] The core issue causing these problems lies in the fact that traditional systems have failed to build an identification and triggering mechanism specifically for the timing and operational behaviors unique to "emergency call" scenarios. The authorization verification process is difficult to adapt to cross-terminal, multi-identity, and multi-node access paths. At the same time, the operation behavior logs do not form a linkage verification chain with key indicators such as identity credentials, terminal location, and call time characteristics. This results in the system lacking dynamic behavior judgment capabilities under high-pressure access conditions. Once the call operation goes out of control or the authorization information is tampered with, the system will find it difficult to trace back the true access chain. This not only poses high-risk risks such as password leakage and misuse of instructions, but also blocks the path for post-event review and responsibility determination, seriously affecting the credibility and compliance transparency of the entire emergency system's instruction execution. Summary of the Invention
[0005] In view of the shortcomings of the prior art, the present invention provides a cloud storage-based file management method and system, which solves the problems mentioned in the background art.
[0006] To achieve the above objectives, the present invention provides the following technical solution: a cloud storage-based file management method, comprising the following steps:
[0007] S1. Collect emergency status-related data and terminal access-related data in real time, and construct a data set S for file retrieval;
[0008] S2. Based on the relevant data set S retrieved from the file, feature extraction is performed to obtain the access fingerprint consistency score Sf, and the structural signature value Hs of the target file is constructed.
[0009] S3. Based on the data set S related to file retrieval, obtain the emergency behavior response index Et, and combine it with the access fingerprint consistency score Sf to generate a comprehensive risk score Zh. Perform file retrieval request authorization verification, construct a dynamic access key K, record authorization verification related data, and construct an authorization trajectory subchain.
[0010] S4. Based on the dynamic access key K, perform the decryption operation and collect decryption behavior data in real time to construct a decryption behavior restriction function. Assess the compliance of decryption operations, collect decryption behavior data from each decryption node, construct a data decryption subchain, and combine it with the authorization trajectory subchain to obtain a complete data audit chain;
[0011] S5. Based on the complete data audit chain, analyze the degree of abnormality of file access behavior to obtain an abnormal audit score Re and assess the risk level of file access behavior.
[0012] Preferably, step S1 specifically includes:
[0013] S11. By monitoring the scheduling bus through the cloud storage system's status management interface, upon receiving a file retrieval request, record emergency status-related data, including the system emergency level. and authorized access window width ;
[0014] S12. Call the terminal operating system API interface to obtain the visitor's terminal access-related data in real time. The terminal access-related data includes the feature vector of the terminal access device. Access command path depth Terminal geographical location drift distance Matching degree with user behavior template ;
[0015] Feature vector of terminal access device It includes various hardware identifiers of the terminal access device, including MAC address, motherboard serial number, CPU serial number, and hard disk ID;
[0016] Access command path depth This refers to the number of operation command paths involved in a user initiating a file retrieval request in the terminal;
[0017] Terminal geographic location drift distance This refers to the distance difference between the physical location of the terminal device and the physical location recorded in the historical trusted access record when the file retrieval request is issued, which is used to assess whether the visitor has geographically shifted.
[0018] User behavior template matching degree This refers to the similarity between the user's action path during the process of issuing a file retrieval request and historically trusted action paths.
[0019] S13. Perform dimensionless processing on emergency-related data and terminal access-related data, unify different physical dimension parameters, and construct a data set S for file retrieval based on the dimensionless emergency-related data and terminal access-related data.
[0020] Preferably, step S2 specifically includes:
[0021] S21. Based on the terminal access-related data retrieved from the relevant data set S, analyze the rationality and credibility of the visitor's access behavior, and obtain the access fingerprint consistency score Sf. The specific method for obtaining the access fingerprint consistency score Sf is as follows: ;
[0022] In the formula, Indicates the path depth of the access command. Indicates the degree of matching between user behavior and template. Indicates the distance the terminal's geographical location has drifted. Indicates the similarity between terminal devices. The feature vector representing the terminal access device used by the current visitor. The i-th hardware identifier within, Feature vector representing historical trusted terminal access devices The i-th hardware identifier within, Indicates an indicator function, if = ,but If it is 1, ≠ ,but If n is 0, then n represents the total number of hardware identifiers in the feature vector of the terminal access device.
[0023] Preferably, step S2 further includes,
[0024] S22. Based on the cloud storage system, locate the target file requested by the visitor, and extract the content summary and structured metadata from the target file. Use a hash function to hash and encrypt the content summary and structured metadata of the target file to obtain the structured signature value Hs of the target file. The content summary includes the beginning of the text, tag content, and the closing approval record. The structured metadata includes the file creation time, the account ID of the modifier, the responsible unit, and the IP address of the terminal of the last operation.
[0025] Preferably, step S3 specifically includes:
[0026] S31. Based on the relevant data set S retrieved from the archives, analyze the visitor's situation when the system is at its current emergency level. The stability of visitor behavior is assessed, and an emergency response index Et is calculated. The specific method for obtaining the emergency response index Et is as follows: ;
[0027] In the formula, Indicates the width of the authorized access window. Indicates the system emergency level. Indicates the distance the terminal's geographical location has drifted. This represents the maximum authorized geographic range tolerance allowed by the system, sin represents the sine function, and ln represents the logarithm with the irrational number e as the base. Pi is a constant. ∈{0,1}.
[0028] Preferably, step S3 further includes,
[0029] S32. Based on the visitor fingerprint consistency score Sf and the emergency behavior response index Et, analyze the changes in the visitor's behavioral response in the current visit state to obtain a comprehensive risk score Zh. The specific method for obtaining the comprehensive risk score Zh is as follows: ;
[0030] In the formula, Indicates the system alert level. denoted by , log represents the logarithm to the natural constant 10;
[0031] A preset system authorization threshold ZHyz is used. The comprehensive risk score Zh and the system authorization threshold ZHyz are compared and analyzed to verify the authorization of file retrieval requests. The specific evaluation content is as follows:
[0032] When the comprehensive risk score Zh is greater than or equal to the system authorization threshold ZHyz, i.e. Zh≥ZHyz, the accessor's file retrieval request is deemed authorized, the file structure signature Hs is immediately extracted, and the file is decrypted.
[0033] When the comprehensive risk score Zh is less than the system authorization threshold ZHyz, i.e. Zh < ZHyz, it is determined that the visitor's file retrieval request is not authorized. At this time, an alarm is immediately issued, an abnormal behavior audit record is automatically generated, and the system administrator is notified to intervene manually.
[0034] S33. When a visitor's file retrieval request is authorized, based on the target file's structural signature value Hs and combined with the comprehensive risk score Zh, a hash algorithm is used to encrypt and obtain a dynamic access key K. The specific method for obtaining the dynamic access key K is as follows: ;
[0035] In the formula, This represents the structural signature value of the target file. Represents a hash function. This represents the pseudo-time perturbation factor. Pi constant This represents the XOR operator.
[0036] S34. Record authorization verification-related data in real time during the file retrieval request authorization verification process to construct an authorization trajectory subchain. The authorization trajectory subchain includes the access fingerprint consistency score Sf, the emergency behavior response index Et, the comprehensive risk score Zh, and the authorization pass timestamp.
[0037] Preferably, step S4 specifically includes:
[0038] S41. Based on the generated dynamic access key K, locate the structured data block in the structured block directory of the cloud storage system using the dynamic access key K, and record the structured data block number Index. Here, the structured block directory refers to the numbered directory constructed by using a segmented encryption storage method to divide the target file into several structured data blocks for data storage and summarizing the numbers of each structured data block when storing the target file.
[0039] S42. Define each structured data block as a decryption node, and collect the decryption behavior data of each decryption node in real time during the decryption operation. The decryption behavior data includes the decryption time. and data read volume ;
[0040] Decryption time The total time for decryption operations at the decryption node is collected by the system access controller.
[0041] Data read volume This refers to the total amount of archive data read, which is obtained through USN log identification;
[0042] S43. Based on the decryption behavior data, construct a decryption behavior constraint function. And for each decryption node, the decryption time is calculated. Timeout and data read volume The compliance of decryption operations at decryption nodes is jointly judged based on two dimensions: whether it exceeds the limit and whether it exceeds the limit. The decryption behavior restriction function is used as an example. Obtain it using the following formula: ;
[0043] In the formula, This indicates the maximum decryption time threshold. This represents the maximum read range threshold, i.e., the maximum amount of data allowed to be decrypted in a single authorization. In addition to All other cases;
[0044] like If the value is 1, the decryption operation is deemed compliant, and the system allows the decryption operation to be performed. At this time, the decryption node is marked as a normal node, and the decrypted plaintext data is automatically returned.
[0045] like If the value is 0, the decryption operation is deemed non-compliant, the system refuses to execute the decryption operation, the decryption node is marked as an abnormal node, and the decryption operation is stopped.
[0046] Preferably, step S4 further includes,
[0047] S44. Collect the decryption behavior data from each decryption node and encapsulate it in a structured manner to construct a data decryption subchain. The data decryption subchain includes the structured data block number (Index) and data read volume of each decryption node. Decryption time Decryption behavior restriction function Numerical values and decryption node markers;
[0048] S45. Record the end time of the decryption operation of the last decryption node as the file access end time. At this point, the file decryption operation terminates, and the constructed authorized trajectory subchain, data decryption subchain, and file access termination time point are linked together. Perform unified structural encapsulation to obtain a complete data audit chain.
[0049] Preferably, step S5 specifically includes:
[0050] S51. Based on the complete data audit chain, analyze the degree of anomaly in the overall file access process to obtain an anomaly audit score Re. The specific method for obtaining the anomaly audit score Re is as follows: ;
[0051] In the formula, Indicates the point in time when access to the archive ended. Indicates the start time of file access. Indicates the width of the authorized access window. Indicates the function that restricts decryption behavior. The total number of decryption nodes is 1. Indicates the total number of decryption nodes;
[0052] S52. Preset anomaly audit threshold Reyz, and compare and analyze the anomaly audit score Re and the anomaly audit threshold Reyz to assess the risk level of file access behavior. The specific assessment process is as follows:
[0053] If the abnormal audit score Re is less than the abnormal audit threshold Reyz, the file access behavior is determined to be of the first risk level. At this time, no action is required, and the file access behavior is archived into the file access log.
[0054] If the abnormal audit score Re is greater than or equal to the abnormal audit threshold Reyz, it indicates that the file access behavior is at the second risk level. At this time, the risk alarm mechanism is triggered, the access terminal of the visitor is automatically marked, and an abnormal behavior report is generated. At the same time, the abnormal behavior report is sent to the system administrator to generate response and handling strategies, including terminal blocking and behavior authentication restart.
[0055] Preferably, a cloud storage-based archive management system includes a data acquisition module, a data analysis module, an authorization verification module, an archive decryption module, and an anomaly assessment module;
[0056] The data acquisition module is used to collect emergency-related data and terminal access-related data in real time, and to build a data set S for file retrieval.
[0057] The data analysis module retrieves relevant data set S based on the file, performs feature extraction, obtains the access fingerprint consistency score Sf, and constructs the structural signature value Hs of the target file;
[0058] The authorization verification module is used to obtain the emergency behavior response index Et based on the file retrieval related data set S, and generate a comprehensive risk score Zh by combining the access fingerprint consistency score Sf, to perform file retrieval request authorization verification, construct a dynamic access key K, record authorization verification related data, and construct an authorization trajectory subchain.
[0059] The file decryption module is used to perform decryption operations based on the dynamic access key K, and to collect decryption behavior data in real time to construct decryption behavior restriction functions. Assess the compliance of decryption operations, collect decryption behavior data from each decryption node, construct a data decryption subchain, and combine it with the authorization trajectory subchain to obtain a complete data audit chain;
[0060] The anomaly assessment module is used to analyze the degree of anomaly in file access behavior based on the complete data audit chain, in order to obtain an anomaly audit score (Re) and assess the risk level of the file access behavior.
[0061] This invention provides a cloud storage-based file management method and system, which has the following beneficial effects:
[0062] (1) By constructing an authorization trajectory sub-chain and a data decryption sub-chain for file access, and forming a complete data audit chain after the access is completed, the structured encapsulation and traceable recording of the entire access process are realized. Compared with the existing file management system, which only makes access judgment based on whether the access request is authorized, this invention not only records the risk scoring process before authorization, such as the access fingerprint consistency score Sf and the comprehensive risk score Zh, but also covers the behavior of each structured node in the decryption operation, such as the decryption time and data reading volume. Thus, a closed-loop access link audit mechanism of "authorization → decryption → termination" is formed, which can effectively deal with the problem of "only authorization, no audit" in the traditional system, improve the controllability of the entire file extraction operation, and is particularly suitable for the management scenarios of high-risk files such as classified emergency documents and emergency response documents.
[0063] (2) By decrypting the behavior restriction function The system incorporates a quantifiable behavior scoring system based on the anomaly audit score Re, used to assess the compliance risk level of file access behavior. When the score is below the preset anomaly audit threshold Reyz, the system classifies the file access behavior as the first risk level and allows for direct archiving. Conversely, when the score is above the preset anomaly audit threshold Reyz, the system immediately triggers an automatic blocking mechanism, generates an anomaly behavior report, and links with the security audit process. This enables real-time tiered response to access behavior. Through this mechanism, the system can dynamically identify risk characteristics such as operation delays, decryption failures, and behavior path deviations in access behavior, and control subsequent operation permissions accordingly. This solves the "authorization equals permission" defect caused by the difficulty in quantifying and providing early warnings for access behavior, effectively improving the flexibility and security resilience of access policy execution.
[0064] (3) By jointly calculating the comprehensive risk score Zh by access fingerprint consistency score Sf and emergency behavior response index Et, and completing authorization verification and dynamic access key K generation based on the comprehensive risk score Zh, the response delay of multi-level approval and manual operation path in traditional emergency access is effectively reduced. At the same time, the present invention uses structured data blocks as decryption nodes and sets decryption behavior restriction functions for each node. This design enables segmented verification and parallel control of decryption operations, effectively mitigating the problems of "over-reading" and "timeout" in the decryption process. It enhances the system's ability to quickly retrieve data and improves decryption efficiency in emergency situations, while ensuring the verifiability and trustworthiness of the data reading process. This design also addresses the structural deficiencies of existing technologies in balancing rapid response and access compliance. Attached Figure Description
[0065] Figure 1 This is a schematic diagram of a cloud storage-based file management method according to the present invention;
[0066] Figure 2 This is a block diagram of a cloud storage-based archive management system according to the present invention;
[0067] Figure 3 This is a data frame diagram of the relevant data set S retrieved from the archives of this invention;
[0068] Figure 4 This is a schematic diagram of the authorization verification process for requesting access to the archives of this invention. Detailed Implementation
[0069] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0070] Example 1:
[0071] Please see Figure 1 This invention provides a cloud storage-based file management method, comprising the following steps:
[0072] S1. Collect emergency status-related data and terminal access-related data in real time, and construct a data set S for file retrieval;
[0073] S2. Based on the relevant data set S retrieved from the file, feature extraction is performed to obtain the access fingerprint consistency score Sf, and the structural signature value Hs of the target file is constructed.
[0074] S3. Based on the data set S related to file retrieval, obtain the emergency behavior response index Et, and combine it with the access fingerprint consistency score Sf to generate a comprehensive risk score Zh. Perform file retrieval request authorization verification, construct a dynamic access key K, record authorization verification related data, and construct an authorization trajectory subchain.
[0075] S4. Based on the dynamic access key K, perform the decryption operation and collect decryption behavior data in real time to construct a decryption behavior restriction function. Assess the compliance of decryption operations, collect decryption behavior data from each decryption node, construct a data decryption subchain, and combine it with the authorization trajectory subchain to obtain a complete data audit chain;
[0076] S5. Based on the complete data audit chain, analyze the degree of abnormality of file access behavior to obtain an abnormal audit score Re and assess the risk level of file access behavior.
[0077] In this embodiment, by collecting data such as system emergency level, terminal location, and device characteristics when a file retrieval request is initiated, dynamic acquisition of the access behavior context is achieved, enhancing the behavior perception capability of the retrieval process. Furthermore, an access fingerprint consistency score Sf is constructed, enabling the system to comprehensively evaluate whether the access behavior conforms to historical trusted behavior patterns, improving the access control's ability to judge user authenticity, and avoiding the risks of identity impersonation and illegal proxy behavior. In addition, by introducing the emergency behavior response index Et and the comprehensive risk score Zh, quantitative judgment of the access behavior risk level is achieved, thereby supporting the refusal of authorization or the implementation of stricter hierarchical access control in high-risk states. Moreover, the authorization trajectory sub-chain generated in the authorization stage is merged with the data decryption sub-chain collected in the decryption stage to construct a complete data audit chain, realizing traceable and retrospective recording of the entire access process, and improving the system's audit capabilities.
[0078] Example 2:
[0079] Please refer to Figure 1 and Figure 3 Specifically: S1 includes the following steps:
[0080] S11. By monitoring the scheduling bus through the cloud storage system's status management interface, upon receiving a file retrieval request, record emergency status-related data, including the system emergency level. and authorized access window width ;
[0081] System Emergency Level This refers to the current emergency response level of the cloud storage system. It is determined by statistically analyzing the number of access requests for target files over a period of time and comparing the number of access requests with the set emergency response level judgment threshold, thereby identifying whether the current file access request occurs in a normal state, a warning state, or an emergency state.
[0082] Authorized access window width This refers to the maximum time interval during which the file retrieval request is allowed to continue under the system's authorization policy, which is identified and obtained through the access control policy library.
[0083] S12. Call the terminal operating system API interface to obtain the visitor's terminal access-related data in real time. The terminal access-related data includes the feature vector of the terminal access device. Access command path depth Terminal geographical location drift distance Matching degree with user behavior template ;
[0084] Feature vector of terminal access device This includes various hardware identifiers of the terminal access device, including the MAC address, motherboard serial number, CPU serial number, and hard drive ID, as well as the feature vector of the terminal access device. Obtained by calling the hardware identifier interface module of the terminal operating system;
[0085] Access command path depth This refers to the number of operation command paths involved in a user initiating a file retrieval request in the terminal. It reflects the complexity of the operation path. For example, "Main Menu → Submenu → Function Page" indicates an access command path depth of 3. Access it via the log menu;
[0086] Terminal geographic location drift distance This refers to the distance difference between the physical location of the terminal device when the file retrieval request is issued and the physical location recorded in the historical trusted access record. It is used to assess whether the visitor has geographically shifted and the distance of the terminal's geographical location drift. The physical location of the terminal device is determined by GPS sensors, and the Euclidean distance is calculated between the location and the physical location recorded in the historical trusted access records.
[0087] User behavior template matching degree This refers to the similarity between the user's action path during the file retrieval request process and historically trusted action paths. The action path includes system interface click sequences, command-line operations or instruction call chains, API call order, and control behaviors. User behavior template matching degree is also considered. It is obtained by calculating the cosine similarity between the user's action path and historical trusted action paths;
[0088] S13. Perform dimensionless processing on emergency-related data and terminal access-related data, unify different physical dimension parameters, and construct a data set S for file retrieval based on the dimensionless emergency-related data and terminal access-related data.
[0089] In this embodiment, by simultaneously collecting the system's emergency level and authorized access window width in real time upon receiving a file retrieval request, the response status of the access behavior is effectively identified. Combined with the hardware indicators of the terminal access device, path depth, geographical location changes, and behavioral template similarity, multi-dimensional dynamic perception of the visitor's operation behavior is achieved, constructing a complete and highly differentiated file retrieval data profile. Compared with the existing call mechanism that relies on static configuration, this embodiment can dynamically adapt to changes in access behavior under emergency scenarios, improve the accuracy of identifying illegal access, unauthorized operations, and behavioral deviations, effectively solve the problems of opaque retrieval paths and difficulty in tracing abnormal operations in traditional solutions, significantly enhance the security and controllability of file access management under emergency situations, and provide reliable data support for subsequent risk assessment and audit tracing.
[0090] Example 3:
[0091] Please refer to Figure 1 , Figure 3 and Figure 4 Specifically: The specific steps of S2 include,
[0092] S21. Based on the terminal access-related data retrieved from the relevant data set S, analyze the rationality and credibility of the visitor's access behavior, and obtain the access fingerprint consistency score Sf. The specific method for obtaining the access fingerprint consistency score Sf is as follows: ;
[0093] In the formula, Indicates the path depth of the access command. Indicates the degree of matching between user behavior and template. Indicates the distance the terminal's geographical location has drifted. Indicates the similarity between terminal devices. The feature vector representing the terminal access device used by the current visitor. The i-th hardware identifier within, Feature vector representing historical trusted terminal access devices The i-th hardware identifier within, Indicates an indicator function, if = ,but If it is 1, ≠ ,but If n is 0, then n represents the total number of hardware identifiers in the feature vector of the terminal access device.
[0094] The derivation logic and physical meaning of the formula: This represents a positive behavior enhancement factor, where, Indicates the rationality of path behavior User behavior consistency is calculated using a parallel enhancement factor construction method, which forms positive supporting factors for behavioral credibility. The core logic of the product approach is as follows:
[0095] Only when both path behavior and terminal behavior are reasonable can a high access fingerprint consistency score Sf be given.
[0096] The similarity between terminal devices is represented by the feature vector of the terminal device used by the visitor. Feature vectors of historical trusted terminal access devices The system compares each hardware identifier to determine if they match. If they match, a score of 1 is added. Each hardware identifier is compared, and the final score is calculated by summing and averaging the results to obtain the terminal device matching similarity. And match terminal devices by similarity With the previous Combining them to form a "reliable path" Reliable operation The complete access consistency framework for "trusted devices" still uses multiplication, with the following logic:
[0097] If any one item is 0, the total score will be significantly reduced, ensuring that the credibility judgment "prevents missed detections";
[0098] The overall negative perturbation suppression factor has the important function of suppressing the interference of location perturbations on access consistency scores and suppressing the risk of inflated scores caused by suspicious spatial movement behavior. This indicates a nonlinear enhancement of position disturbance, amplifying the effect of high displacements, i.e., a heavier penalty for position drift. The square root is used to prevent the value under the square root from being 0, which is a fundamental data theory. The square root is used to alleviate the magnitude expansion caused by squaring, and to maintain numerical stability while preserving the non-linear penalty trend.
[0099] Specific examples are as follows:
[0100] Assume the specific data of the extracted terminal access data group is as shown in Table 1 below:
[0101]
[0102] Calculate the access fingerprint consistency score Sf based on Table 1:
[0103] ;
[0104] S2 specific steps also include,
[0105] S22. Based on the cloud storage system, locate the target file requested by the visitor, and extract the content summary and structured metadata from the target file. Use a hash function to hash and encrypt the content summary and structured metadata of the target file to obtain the structured signature value Hs of the target file. The content summary includes the beginning of the text, tag content, and the closing approval record. The structured metadata includes the file creation time, the account ID of the modifier, the responsible unit, and the IP address of the terminal of the last operation.
[0106] In this embodiment, the access instruction path depth is fused. Terminal geographical location drift distance Matching degree with user behavior template and terminal device matching similarity By comprehensively acquiring the access fingerprint consistency score Sf, the deviation between access behavior and historical trusted behavior is effectively assessed, achieving dual verification of the accesser's identity credibility and behavior compliance. At the same time, by extracting the content summary and structured metadata of the target file and generating a structure signature value Hs, it is ensured that the file has a clear structure identity before authorized decryption. Compared with the existing verification mechanism that only relies on access credentials or static permissions, this embodiment significantly improves the granularity of behavior recognition and the controllability of document objects in file access scenarios, providing a high-precision identification basis for rapid file retrieval and secure access in emergency situations, and effectively suppressing behaviors such as access path forgery and identity impersonation.
[0107] Example 4:
[0108] Please refer to Figure 1 and Figure 4 Specifically: The specific steps of S3 include,
[0109] S31. Based on the relevant data set S retrieved from the archives, analyze the visitor's situation when the system is at the current emergency level. The stability of visitor behavior is assessed, and an emergency response index Et is calculated. The specific method for obtaining the emergency response index Et is as follows: ;
[0110] In the formula, Indicates the width of the authorized access window. Indicates the system emergency level. Indicates the distance the terminal's geographical location has drifted. This represents the maximum authorized geographic range tolerance allowed by the system, sin represents the sine function, and ln represents the logarithm with the irrational number e as the base. Pi is a constant. ∈{0,1}.
[0111] The system's maximum allowed authorized geographic range tolerance The method for obtaining this information involves clustering the historical access trajectories of visitors to create a trusted location area distribution map. Using the center of this map as the trusted center, the actual spatial distance from each historical access point to the trusted center is calculated, and the maximum spatial distance is extracted as the maximum authorized geographic range tolerance. ;
[0112] The derivation logic and physical meaning of the formula: Indicates proactive emergency response items. This is the width of the authorized access window. The smaller the value, the more urgent the access. Squaring it is done to perform non-linear enhancement. This indicates the system emergency level. The two together form a comprehensive expression for measuring the timeliness of authorization and the overall emergency situation of the system;
[0113] Represents the spatial perturbation adjustment factor, perturbation function The phase disturbance response model originates from the field of signal control, in which... The symbol represents the proportion of the displacement, and sin represents the sine function. When analyzing spatial perturbations in access behavior, the spatial perturbation is usually a continuously varying perturbation amplitude. The purpose of using the sine function sin is to simulate the process of perturbation enhancement and mitigation in the interval {0, π}, and to construct... The purpose of this format is to convert physical displacement into a standard angle input that is acceptable to a sine function;
[0114] The natural logarithm function ln is used to make the output a stable, continuous, and timely behavioral scoring indicator;
[0115] In the field of signal control, the phase disturbance response model is based on the principle that when a dynamic entity, such as a signal or terminal, deviates from its reference position or state center, its disturbance amplitude can be modeled by a periodic function. Trigonometric functions, such as sin and cos, are commonly used to represent the nonlinear fluctuations of the disturbance in space or time.
[0116] Specific examples are as follows:
[0117] Assume the parameters are as shown in Table 2:
[0118]
[0119] Based on Table 2, the extracted parameters were substituted into the formula for calculating the emergency response index Et, resulting in an emergency response index Et of 2.6.
[0120] S3 specific steps also include,
[0121] S32. Based on the visitor fingerprint consistency score Sf and the emergency behavior response index Et, analyze the changes in the visitor's behavioral response in the current visit state to obtain a comprehensive risk score Zh. The specific method for obtaining the comprehensive risk score Zh is as follows: ;
[0122] In the formula, Indicates the system alert level. denoted by , log represents the logarithm to the natural constant 10;
[0123] In the comprehensive risk score Zh calculation formula, firstly, the access fingerprint consistency score Sf is subjected to power function risk enhancement processing to obtain... Secondly, a logarithmic response function is constructed by combining the emergency behavior response index E under the current system state to reflect the coupling effect between behavioral deviation risk and system environmental state. Finally, to prevent a non-linear surge in the comprehensive risk score Zh from amplifying risk and leading to misjudgment, a system warning coefficient is set. This helps to curb the excessively rapid growth of the comprehensive risk score Zh and constructs a complete comprehensive risk score Zh.
[0124] The formula derivation logic and physical meaning: The formula is a composite nonlinear risk scoring function, which draws on the construction method of multi-factor risk scoring models. Its theoretical basis includes the exponential enhancement modeling idea, the logarithmic compression function, and the denominator regularization term. Among them, the exponential enhancement modeling idea is used to represent the trend of amplification of abnormal behavior, which comes from the "behavioral amplification factor" modeling in behavioral science and machine learning. The logarithmic compression function is used to compress large input values to avoid the exponential expansion of risk scores. The denominator regularization term introduces an environmental stability suppression term, which is commonly found in the "suppression term modeling" in control theory.
[0125] and It is a linear addition structure. This represents the exponential enhancement term of the access fingerprint consistency score Sf. The natural logarithm of the emergency response index Et+1 is squared, and the numerator is a joint response model of the behavioral credibility factor and the state fluctuation factor, with a power exponent factor. This is used to enhance the amplified expression of consistency deviations, thereby strengthening the ability to sensitively identify behavioral deviations. The intensity of access disturbances under emergency conditions is measured in logarithmic form, reflecting the amplitude of behavioral fluctuations of the system under different response levels. The nonlinear expression of the disturbance is enhanced by squaring, and the denominator is a system alert coefficient that is introduced to suppress the disorderly expansion of high-risk scoring results.
[0126] In a specific example, assuming the access fingerprint consistency score Sf is 2.6, the power factor... The emergency response index Et is 2.6, and the system alert coefficient is 1.3. If the value is 2, then the final comprehensive risk score Zh is calculated to be 0.365.
[0127] Among them, the system alert coefficient This indicates the system's tolerance level for file retrieval risks under the security policy corresponding to the current emergency state. It is an important factor in regulating the fluctuation range of the comprehensive risk score and is set by the administrator according to the policy management panel.
[0128] Power factor It is a control factor used for nonlinear adjustment of the access fingerprint consistency score Sf. Its main function is to amplify or suppress the influence of the access fingerprint score on the comprehensive risk score Zh. Its value range is set according to the system strategy and is usually in the range of 1.1 to 2.5.
[0129] A preset system authorization threshold ZHyz is used. The comprehensive risk score Zh and the system authorization threshold ZHyz are compared and analyzed to verify the authorization of file retrieval requests. The specific evaluation content is as follows:
[0130] When the comprehensive risk score Zh is greater than or equal to the system authorization threshold ZHyz, i.e. Zh≥ZHyz, the accessor's file retrieval request is deemed authorized, the file structure signature Hs is immediately extracted, and the file is decrypted.
[0131] When the comprehensive risk score Zh is less than the system authorization threshold ZHyz, i.e. Zh < ZHyz, it is determined that the visitor's file retrieval request is not authorized. At this time, an alarm is immediately issued, an abnormal behavior audit record is automatically generated, and the system administrator is notified to intervene manually.
[0132] S33. When a visitor's file retrieval request is authorized, based on the target file's structural signature value Hs and combined with the comprehensive risk score Zh, a hash algorithm is used to encrypt and obtain a dynamic access key K. The specific method for obtaining the dynamic access key K is as follows: ;
[0133] In the formula, This represents the structural signature value of the target file. Represents a hash function. This represents the pseudo-time perturbation factor. Pi is a constant. This represents the XOR operator.
[0134] Pseudo-time perturbation factor This mechanism introduces a time-dimensional perturbation mechanism to improve the uniqueness and security of dynamic key generation. Specifically, it calls the system clock interface of the cloud storage system to extract the timestamp when the file authorization is approved, and calculates the value by combining it with the system's built-in time perturbation function. The time perturbation function is a mathematical mapping function used to map input variables, such as timestamps, spatial locations, and behavioral frequencies, to highly nonlinear and low-predictability output values.
[0135] In the formula for calculating the dynamic access key K, This is the static part, representing the signature value for accessing the target structure, used to ensure that the generated key is bound to the target structure. This is the dynamic part, used to analyze visitor behavior, system state, and micro-temporal perturbations to ensure the key is dynamic and time-varying, while the XOR operator... This is used to mix the static and dynamic parts to form the final dynamic access key K, thus enabling two-factor binding.
[0136] Formula derivation logic: The formula for calculating the dynamic access key K originates from the hash-mixed key generation mechanism, specifically the XOR operator. The XOR operation, a classic information confusion operator, combines two hash values into a new pseudo-random output. When combined with a hash function, it forms an irreversible mapping, satisfying the cryptographic requirements of one-way hashing and unpredictable collisions. This can introduce unpredictable disturbances, ensuring that the key obtained each time access is performed on the same file is different, resulting in a product... This amplifies the changing trends of comprehensive risk factors, making security disturbances more sensitive. Can this combination prevent key replay attacks and avoid "the same behavior generating the same key"?
[0137] S34. Record authorization verification-related data in real time during the file retrieval request authorization verification process to construct an authorization trajectory subchain. The authorization trajectory subchain includes the access fingerprint consistency score Sf, the emergency behavior response index Et, the comprehensive risk score Zh, and the authorization pass timestamp.
[0138] In this embodiment, an emergency behavior response index Et is constructed. Combining the system's emergency level, authorization window width, and geographical location changes, it dynamically reflects the stability of the visitor's behavior under special conditions. Furthermore, it integrates the access fingerprint consistency score Sf to generate a comprehensive risk score Zh, achieving refined authorization judgment for retrieval requests. Compared with the traditional method that relies on static permission verification, this embodiment can quickly identify high-risk operations in sudden emergency scenarios and dynamically decide whether to allow access requests based on authorization thresholds, thereby effectively improving the flexibility and security of the authorization process. At the same time, a dynamic access key K is constructed based on the structural signature value Hs and the comprehensive risk score Zh, and the complete authorization process is recorded synchronously to generate an authorization trajectory subchain, providing chain evidence support for post-event auditing and accountability tracing, ensuring that the entire process of accessing sensitive files is controllable, auditable, and traceable.
[0139] Example 5:
[0140] Please refer to Figure 1 Specifically: The specific steps of S4 include,
[0141] S41. Based on the generated dynamic access key K, locate the structured data block in the structured block directory of the cloud storage system using the dynamic access key K, and record the structured data block number Index. Here, the structured block directory refers to the numbered directory constructed by using a segmented encryption storage method to divide the target file into several structured data blocks for data storage and summarizing the numbers of each structured data block when storing the target file.
[0142] S42. Define each structured data block as a decryption node, and collect the decryption behavior data of each decryption node in real time during the decryption operation. The decryption behavior data includes the decryption time. and data read volume ;
[0143] Decryption time The total time for decryption operations at the decryption node is collected by the system access controller.
[0144] Data read volume This refers to the total amount of archive data read, which is obtained through the USN log. The USN log is a built-in mechanism in the Windows NTFS file system used to record changes to all files and directories on the volume.
[0145] S43. Based on the decryption behavior data, construct a decryption behavior constraint function. And for each decryption node, the decryption time is calculated. Timeout and data read volume The compliance of decryption operations at decryption nodes is jointly judged based on two dimensions: whether it exceeds the limit and whether it exceeds the limit. The decryption behavior restriction function is used as an example. Obtain it using the following formula: ;
[0146] In the formula, This indicates the maximum decryption time threshold. This represents the maximum read range threshold, i.e., the maximum amount of data allowed to be decrypted in a single authorization. In addition to All other cases;
[0147] express and Both conditions must be met simultaneously, when and When both conditions are met, the decryption behavior restriction function is activated. The value is 1;
[0148] Decryption behavior restriction function The logical structure is a binary decision function used to determine whether the current decryption operation is compliant and authorized. If the decryption operation is successful, the node is marked as authorized. =1, and except All other situations are considered non-compliant decryption operations. =0;
[0149] Among them, the maximum decryption time threshold and maximum read range threshold Set by the client based on historical experience;
[0150] like If the value is 1, the decryption operation is deemed compliant, and the system allows the decryption operation to be performed. At this time, the decryption node is marked as a normal node, and the decrypted plaintext data is automatically returned.
[0151] like If the value is 0, the decryption operation is deemed non-compliant, the system refuses to execute the decryption operation, the decryption node is marked as an abnormal node, and the decryption operation is stopped.
[0152] The specific steps in S4 also include,
[0153] S44. Collect the decryption behavior data from each decryption node and encapsulate it in a structured manner to construct a data decryption subchain. The data decryption subchain includes the structured data block number (Index) and data read volume of each decryption node. Decryption time Decryption behavior restriction function Numerical values and decryption node markers;
[0154] S45. Record the end time of the decryption operation of the last decryption node as the file access end time. At this point, the file decryption operation terminates, and the constructed authorized trajectory subchain, data decryption subchain, and file access termination time point are linked together. A unified structural encapsulation is performed to obtain a complete data audit chain. The retrieval of the target file includes two stages: file retrieval request authorization verification and file decryption. The authorization verification stage obtains an authorization trajectory sub-chain, and the decryption stage obtains a data decryption sub-chain. These two sub-chains are combined to construct the complete data audit chain. The file decryption stage performs compliance checks on each decryption node of the target file. Once each decryption node has completed its compliance check, the decryption stage is complete. The termination time of the decryption operation at the last decryption node is the file access termination time. The decryption phase is complete, and the file retrieval process is finished.
[0155] In this embodiment, by structurally dividing the target file into blocks and setting independent decryption nodes, the management granularity of the decryption operation is refined, avoiding the risk diffusion problem caused by the overall decryption process. Furthermore, by using a dynamic access key K to precisely locate data blocks, the consistency of the decryption behavior and the controllability of the process are effectively improved. Simultaneously, the behavioral data of each decryption node, including decryption time and data read volume, is collected and analyzed in real time, combined with a decryption behavior constraint function. Compliance assessments can automatically identify unauthorized operations or abnormal behaviors at the system level, enhancing the risk adaptability of the decryption process. Ultimately, the constructed data decryption subchain and authorization trajectory subchain jointly form a complete data audit chain, enabling full-process tracking and recording of the decryption process. This provides comprehensive and structured reliable support for subsequent anomaly tracing, accountability review, and access behavior assessment, significantly enhancing the security and auditability of the system's access to sensitive files in emergency situations.
[0156] Example 6:
[0157] Please refer to Figure 1 Specifically: The S5 steps include,
[0158] S51. Based on the complete data audit chain, analyze the degree of anomaly in the overall file access process to obtain an anomaly audit score Re. The specific method for obtaining the anomaly audit score Re is as follows: ;
[0159] In the formula, Indicates the point in time when access to the archive ended. Indicates the start time of file access. Indicates the width of the authorized access window. Indicates the function that restricts decryption behavior. The total number of decryption nodes is 1. Indicates the total number of decryption nodes;
[0160] The derivation logic and physical meaning of the formula: The access time offset rating item is derived from the standardized deviation measurement model. Its purpose is to compare the actual time a visitor spends accessing the target file with the system's authorized access window to determine whether a timeout has occurred. The squared form is used to make the deviation non-linearly amplified, making it more sensitive to abnormal access times.
[0161] The anomaly score Re represents decryption behavior anomalies. It originates from the access authorization compliance rate model in cryptography and is used to assess how many decryption nodes failed to meet behavioral restrictions during the overall file decryption process. The anomaly audit score Re is a linear combination of two substructures in terms of structure. The combination method is direct superposition. The two complement each other in terms of the ability to interpret anomalies, avoiding misjudgment by a single indicator. The larger the value of the anomaly audit score Re, the more serious the overall deviation of this file access.
[0162] Specific examples are as follows:
[0163] Assuming the parameters are obtained as follows Figure 3 :
[0164]
[0165] Based on Table 3, calculate the access time offset scoring item:
[0166] =1.17;
[0167] Calculate authorization compliance deviation:
[0168] =0.2;
[0169] Combined acquisition of abnormal audit scores Re:
[0170] Re=1.37.
[0171] If the abnormal audit threshold Reyz is set to 2, and the abnormal audit score Re=1.37 is less than the abnormal audit threshold Reyz, then the file access behavior is judged to be of the first risk level and no action is required.
[0172] S52. Preset anomaly audit threshold Reyz, and compare and analyze the anomaly audit score Re and the anomaly audit threshold Reyz to assess the risk level of file access behavior. The specific assessment process is as follows:
[0173] If the abnormal audit score Re is less than the abnormal audit threshold Reyz, the file access behavior is determined to be of the first risk level. At this time, no action is required, and the file access behavior is archived into the file access log.
[0174] If the abnormal audit score Re is greater than or equal to the abnormal audit threshold Reyz, it indicates that the file access behavior is at the second risk level. At this time, the risk alarm mechanism is triggered, the access terminal of the visitor is automatically marked, and an abnormal behavior report is generated. At the same time, the abnormal behavior report is sent to the system administrator to generate response and handling strategies, including terminal blocking and behavior authentication restart.
[0175] Reyz pre-sets the anomaly audit threshold by using the quartile method based on historical behavior audit data.
[0176] In this embodiment, a complete data audit chain enables precise recording and traceability of the entire file access process. Especially in emergency decryption environments, it ensures a systematic assessment of the continuity, integrity, and compliance of access behavior. Furthermore, by calculating the anomaly audit score Re, it effectively integrates access duration, authorization time window, and the compliance status of behavior at each decryption node, quantifying the degree of anomaly in the access process and ensuring that access risk assessment has a data foundation and is verifiable. Simultaneously, by setting an anomaly audit threshold Reyz, a risk level judgment mechanism is established, enabling automatic graded response to access behavior. When a high anomaly risk is detected, the system can automatically block access, generate an anomaly report, and link the audit process, constructing a closed-loop control chain of "behavior perception - risk identification - security linkage," significantly improving the system's security response capabilities and accountability traceability in highly sensitive file management scenarios.
[0177] Example 7:
[0178] Please refer to Figure 2 Specifically: a cloud storage-based archive management system, including a data acquisition module, a data analysis module, an authorization verification module, an archive decryption module, and an anomaly assessment module;
[0179] The data acquisition module is used to collect emergency-related data and terminal access-related data in real time, and to build a data set S for file retrieval.
[0180] The data analysis module retrieves relevant data set S based on the file, performs feature extraction, obtains the access fingerprint consistency score Sf, and constructs the structural signature value Hs of the target file;
[0181] The authorization verification module is used to obtain the emergency behavior response index Et based on the file retrieval related data set S, and generate a comprehensive risk score Zh by combining the access fingerprint consistency score Sf, to perform file retrieval request authorization verification, construct a dynamic access key K, record authorization verification related data, and construct an authorization trajectory subchain.
[0182] The file decryption module is used to perform decryption operations based on the dynamic access key K, and to collect decryption behavior data in real time to construct decryption behavior restriction functions. Assess the compliance of decryption operations, collect decryption behavior data from each decryption node, construct a data decryption subchain, and combine it with the authorization trajectory subchain to obtain a complete data audit chain;
[0183] The anomaly assessment module is used to analyze the degree of anomaly in file access behavior based on the complete data audit chain, in order to obtain an anomaly audit score (Re) and assess the risk level of the file access behavior.
[0184] In this embodiment, by structurally dividing the entire process of collecting, analyzing, authorizing, decrypting, and assessing anomalies related to file access behavior, the system achieves high cohesion of functions and strong coupling of process logic, thereby improving overall processing efficiency and security controllability. The system can not only accurately identify visitor behavior characteristics and access background, but also perform risk perception and authorization decisions based on behavioral fingerprints and emergency response status, enabling rapid decryption and access tracking to proceed in parallel. At the same time, by monitoring the behavior of decryption nodes in real time and building a complete data audit chain, the entire access process has traceability and quantifiable risk analysis capabilities, significantly enhancing compliance assurance and accountability traceability in emergency decryption scenarios.
[0185] Although embodiments of the invention have been shown and described, it will be understood by those skilled in the art that various changes, modifications, substitutions and alterations can be made to these embodiments without departing from the principles and spirit of the invention, the scope of which is defined by the appended claims and their equivalents.
Claims
1. A cloud storage-based file management method, characterized in that: Includes the following steps, S1. Collect emergency status-related data and terminal access-related data in real time, and construct a data set S for file retrieval; S2. Based on the relevant data set S retrieved from the file, feature extraction is performed to obtain the access fingerprint consistency score Sf, and the structural signature value Hs of the target file is constructed. S3. Based on the data set S related to file retrieval, obtain the emergency behavior response index Et, and combine it with the access fingerprint consistency score Sf to generate a comprehensive risk score Zh. Perform file retrieval request authorization verification, construct a dynamic access key K, record authorization verification related data, and construct an authorization trajectory subchain. S4. Based on the dynamic access key K, perform the decryption operation and collect decryption behavior data in real time to construct a decryption behavior restriction function. Assess the compliance of decryption operations, collect decryption behavior data from each decryption node, construct a data decryption subchain, and combine it with the authorization trajectory subchain to obtain a complete data audit chain; S5. Based on the complete data audit chain, analyze the degree of abnormality of file access behavior to obtain an abnormal audit score Re and assess the risk level of file access behavior.
2. The file management method based on cloud storage according to claim 1, characterized in that: The specific steps in S1 include: S11. By monitoring the scheduling bus through the cloud storage system's status management interface, upon receiving a file retrieval request, record emergency status-related data, including the system emergency level. and authorized access window width ; S12. Call the terminal operating system API interface to obtain the visitor's terminal access-related data in real time. The terminal access-related data includes the feature vector of the terminal access device. Access command path depth Terminal geographical location drift distance Matching degree with user behavior template ; Feature vector of terminal access device It includes various hardware identifiers of the terminal access device, including MAC address, motherboard serial number, CPU serial number, and hard disk ID; Access command path depth This refers to the number of operation command paths involved in a user initiating a file retrieval request in the terminal; Terminal geographic location drift distance This refers to the distance difference between the physical location of the terminal device and the physical location recorded in the historical trusted access record when the file retrieval request is issued, which is used to assess whether the visitor has geographically shifted. User behavior template matching degree This refers to the similarity between the user's action path during the process of issuing a file retrieval request and historically trusted action paths. S13. Perform dimensionless processing on emergency-related data and terminal access-related data, unify different physical dimension parameters, and construct a data set S for file retrieval based on the dimensionless emergency-related data and terminal access-related data.
3. The cloud storage-based file management method according to claim 2, characterized in that: The specific steps of S2 include, S21. Based on the terminal access-related data retrieved from the relevant data set S, analyze the rationality and credibility of the visitor's access behavior, and obtain the access fingerprint consistency score Sf. The specific method for obtaining the access fingerprint consistency score Sf is as follows: ; In the formula, Indicates the path depth of the access command. Indicates the degree of matching between user behavior and template. Indicates the distance the terminal's geographical location has drifted. Indicates the similarity between terminal devices. The feature vector representing the terminal access device used by the current visitor. The i-th hardware identifier within, Feature vector representing historical trusted terminal access devices The i-th hardware identifier within, Indicates an indicator function, if = ,but If it is 1, ≠ ,but If n is 0, then n represents the total number of hardware identifiers in the feature vector of the terminal access device.
4. The cloud storage-based file management method according to claim 3, characterized in that: S2 specific steps also include, S22. Based on the cloud storage system, locate the target file requested by the visitor, and extract the content summary and structured metadata from the target file. Use a hash function to hash and encrypt the content summary and structured metadata of the target file to obtain the structured signature value Hs of the target file. The content summary includes the beginning of the text, tag content, and the closing approval record. The structured metadata includes the file creation time, the account ID of the modifier, the responsible unit, and the IP address of the terminal of the last operation.
5. The file management method based on cloud storage according to claim 1, characterized in that: The specific steps of S3 include, S31. Based on the relevant data set S retrieved from the archives, analyze the visitor's situation when the system is at its current emergency level. The stability of visitor behavior is assessed, and an emergency response index Et is calculated. The specific method for obtaining the emergency response index Et is as follows: ; In the formula, Indicates the width of the authorized access window. Indicates the system emergency level. Indicates the distance the terminal's geographical location has drifted. This represents the maximum authorized geographic range tolerance allowed by the system, sin represents the sine function, and ln represents the logarithm with the irrational number e as the base. Pi is a constant. ∈{0,1}.
6. The file management method based on cloud storage according to claim 5, characterized in that: S3 specific steps also include, S32. Based on the visitor fingerprint consistency score Sf and the emergency behavior response index Et, analyze the changes in the visitor's behavioral response in the current visit state to obtain a comprehensive risk score Zh. The specific method for obtaining the comprehensive risk score Zh is as follows: ; In the formula, Indicates the system alert level. denoted by , log represents the logarithm to the natural constant 10; A preset system authorization threshold ZHyz is used. The comprehensive risk score Zh and the system authorization threshold ZHyz are compared and analyzed to verify the authorization of file retrieval requests. The specific evaluation content is as follows: When the comprehensive risk score Zh is greater than or equal to the system authorization threshold ZHyz, i.e. Zh≥ZHyz, the accessor's file retrieval request is deemed authorized, the file structure signature Hs is immediately extracted, and the file is decrypted. When the comprehensive risk score Zh is less than the system authorization threshold ZHyz, i.e. Zh < ZHyz, it is determined that the visitor's file retrieval request is not authorized. At this time, an alarm is immediately issued, an abnormal behavior audit record is automatically generated, and the system administrator is notified to intervene manually. S33. When a visitor's file retrieval request is authorized, based on the target file's structural signature value Hs and combined with the comprehensive risk score Zh, a hash algorithm is used to encrypt and obtain a dynamic access key K. The specific method for obtaining the dynamic access key K is as follows: ; In the formula, This represents the structural signature value of the target file. Represents a hash function. This represents the pseudo-time perturbation factor. Pi is a constant. This represents the XOR operator; S34. Record authorization verification-related data in real time during the file retrieval request authorization verification process to construct an authorization trajectory subchain. The authorization trajectory subchain includes the access fingerprint consistency score Sf, the emergency behavior response index Et, the comprehensive risk score Zh, and the authorization pass timestamp.
7. The file management method based on cloud storage according to claim 6, characterized in that: The specific steps of S4 include, S41. Based on the generated dynamic access key K, locate the structured data block in the structured block directory of the cloud storage system using the dynamic access key K, and record the structured data block number Index. Here, the structured block directory refers to the numbered directory constructed by using a segmented encryption storage method to divide the target file into several structured data blocks for data storage and summarizing the numbers of each structured data block when storing the target file. S42. Define each structured data block as a decryption node, and collect the decryption behavior data of each decryption node in real time during the decryption operation. The decryption behavior data includes the decryption time. and data read volume ; Decryption time The total time for decryption operations at the decryption node is collected by the system access controller. Data read volume This refers to the total amount of archive data read, which is obtained through USN log identification; S43. Based on the decryption behavior data, construct a decryption behavior constraint function. And for each decryption node, the decryption time is calculated. Timeout and data read volume The compliance of decryption operations at decryption nodes is jointly judged based on two dimensions: whether it exceeds the limit and whether it exceeds the limit. The decryption behavior restriction function is used as an example. Obtain it using the following formula: ; In the formula, This indicates the maximum decryption time threshold. This represents the maximum read range threshold, i.e., the maximum amount of data allowed to be decrypted in a single authorization. In addition to All other cases; like If the value is 1, the decryption operation is deemed compliant, and the system allows the decryption operation to be performed. At this time, the decryption node is marked as a normal node, and the decrypted plaintext data is automatically returned. like If the value is 0, the decryption operation is deemed non-compliant, the system refuses to execute the decryption operation, the decryption node is marked as an abnormal node, and the decryption operation is stopped.
8. The file management method based on cloud storage according to claim 7, characterized in that: The specific steps in S4 also include, S44. Collect the decryption behavior data from each decryption node and encapsulate it in a structured manner to construct a data decryption subchain. The data decryption subchain includes the structured data block number (Index) and data read volume of each decryption node. Decryption time Decryption behavior restriction function Numerical values and decryption node markers; S45. Record the end time of the decryption operation of the last decryption node as the file access end time. At this point, the file decryption operation terminates, and the constructed authorized trajectory subchain, data decryption subchain, and file access termination time point are linked together. Perform unified structural encapsulation to obtain a complete data audit chain.
9. A cloud storage-based file management method according to claim 8, characterized in that: The specific steps of S5 include, S51. Based on the complete data audit chain, analyze the degree of anomaly in the overall file access process to obtain an anomaly audit score Re. The specific method for obtaining the anomaly audit score Re is as follows: ; In the formula, Indicates the point in time when access to the archive ended. Indicates the start time of file access. Indicates the width of the authorized access window. Indicates the function that restricts decryption behavior. The total number of decryption nodes is 1. Indicates the total number of decryption nodes; S52. Preset anomaly audit threshold Reyz, and compare and analyze the anomaly audit score Re and the anomaly audit threshold Reyz to assess the risk level of file access behavior. The specific assessment process is as follows: If the abnormal audit score Re is less than the abnormal audit threshold Reyz, the file access behavior is determined to be of the first risk level. At this time, no action is required, and the file access behavior is archived into the file access log. If the abnormal audit score Re is greater than or equal to the abnormal audit threshold Reyz, it indicates that the file access behavior is at the second risk level. At this time, the risk alarm mechanism is triggered, the access terminal of the visitor is automatically marked, and an abnormal behavior report is generated. At the same time, the abnormal behavior report is sent to the system administrator to generate response and handling strategies, including terminal blocking and behavior authentication restart.
10. A cloud-based archive management system, used to implement the cloud-based archive management method according to any one of claims 1 to 9, characterized in that: It includes a data acquisition module, a data analysis module, an authorization verification module, an archive decryption module, and an anomaly assessment module; The data acquisition module is used to collect emergency-related data and terminal access-related data in real time, and to build a data set S for file retrieval. The data analysis module retrieves relevant data set S based on the file, performs feature extraction, obtains the access fingerprint consistency score Sf, and constructs the structural signature value Hs of the target file; The authorization verification module is used to obtain the emergency behavior response index Et based on the file retrieval related data set S, and generate a comprehensive risk score Zh by combining the access fingerprint consistency score Sf, to perform file retrieval request authorization verification, construct a dynamic access key K, record authorization verification related data, and construct an authorization trajectory subchain. The file decryption module is used to perform decryption operations based on the dynamic access key K, and to collect decryption behavior data in real time to construct decryption behavior restriction functions. Assess the compliance of decryption operations, collect decryption behavior data from each decryption node, construct a data decryption subchain, and combine it with the authorization trajectory subchain to obtain a complete data audit chain; The anomaly assessment module is used to analyze the degree of anomaly in file access behavior based on the complete data audit chain, in order to obtain an anomaly audit score (Re) and assess the risk level of the file access behavior.
Citation Information
Patent Citations
Intelligent archival repository identity data processing method and system
CN119992632A
File full life cycle management system and method based on cloud computing
CN120045520A