Data security protection method and device in cloud computing and storage medium
By extracting feature vectors from time-series framed data, setting priorities, and dynamically encrypting them, combined with trust state assessment and path optimization, the problem of low data security protection efficiency in existing technologies is solved, achieving efficient and secure data transmission.
Patent Information
- Application Number
- CN202511245369.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-09-02
- Publication Date
- 2026-03-17
- Estimated Expiration
- 2045-09-02
AI Technical Summary
Existing data security protection methods are difficult to adapt to the dynamic and changing industrial time-series data environment and cannot meet the dual requirements of real-time and high security. They are particularly vulnerable to attacks or latency anomalies in high-concurrency scenarios.
By extracting feature vectors from time-series framed data to set data priorities, and combining this with dynamic encryption technology, the trust status of edge devices is evaluated in real time, the transmission path is optimized, the framing strategy is dynamically adjusted, and a spatiotemporal correlation matrix is constructed to select the optimal path for data transmission.
It significantly improves the security and transmission efficiency of industrial time-series data in a cloud-edge collaborative environment, effectively prevents data leakage and tampering, reduces latency, enhances anti-attack capabilities, and optimizes the real-time performance and stability of data transmission.
Smart Images

Figure CN121283665B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of data security technology, and in particular to a data security protection method, device and storage medium in cloud computing. Background Technology
[0002] With the rapid development of cloud computing technology, edge computing, as an important extension, has gradually become a core supporting technology in the Industrial Internet of Things (IIoT). In a cloud-edge collaborative architecture, time-series data generated by edge devices needs to be transmitted to the cloud in real time for processing and analysis to achieve efficient industrial automation control. However, this data transmission process faces many security challenges, such as data leakage, tampering, and transmission delays. Existing data security protection methods mostly focus on the encryption of static data and the fixed optimization of transmission paths, which are difficult to adapt to the dynamically changing industrial time-series data environment, resulting in low data security protection efficiency and failing to meet the dual requirements of real-time performance and high security.
[0003] Furthermore, the heterogeneity of edge devices and the complexity of network environments further exacerbate the difficulty of data security protection. Traditional methods often neglect the dynamic assessment of device trust status and real-time optimization of transmission paths, making data transmission vulnerable to attacks or experiencing abnormal latency. Especially in high-concurrency scenarios, unreasonable data priority allocation or a single encryption method may lead to data congestion or security vulnerabilities. Therefore, there is an urgent need for a data protection method that can dynamically adapt to the characteristics of industrial time-series data and balance security and real-time performance to improve the efficiency of data security protection in cloud computing environments. Summary of the Invention
[0004] The purpose of this invention is to provide a data security protection method, device and storage medium in cloud computing, so as to solve at least one of the problems existing in the prior art.
[0005] To achieve the above objectives, according to one aspect of this application, the present invention provides a data security protection method in cloud computing, comprising:
[0006] The feature vectors of the time-series framed data are extracted based on the time-series framed data, and the data priority of each edge device is set based on the feature vectors of the time-series framed data. The time-series framed data is also encrypted based on the feature vectors of the time-series framed data.
[0007] The transmission trust status of each edge device is determined, and then a transmission path is established based on the transmission trust status determination result. The time-series framed data of each edge device is then uploaded based on the transmission path.
[0008] The system processes the uploaded time-series framed data from each edge device and collects the cloud computing feedback time. This allows the system to determine the real-time response status of each edge device and update the framed data process of the original time-series data from each edge device.
[0009] Optionally, the raw time-series data of each edge device can be collected in real time, and the raw time-series data can be processed into frames to obtain time-series framed data.
[0010] The original timing data of each edge device is divided into frames according to a set frame length to obtain the timing frame data of each edge device.
[0011] Optionally, the feature vector of the time-series framed data of each edge device is extracted and set as F(i), where F(i) = {cv(i), t(i), T(i), ZC(i), f(i)}, where cv(i) is the coefficient of variation of the time-series framed data of the i-th edge device, t(i) represents the data sequence of the time-series framed data of the i-th edge device, T(i) represents the timestamp of the time-series framed data of the i-th edge device, ZC(i) represents the set frame length of the time-series framed data of the i-th edge device, and f(i) represents the fluctuation entropy of the time-series framed data of the i-th edge device.
[0012] Optionally, the priority index of the time-series framed data is calculated in a weighted manner and denoted as y(i). The formula is set as y(i) = a1×cv(i) + a2×f(i), where a1 and a2 are the fluctuation weight and entropy weight, respectively, and a1+a2=1.
[0013] The priority index of the time-series framed data of each edge device is sorted in descending order, and the sorting result is used as the data priority of the time-series framed data.
[0014] The combination of time-series frame data and its feature vectors is used as the encrypted data.
[0015] Optionally, a trust index α(i) is constructed for each edge device;
[0016] The trust index of each edge device is compared with a preset trust threshold. Edge devices with a trust status greater than or equal to the preset trust threshold are judged as trustworthy edge devices, while edge devices with a trust status lower than the preset trust threshold are judged as risky edge devices.
[0017] Optionally, a spatiotemporal correlation matrix between trusted edge devices is established, and the establishment process is as follows:
[0018] Obtain the spatial distance between each edge device, and denote the spatial distance between the i-th edge device and the k-th edge device as d(i,k). Then, use the result of {d(i,k)×[α(i)-preset trust threshold] / preset trust threshold×[α(k)-preset trust threshold] / preset trust threshold} as the transmission security coefficient between the i-th edge device and the k-th edge device.
[0019] A spatiotemporal correlation matrix between edge devices is constructed based on the transmission security coefficient between each edge device.
[0020] Optionally, the nearest relay node to the i-th edge device is retrieved, and the edge device closest to that relay node is taken as the target node;
[0021] Retrieve all non-repeating paths from the i-th edge device to the target node using the spatiotemporal correlation matrix between each edge device, and calculate the security index β(i,h) for each non-repeating path, where β(i,h) represents the security index of the h-th non-repeating path of the i-th edge device, and the value of β(i,h) is set to be the sum of the transmission security coefficients between each edge device traversed in the h-th non-repeating path of the i-th edge device.
[0022] The path with the highest security index among all non-repeating paths is selected as the transmission path.
[0023] When an edge device transmits encrypted time-series framed data to the next edge device, the time-series framed data to be transmitted in the next edge device is prioritized according to the data priority of the time-series framed data. The time-series framed data is then transmitted to the next edge device with the reordered priority, until it reaches the target node, from which it is transmitted to the cloud server.
[0024] Optionally, the processed time-series framed data is input to a cloud server for cloud computing processing, and the cloud computing feedback time ft is collected. Then, the data response time XT of the edge device where the time-series framed data is located is calculated, and XT = ft + 2 × ct is set.
[0025] The data response time of the edge device where the time-series frame data is located is compared with the preset response time. The real-time response status of the edge device when XT is greater than the preset response time is judged as an abnormal state, and the real-time response status of the edge device when XT is less than or equal to the preset response time is judged as a normal state.
[0026] When the real-time response status of the edge device is normal, the framing process of the original data of the edge device is not updated.
[0027] When the real-time response status of the edge device is abnormal, update the set frame length of the original data of the edge device to ZC(i)'.
[0028] According to another aspect of this application, a data security protection device for cloud computing is provided, comprising:
[0029] The framing unit is used to collect raw time-series data from each edge device in real time and perform framing processing on the raw time-series data to obtain time-series framed data.
[0030] The encryption unit is used to extract the feature vector of the time-series framed data based on the time-series framed data, set the data priority of each edge device based on the feature vector of the time-series framed data, and encrypt the time-series framed data based on the feature vector of the time-series framed data.
[0031] The upload unit is used to determine the transmission trust status of each edge device, and then establish a transmission path based on the transmission trust status determination result, and upload the time-series framed data of each edge device based on the transmission path.
[0032] The response analysis unit is used to process the time-series frame data uploaded from each edge device, collect the cloud computing feedback time, and then judge the real-time response status of each edge device.
[0033] The update unit is used to update the framing process of the original time-series data of each edge device based on the real-time response status of each edge device.
[0034] According to another aspect of this application, a computer-readable storage medium is provided, the computer-readable storage medium storing a computer program, wherein the computer program is used to control the electronic device in which the computer-readable storage medium is located to perform the data security protection method in cloud computing during runtime.
[0035] Compared with existing technologies, the advantages of this invention are as follows: Through dynamic acquisition, frame processing, and feature extraction, it significantly improves the security and transmission efficiency of industrial time-series data in a cloud-edge collaborative environment. This method intelligently sets priorities based on the feature vectors of time-series data and combines them with dynamic encryption technology to effectively prevent data leakage and tampering, ensuring data integrity and confidentiality. By evaluating the trust status of edge devices in real time and optimizing transmission paths, the system can automatically avoid high-risk nodes and select the optimal path for data transmission, thereby reducing latency and enhancing anti-attack capabilities. Furthermore, the system continuously monitors the response status and dynamically adjusts the frame-segmentation strategy, further optimizing the real-time performance and stability of data transmission. The overall solution balances security and transmission efficiency, is suitable for high-concurrency, high-dynamic industrial IoT scenarios, and provides an efficient and reliable solution for data security protection in cloud computing environments. Attached Figure Description
[0036] To more clearly illustrate the technical solutions in the embodiments of the present invention, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0037] Figure 1 This is a flowchart illustrating the data security protection method in cloud computing in this embodiment.
[0038] Figure 2 This is a flowchart illustrating the temporal feature extraction method in this embodiment.
[0039] Figure 3 This is a flowchart illustrating the time-series framed data upload method in this embodiment.
[0040] Figure 4 This is a schematic diagram of the data security protection device in cloud computing provided in this embodiment. Detailed Implementation
[0041] To more clearly illustrate the present invention, the following description, in conjunction with preferred embodiments and accompanying drawings, further clarifies the invention. Similar components in the drawings are indicated by the same reference numerals. Those skilled in the art should understand that the specific description below is illustrative rather than restrictive and should not be construed as limiting the scope of protection of the present invention.
[0042] It should be noted that although the terms first, second, third, etc., may be used in the embodiments of this application for description, these descriptions should not be limited to these terms. These terms are only used to distinguish the descriptions. For example, without departing from the scope of the embodiments of this application, first can also be referred to as second, and similarly, second can also be referred to as first.
[0043] The acquisition, storage, use, and processing of data in this application all comply with the relevant provisions of national laws and regulations.
[0044] Specifically, the data security protection method in cloud computing described in this application is applied to data security protection during the dynamic transmission of time-series data in a cloud-edge collaborative architecture; the time-series data described in this application is specifically industrial time-series data; specifically, during the dynamic transmission of time-series data described in this application, a transmission path needs to be jointly established by edge devices and relay nodes to transmit the time-series data to the cloud server through the relay node, and the cloud server processes the time-series data to achieve low-latency and high-security data transmission of time-series data from edge devices in industrial scenarios.
[0045] To apply the above-mentioned application scenarios, this application provides a data security protection method in cloud computing, the flowchart of which can be found in the document. Figure 1 As shown, it includes:
[0046] Step S101: Collect raw time-series data from each edge device in real time, and perform frame-segmentation processing on the raw time-series data to obtain time-series framed data.
[0047] The edge device described in this application is an industrial device on an industrial production line;
[0048] The raw time-series data of each edge device is a raw time-series data stream collected from the edge device. The data structure of the data stream is a data set, which can be denoted as D in this application. In this application, D is a set of data of one data type, such as: {d1,d2,d3...}, where d1, d2, and d3 represent the first data, the second data, and the third data, respectively. At the same time, the raw data of each edge device can also be a set of data of multiple data types. In this case, the raw time-series data is composed of multiple data. This application does not specifically limit the number of data types, but sets it according to the number of data types in the raw time-series data transmitted by the edge device.
[0049] Specifically, in step S101, the process of framing the original data is as follows: the original timing data of each edge device is framing according to a set frame length to obtain the timing framed data of each edge device.
[0050] For example, this application does not specifically limit the value of the set frame length. Those skilled in the art can set it freely, as long as the value requirement of the set frame length is met. This application provides an exemplary embodiment of a set frame length setting method, the process of which is as follows: the data acquisition frequency of each edge device is obtained, and the frame processing time is 5ms as the cutoff processing time. The number of data is collected for the cutoff processing time, and the product of the number of data and the data acquisition frequency of each edge device is used as the set frame length of each edge device.
[0051] It is worth noting that the time-series framed data obtained through the frame-segmentation processing described in this application has the same amount of data per frame, but the set duration of each edge device is different.
[0052] Specifically, by collecting raw time-series data from edge devices in real time and performing frame segmentation, the complexity of data transmission can be effectively reduced, and processing efficiency improved. Framed data is easier to manage and encrypt, while also reducing latency during transmission. This method also supports dynamic adjustment of frame length to adapt to the transmission needs of different devices, ensuring the stability and reliability of data in complex network environments and laying the foundation for subsequent security measures.
[0053] Please continue reading. Figure 1 As shown, the data security protection method in cloud computing also includes:
[0054] Step S102: Extract the feature vector of the time-series framed data based on the time-series framed data, set the data priority of each edge device based on the feature vector of the time-series framed data, and encrypt the time-series framed data based on the feature vector of the time-series framed data.
[0055] Please see Figure 2 The diagram shown is a flowchart of the temporal feature extraction method provided in this application, including:
[0056] Step S201: Extract the feature vector of the time-series framed data based on the time-series framed data.
[0057] Specifically, in step S201, the process of calculating the feature vector of the time-series framed data is as follows:
[0058] Extract the feature vector of the time-series framed data of each edge device and set it as F(i), where F(i) = {cv(i), t(i), T(i), ZC(i), f(i)}, where cv(i) is the coefficient of variation of the time-series framed data of the i-th edge device, t(i) represents the data sequence of the time-series framed data of the i-th edge device, T(i) represents the timestamp of the time-series framed data of the i-th edge device, ZC(i) represents the set frame length of the time-series framed data of the i-th edge device, and f(i) represents the fluctuation entropy of the time-series framed data of the i-th edge device. In the formula, p[D(i,j)] represents the frequency of occurrence of the j-th data in the time-series framed data of the i-th edge device, and J is the number of data categories in the time-series framed data of the i-th edge device.
[0059] It is understood that the feature vector of the time-series framed data of each edge device described in this application includes five sub-vectors: {cv(i), t(i), T(i), ZC(i), f(i)}. Among them, cv(i), t(i), and f(i) are dimensionless sub-vectors, while T(i) and ZC(i) have temporal physical meaning. The feature vector described in this application refers to data that can represent the characteristics of the time-series framed data. At the same time, the "number of data categories in the time-series framed data of the i-th edge device" mentioned in this application refers to the number of different data of this data type in the time-series framed data provided by the edge device.
[0060] Please continue reading. Figure 2 As shown, the time-series feature extraction method further includes:
[0061] Step S202: Set the data priority of each edge device using the feature vector of the time-series framed data, and encrypt the time-series framed data using the feature vector of the time-series framed data.
[0062] Specifically, in step S202, the process of setting the data priority of each edge data node is as follows:
[0063] The priority index of the time-series framed data is calculated by weighted calculation and denoted as y(i). Set y(i) = a1×cv(i) + a2×f(i), where a1 and a2 are the fluctuation weight and entropy weight, respectively, and a1+a2=1.
[0064] The priority index of the time-series framed data of each edge device is sorted in descending order, and the sorting result is used as the data priority of the time-series framed data.
[0065] In an exemplary embodiment, the priority index of the time-series framed data of each edge device can be numerically determined, and the transmission process of each edge device can be set by setting a priority threshold: when the priority index is less than the priority threshold, the transmission process of the edge device corresponding to the priority index can be not set; when the priority index is greater than or equal to the priority threshold, the transmission process of the edge device corresponding to the priority index is stopped, and the time-series framed data is processed by the edge device alternative program; the priority threshold value mentioned in this application is 0.5.
[0066] Specifically, in step S202, the process of encrypting the time-series framed data is as follows:
[0067] The combination of time-series frame data and its feature vectors is used as the encrypted data.
[0068] Specifically, this application does not impose specific limitations on its encryption process. Those skilled in the art can freely set it using existing publicly available encryption algorithms, as long as the encryption requirements are met. In this application, the AMS algorithm can be used for encryption.
[0069] It is worth noting that the extraction of feature vectors from time-series framed data and the encryption of time-series framed data in this application are performed on the edge device that generates the time-series framed data.
[0070] Specifically, by extracting feature vectors from time-series framed data, key data attributes, such as the coefficient of variation and fluctuation entropy, can be accurately identified, providing a scientific basis for data prioritization. Reasonable priority allocation ensures the priority transmission of highly important data, avoiding network congestion and optimizing resource utilization. This step significantly improves data transmission efficiency and real-time performance, making it particularly suitable for high-concurrency scenarios.
[0071] Please continue reading. Figure 1 As shown, the data security protection method in cloud computing also includes:
[0072] Step S103: Obtain physical signal data of each edge device, determine the transmission trust status of each edge device, construct a spatiotemporal correlation matrix between each edge device based on the transmission trust status determination result, establish a transmission path by combining the construction correlation matrix between each edge device, and upload the time-series framed data of each edge device using the transmission path.
[0073] Please see Figure 3 The diagram shown is a flowchart illustrating the time-series framed data upload method provided in this application, including:
[0074] Step S301: Obtain physical signal data of each edge device; the physical signal data includes the Doppler frequency shift of each edge device relative to the observation position and the signal strength of each edge device, wherein the observation position is a fixed measurement position.
[0075] Please continue reading. Figure 3 As shown, the time-series framed data upload method further includes:
[0076] Step S302: Determine the transmission trust status of each edge device based on the physical signal data of each edge device.
[0077] Specifically, the process of determining the transmission trust status of each edge device is as follows:
[0078] Construct the trust index α(i) for each edge device, and set α(i) = cv[qd(i)];
[0079] In the formula, qd(i) represents the signal strength of the i-th edge device, and cv[qd(i)] represents the coefficient of variation of the signal strength;
[0080] The trust index of each edge device is compared with the preset trust threshold. Edge devices with a trust status greater than or equal to the preset trust threshold are judged as trustworthy edge devices, while edge devices with a trust status lower than the preset trust threshold are judged as risky edge devices.
[0081] Warning users about devices at risk.
[0082] Specifically, the preset trust threshold value described in this application is 0.15.
[0083] Please continue reading. Figure 3 As shown, the time-series framed data upload method further includes:
[0084] Step S303: Establish the spatiotemporal correlation matrix between trusted edge devices. The establishment process is as follows:
[0085] Obtain the spatial distance between each edge device, and denote the spatial distance between the i-th edge device and the k-th edge device as d(i,k). Then, use the result of {d(i,k)×[α(i)-preset trust threshold] / preset trust threshold×[α(k)-preset trust threshold] / preset trust threshold} as the transmission security coefficient between the i-th edge device and the k-th edge device; α(k) is the trust index of the h-th edge device;
[0086] A spatiotemporal correlation matrix between edge devices is constructed based on the transmission security coefficient between each edge device.
[0087] Please continue reading. Figure 3 As shown, the time-series framed data upload method further includes:
[0088] Step S303: Establish a transmission path by combining the spatiotemporal correlation matrix between each edge device, and upload the time-series framed data of each edge device using the transmission path.
[0089] Specifically, in step S303, the process of establishing the transmission path is as follows:
[0090] Retrieve the relay node closest to the i-th edge device, and use the edge device closest to that relay node as the target node;
[0091] Retrieve all non-repeating paths from the i-th edge device to the target node using the spatiotemporal correlation matrix between each edge device, and calculate the security index β(i,h) for each non-repeating path, where β(i,h) represents the security index of the h-th non-repeating path of the i-th edge device, and the value of β(i,h) is set to be the sum of the transmission security coefficients between each edge device traversed in the h-th non-repeating path of the i-th edge device.
[0092] The path with the highest security index among all non-repeating paths is selected as the transmission path.
[0093] Specifically, the non-repeating path described in this application is a path in which no duplicate edge devices appear.
[0094] Specifically, the process of uploading the time-series framed data of each edge device in step S303 is as follows:
[0095] When an edge device transmits encrypted time-series framed data to the next edge device, the time-series framed data to be transmitted in the next edge device is prioritized according to the data priority of the time-series framed data. The time-series framed data is then transmitted to the next edge device with the reordered priority, until it reaches the target node, from which it is transmitted to the cloud server.
[0096] Specifically, feature vectors are used to encrypt time-series framed data, enhancing data confidentiality and integrity. The encryption process is closely integrated with data characteristics, making security protection more targeted and effectively resisting the risks of tampering and leakage. Furthermore, even if the encrypted data is intercepted during transmission, it is difficult to decrypt, thus ensuring secure interaction of industrial data between the cloud and edge devices.
[0097] Please continue reading. Figure 1 As shown, the data security protection method in cloud computing also includes:
[0098] Step S104: Process the time-series frame data uploaded from each edge device, collect the cloud computing feedback duration, and then judge the real-time response status of each edge device based on the cloud computing feedback duration.
[0099] Specifically, in step S104, the process of processing the time-series framed data of each edge device is as follows:
[0100] The uploaded time-series frame data of each edge device is decrypted to obtain the time-series frame data and corresponding feature vectors of each edge device. The sequence of the uploaded time-series frame data is verified by the data sequence in the feature vector. If the verification fails, a data sequence alarm is triggered and the time-series frame data is deleted.
[0101] The transmission time of the time-series framed data is calculated using the timestamps of the time-series framed data in the feature vector and denoted as ct. The transmission delay status is judged by setting a transmission time threshold. When the transmission time is greater than the transmission time threshold, the delay is judged to be abnormal, and the edge device where the time-series framed data is located is marked. When the number of marks on the edge device is greater than 10, the trusted status of the edge device is updated to a contributing edge device. When the transmission time is less than or equal to the transmission time threshold, the delay is judged to be normal.
[0102] Specifically, the transmission time threshold mentioned in this application is 20ms.
[0103] Specifically, the process of determining the real-time response status of each edge device in step S104 is as follows:
[0104] The processed time-series framed data is input into the cloud server for cloud computing processing, and the cloud computing feedback time ft is collected. Then, the data response time XT of the edge device where the time-series framed data is located is calculated, and XT = ft + 2 × ct is set.
[0105] The data response time of the edge device containing the time-series framed data is compared with the preset response time. The real-time response status of the edge device when XT is greater than the preset response time is judged as an abnormal state, and the real-time response status of the edge device when XT is less than or equal to the preset response time is judged as a normal state.
[0106] Specifically, the preset response duration mentioned in this application is 100ms.
[0107] Specifically, by assessing the trust status of edge devices, trusted and risky devices can be dynamically identified, thereby preventing the involvement of insecure nodes. The spatiotemporal correlation matrix constructed based on the trust status further optimizes the transmission path, selecting the most secure path for data transmission. This method not only improves transmission efficiency but also significantly reduces the risk of data attack or loss.
[0108] Please continue reading. Figure 1 As shown, the data security protection method in cloud computing also includes:
[0109] Step S105: Update the framing process of the original time-series data of each edge device according to the real-time response status of each edge device.
[0110] Specifically, in step S105, the process of updating the framing of the original timing data of each edge device is as follows:
[0111] When the real-time response status of the edge device is normal, the framing process of the original data of the edge device is not updated.
[0112] When the real-time response status of the edge device is abnormal, update the set frame length of the original data of the edge device to ZC(i)', and set ZC(i)' = ZC(i) × exp{(preset response time - XT) / (XT + preset response time)}.
[0113] Specifically, by monitoring the cloud computing feedback time and the response status of edge devices, anomalies can be detected promptly and corresponding measures taken. Dynamically adjusting the framing process of raw data optimizes the real-time performance and stability of data transmission. This step ensures that the system maintains high efficiency under high load or network fluctuations, improving the adaptability and reliability of overall data security protection.
[0114] Please see Figure 4 As shown, it is a structural diagram of the data security protection device in cloud computing provided in this application, including:
[0115] The framing unit is used to collect raw time-series data from each edge device in real time and perform framing processing on the raw time-series data to obtain time-series framed data.
[0116] The encryption unit is used to extract the feature vector of the time-series framed data based on the time-series framed data, set the data priority of each edge device based on the feature vector of the time-series framed data, and encrypt the time-series framed data based on the feature vector of the time-series framed data.
[0117] The upload unit is used to determine the transmission trust status of each edge device, and then establish a transmission path based on the transmission trust status determination result, and upload the time-series framed data of each edge device based on the transmission path.
[0118] The response analysis unit is used to process the time-series frame data uploaded from each edge device, collect the cloud computing feedback time, and then judge the real-time response status of each edge device.
[0119] The update unit is used to update the framing process of the original time-series data of each edge device based on the real-time response status of each edge device.
[0120] The cloud computing data security protection device provided in this application embodiment can execute the cloud computing data security protection method provided in any embodiment of this application, and has the corresponding functional modules and beneficial effects of the execution method.
[0121] This application also provides a computer-readable storage medium, which is a tangible physical storage medium that can store the aforementioned computer program and various types of data used in the program; the physical storage medium includes, but is not limited to, existing physical storage media or combinations thereof, such as random access memory, read-only memory, optical disk, and hard disk.
[0122] Those skilled in the art will understand that all or some of the steps and systems in the methods disclosed above can be implemented as software, firmware, hardware, and suitable combinations thereof. Some or all of the physical components can be implemented as software executed by a processor, such as a central processing unit, digital signal processor, or microprocessor, or as hardware, or as an integrated circuit, such as an application-specific integrated circuit. Such software can be distributed on a computer-readable medium, which can include computer storage media (or non-transitory media) and communication media (or transient media). As is known to those skilled in the art, the term computer storage media includes volatile and non-volatile, removable and non-removable media implemented in any method or technique for storing information (such as computer-readable programs, data structures, program modules, or other data). Furthermore, it is known to those skilled in the art that communication media typically contain computer-readable programs, data structures, program modules, or other data in modulated data signals such as carrier waves or other transmission mechanisms, and can include any information delivery medium.
[0123] The technical solution of the present invention has been described above with reference to the preferred embodiments shown in the accompanying drawings. However, it will be readily understood by those skilled in the art that the scope of protection of the present invention is obviously not limited to these specific embodiments. Without departing from the principles of the present invention, those skilled in the art can make equivalent changes or substitutions to the relevant technical features, and the technical solutions after these changes or substitutions will all fall within the scope of protection of the present invention.
Claims
1. A data security protection method in cloud computing, characterized in that, The method comprises the following steps: Features of the time-series frame data are extracted, and the features of the time-series frame data are used to set the data priority of each edge device. The combination of the time-series frame data and the features of the time-series frame data is encrypted as encrypted data; The transmission trust state of each edge device is determined, and then a transmission path is established according to the determination result of the transmission trust state, and the time-series frame data of each edge device is uploaded through the transmission path; The uploaded time-series frame data of each edge device is processed, and the processed time-series frame data is input into a cloud server for cloud computing processing. The cloud computing feedback time is collected, and then the real-time response state of each edge device is determined, and the framing process of the original time-series data of each edge device is updated; Features of the time-series frame data of each edge device are extracted and set as F(i), and F(i)={cv(i),t(i),T(i),ZC(i),f(i)}, wherein cv(i) is the coefficient of variation of the time-series frame data of the i-th edge device, t(i) represents the data sequence of the time-series frame data of the i-th edge device, T(i) represents the timestamp of the time-series frame data of the i-th edge device, ZC(i) represents the set frame length of the time-series frame data of the i-th edge device, and f(i) represents the fluctuation entropy of the time-series frame data of the i-th edge device; A trusted index α(i) of each edge device is constructed; The trusted index of each edge device is compared with a preset trust threshold, and the trusted state of the edge device greater than or equal to the preset trust threshold is determined as a trusted edge device, and the trusted state of the edge device lower than the preset trust threshold is determined as a risk edge device.
2. The method of claim 1, wherein, The original time-series data of each edge device is collected in real time, and the original time-series data is framed to obtain time-series frame data; The original time-series data of each edge device is framed with a set frame length to obtain the time-series frame data of each edge device.
3. The method of claim 2, wherein, The priority index of the time-series frame data is calculated in a weighted manner, and is denoted as y(i), and y(i)=a1×cv(i)+a2×f(i), wherein a1 and a2 are fluctuation weight and entropy weight, respectively, and a1+a2=1; The priority index of the time-series frame data of each edge device is sorted in descending order, and the sorting result is used as the data priority of the time-series frame data.
4. The method of claim 3, wherein, A space-time correlation matrix between trusted edge devices is established, and the establishment process is as follows: The spatial distance between each edge device is obtained, and the spatial distance between the i-th edge device and the k-th edge device is denoted as d(i,k), and then the transmission security coefficient between the i-th edge device and the k-th edge device is obtained by {d(i,k)×[α(i)-preset trust threshold] / preset trust threshold×[α(k)-preset trust threshold] / preset trust threshold}; The space-time correlation matrix between each edge device is constructed according to the transmission security coefficient between each edge device.
5. The method of claim 4, wherein, The nearest relay node to the i-th edge device is searched, and the nearest edge device of the relay node is taken as a target node; Retrieving all the non-repeating paths of the i-th edge device to the target node according to the space-time correlation matrix between each edge device, and calculating the security index β(i, h) of each non-repeating path, wherein β(i, h) represents the security index of the h-th non-repeating path of the i-th edge device, and the value of β(i, h) is set as the sum of the transmission security factors between each edge device passed through in the h-th non-repeating path of the i-th edge device; Selecting the non-repeating path with the maximum security index among the security indexes of each non-repeating path as the transmission path; When the edge device transmits the encrypted time sequence frame data to the next edge device, the time sequence frame data is prioritized and rearranged in the next edge device according to the data priority of the time sequence frame data, and the time sequence frame data is transmitted to the next edge device according to the rearranged priority, until the target node is reached, and the target node transmits to the cloud server.
6. The method of claim 5, wherein, The transmission time of the time sequence frame data is calculated according to the timestamp of the time sequence frame data in the feature vector, and is recorded as ct, the processed time sequence frame data is input into the cloud server for cloud computing processing, and the cloud computing feedback time ft is collected, and the data response time XT of the edge device where the time sequence frame data is located is calculated, and XT is set as ft+2×ct; The data response time of the edge device where the time sequence frame data is located is compared with the preset response time, and the real-time response state of the edge device when XT is greater than the preset response time is judged as an abnormal state, and the real-time response state of the edge device when XT is less than or equal to the preset response time is judged as a normal state; When the real-time response state of the edge device is normal, the original data of the edge device is not updated; When the real-time response state of the edge device is abnormal, the original data of the edge device is updated to ZC(i)'.
7. A data security protection device in cloud computing, applied to the data security protection method in cloud computing according to any one of claims 1-6, characterized in that, It comprises: a frame unit for collecting real-time original time sequence data of each edge device and performing frame processing on the original time sequence data to obtain time sequence frame data; an encryption unit for extracting a feature vector of the time sequence frame data according to the time sequence frame data, setting the data priority of each edge device according to the feature vector of the time sequence frame data, and encrypting the time sequence frame data according to the feature vector of the time sequence frame data; an uploading unit for judging the transmission trust state of each edge device, establishing a transmission path according to the judgment result of the transmission trust state, and uploading the time sequence frame data of each edge device according to the transmission path; a response analysis unit for processing the uploaded time sequence frame data of each edge device, collecting the cloud computing feedback time, and judging the real-time response state of each edge device; an updating unit for updating the frame process of the original time sequence data of each edge device according to the real-time response state of each edge device.
8. A computer-readable storage medium, characterized in that, The computer readable storage medium stores a computer program, wherein the computer program is used to control the electronic device where the computer readable storage medium is located to execute the cloud computing data security protection method in any one of claims 1-6 when running.
Citation Information
Patent Citations
Acoustic data storage and retrieval method combined with computer cloud computing
CN120162458A
Multi-source heterogeneous data fusion method and system based on cloud computing
CN120524422A