Distributed data storage method and system based on intelligent terminal

By collecting the status and historical behavior logs of security modules on smart terminals, using an improved analytic hierarchy process to divide nodes and generate a dynamic key matrix, and encrypting sensitive data, the problem of data leakage in distributed data storage on smart terminals is solved, achieving efficient and secure distributed data storage.

CN121967439APending Publication Date: 2026-05-01JIANGXI XIANGYANG CLOUD NETWORK TECHNOLOGY CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
JIANGXI XIANGYANG CLOUD NETWORK TECHNOLOGY CO LTD
Filing Date
2025-11-25
Publication Date
2026-05-01

AI Technical Summary

Technical Problem

Existing distributed data storage technologies based on smart terminals pose a risk of data leakage. They lack copy control and dynamic key management based on terminal trust levels, and the transmission encryption schemes are not adapted to the terminal's computing power. Access control relies on account passwords or simple device identifiers, making it difficult to prevent unauthorized access and trace the source of leakage.

Method used

By collecting the security module status, system integrity, and historical behavior logs of smart terminals, an improved analytic hierarchy process is used to output a trust score, which is then divided into core trusted nodes, ordinary trusted nodes, and trusted nodes to be verified. A dynamic key matrix is ​​generated to encrypt sensitive data, and the data is distributed and stored based on the node trust level and the data sensitivity level.

Benefits of technology

It achieves accurate and effective encrypted storage of distributed data, avoids data leakage, improves data storage efficiency and security, has strong adaptability, and reduces the risk of data leakage.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121967439A_ABST
    Figure CN121967439A_ABST
Patent Text Reader

Abstract

The invention provides a distributed data storage method and system based on an intelligent terminal, and the method comprises the steps: collecting a security module state, system integrity and a historical behavior log of the intelligent terminal, and outputting a corresponding credible score through an improved analytic hierarchy process; the intelligent terminal is correspondingly divided into a core credible node, a common credible node and a credible node to be verified according to the credible score, data content and data attributes of distributed data are collected, and sensitive data and non-sensitive data are divided according to the data content and the attributes; collecting a target data set contained in the sensitive data, and generating a dynamic secret key matrix corresponding to the target data set through the core trusted node; and performing encryption processing on the sensitive data through the dynamic secret key matrix so as to complete storage of the distributed data. The encryption storage efficiency of the distributed data can be effectively improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of data storage technology, and in particular to a distributed data storage method and system based on smart terminals. Background Technology

[0002] With the improvement of computing power, storage, and communication capabilities of smart terminals, distributed data storage technology based on smart terminals has developed rapidly due to its ability to overcome the limitations of single terminals and enable multi-terminal collaborative access. It has been widely used in scenarios such as cross-terminal data sharing. Unlike traditional server clusters, this technology faces security challenges due to its characteristics such as heterogeneous nodes, limited resources, network fluctuations, and susceptibility to offline events. Among these challenges, the risk of data leakage directly relates to user privacy and data security, becoming a core bottleneck for the large-scale application of the technology.

[0003] Existing protection measures are mostly migrated from server cluster solutions, and their insufficient adaptability leads to protection failure: First, multi-copy storage expands the exposure surface to ensure availability, but lacks copy control based on terminal trust level and dynamic key management, and key leakage can easily lead to the loss of all copies; Second, transmission encryption schemes are not adapted to terminal computing power, traditional solutions cause a surge in latency and power consumption, while lightweight solutions simplify the encryption process and introduce the risk of eavesdropping; Third, access control relies on account passwords or simple device identifiers, does not utilize terminal biometrics, hardware security modules and other resources, and lacks access auditing capabilities, making it difficult to prevent unauthorized access and trace the source of leakage.

[0004] The aforementioned deficiencies severely hinder the adoption of the technology, posing risks of privacy, business, and sensor data leakage in consumer, enterprise, and IoT scenarios. Existing solutions either consume excessive terminal resources due to complex processes or sacrifice protective effectiveness by simplifying security mechanisms, failing to create a comprehensive solution that balances security, lightweight design, and adaptability. Therefore, designing a data leakage protection solution tailored to the characteristics of smart terminals, addressing issues such as multiple copies exposed, insufficient transmission encryption, and inadequate access control, has become an urgent need in this field. Summary of the Invention

[0005] Therefore, the purpose of this invention is to provide a distributed data storage method and system based on smart terminals to solve the problem of distributed data leakage risk in the prior art, which reduces data security.

[0006] The first aspect of the present invention proposes: A distributed data storage method based on a smart terminal, wherein the method includes: Collect the security module status, system integrity, and historical behavior logs of smart terminals, and output the corresponding reliability score through an improved analytic hierarchy process. Based on the trust score, the smart terminal is divided into core trusted nodes, ordinary trusted nodes and trusted nodes to be verified. The data content and data attributes of the distributed data are collected to classify sensitive data and non-sensitive data according to the data content and the attributes. Collect the target dataset contained in the sensitive data, and generate a dynamic key matrix corresponding to the target dataset through the core trusted node; The sensitive data is encrypted using the dynamic key matrix to complete the storage of the distributed data.

[0007] The beneficial effects of this invention are as follows: By collecting specific parameters of the smart terminal, the specific working status of the terminal can be known. Based on this, in order to facilitate the subsequent storage of distributed data, the trust score of each smart terminal is calculated, and several types of nodes are correspondingly divided. Based on this, specific parameters of the distributed database are collected, and a dynamic key matrix for subsequent encrypted storage is generated. Sensitive data can be encrypted using this dynamic key matrix, thereby accurately and effectively completing the encrypted storage of distributed data, avoiding the leakage of distributed data, and improving data storage efficiency.

[0008] Furthermore, the step of outputting the corresponding credibility score through the improved analytic hierarchy process includes: With terminal trustworthiness as the target layer, the security module status, the system integrity, and the historical behavior logs as the criteria layer, data detection indicators adapted to the smart terminal are output. Each of the data detection indicators is weighted and fused using a trusted root verification method to output a corresponding dynamic weight vector. Calculate the initial score corresponding to the dynamic weight vector, perform dynamic verification on the initial score, and output the reliable score.

[0009] Furthermore, the step of dynamically validating the initial score to output the reliable score includes: The actual operating parameters of the intelligent terminal in the current time window are collected, and a dynamic verification benchmark library is constructed by combining the historical fluctuation threshold of the criterion layer indicators to generate a dynamic verification threshold range that is adapted to the current scenario. The initial score is compared with the dynamic verification threshold range. If it is within the range, it is directly marked as a candidate reliable score. If it is outside the range, it is re-verified by the root of confidence to generate an anomaly correction coefficient. The initial score is then adjusted accordingly and marked as a candidate reliable score. Collect the distributed storage task attributes to be assigned to the smart terminal, calculate the fit score between the candidate trust score and the task attributes, and if the fit score is greater than a preset score threshold, then the corresponding trust score is determined.

[0010] Furthermore, the step of generating a dynamic key matrix corresponding to the target dataset through the core trusted node includes: The feature parameters and state parameters of the target dataset are collected by the trusted node to create a corresponding multidimensional feature vector. The basic key matrix is ​​generated by iterative operation through an improved chaotic mapping algorithm. The core trusted node generates corresponding timestamp factors and access subject permission factors, and the dynamic adjustment coefficients are obtained by weighted Markov chain fusion. The basic key matrix is ​​optimized using the dynamic adjustment coefficients to generate the dynamic key matrix.

[0011] Furthermore, the step of optimizing the basic key matrix using the dynamic adjustment coefficients to generate the dynamic key matrix includes: By analyzing the row and column sparsity, eigenvalue distribution, and weight dimension of the dynamically adjusted coefficients of the basic key matrix through the core trusted node, the basic key matrix is ​​divided into sensitive matrix blocks and ordinary matrix blocks using a matrix partitioning algorithm. Collect the actual operating environment parameters of the core trusted node; Based on the actual operating environment parameters, the sensitive matrix block is iteratively fine-tuned using a PID control algorithm to generate the dynamic key matrix.

[0012] Furthermore, the step of encrypting the sensitive data using the dynamic key matrix to complete the distributed data storage includes: The core trusted node parses the sensitivity level of the fields of the sensitive data and decomposes the dynamic key matrix into a multi-level sub-key matrix that matches the level. A differentiated strategy is used to encrypt the multi-level key matrix field by field to generate encrypted data packets and attach encryption identifiers; Establish a mapping relationship between field sensitivity level and node trust level, and distribute the encrypted data packets based on the mapping relationship.

[0013] Furthermore, the step of distributing the encrypted data packets based on the mapping relationship includes: Based on the mapping relationship, suitable candidate storage nodes are selected, and the load rate, network latency and transmission success rate of each candidate storage node are collected to construct the corresponding node dynamic adaptation matrix. The storage adaptation score of each candidate storage node is calculated using the entropy weight method, and the encrypted data packet is dynamically fragmented according to the field sensitivity level. A corresponding sorting list is generated based on the storage adaptation score. Each dynamic shard is then encrypted using the node dynamic adaptation matrix based on the sorting list to complete the corresponding distributed storage.

[0014] The second aspect of the present invention proposes: A distributed data storage system based on a smart terminal, wherein the system comprises: The data acquisition module is used to collect the security module status, system integrity, and historical behavior logs of smart terminals, and outputs the corresponding reliability score through an improved analytic hierarchy process. The segmentation module is used to segment the smart terminal into core trusted nodes, ordinary trusted nodes and trusted nodes to be verified according to the trust score, and to collect the data content and data attributes of distributed data to segment sensitive data and non-sensitive data according to the data content and the attributes. The generation module is used to collect the target dataset contained in the sensitive data and generate a dynamic key matrix corresponding to the target dataset through the core trusted node; An encryption module is used to encrypt the sensitive data using the dynamic key matrix to complete the storage of the distributed data.

[0015] Furthermore, the acquisition module is specifically used for: With terminal trustworthiness as the target layer, the security module status, the system integrity, and the historical behavior logs as the criteria layer, data detection indicators adapted to the smart terminal are output. Each of the data detection indicators is weighted and fused using a trusted root verification method to output a corresponding dynamic weight vector. Calculate the initial score corresponding to the dynamic weight vector, perform dynamic verification on the initial score, and output the reliable score.

[0016] Furthermore, the acquisition module is specifically used for: The actual operating parameters of the intelligent terminal in the current time window are collected, and a dynamic verification benchmark library is constructed by combining the historical fluctuation threshold of the criterion layer indicators to generate a dynamic verification threshold range that is adapted to the current scenario. The initial score is compared with the dynamic verification threshold range. If it is within the range, it is directly marked as a candidate reliable score. If it is outside the range, it is re-verified by the root of confidence to generate an anomaly correction coefficient. The initial score is then adjusted accordingly and marked as a candidate reliable score. Collect the distributed storage task attributes to be assigned to the smart terminal, calculate the fit score between the candidate trust score and the task attributes, and if the fit score is greater than a preset score threshold, then the corresponding trust score is determined.

[0017] Furthermore, the generation module is specifically used for: The feature parameters and state parameters of the target dataset are collected by the trusted node to create a corresponding multidimensional feature vector. The basic key matrix is ​​generated by iterative operation through an improved chaotic mapping algorithm. The core trusted node generates corresponding timestamp factors and access subject permission factors, and the dynamic adjustment coefficients are obtained by weighted Markov chain fusion. The basic key matrix is ​​optimized using the dynamic adjustment coefficients to generate the dynamic key matrix.

[0018] Furthermore, the generation module is specifically used for: By analyzing the row and column sparsity, eigenvalue distribution, and weight dimension of the dynamically adjusted coefficients of the basic key matrix through the core trusted node, the basic key matrix is ​​divided into sensitive matrix blocks and ordinary matrix blocks using a matrix partitioning algorithm. Collect the actual operating environment parameters of the core trusted node; Based on the actual operating environment parameters, the sensitive matrix block is iteratively fine-tuned using a PID control algorithm to generate the dynamic key matrix.

[0019] Furthermore, the encryption module is specifically used for: The core trusted node parses the sensitivity level of the fields of the sensitive data and decomposes the dynamic key matrix into a multi-level sub-key matrix that matches the level. A differentiated strategy is used to encrypt the multi-level key matrix field by field to generate encrypted data packets and attach encryption identifiers; Establish a mapping relationship between field sensitivity level and node trust level, and distribute the encrypted data packets based on the mapping relationship.

[0020] Furthermore, the encryption module is specifically used for: Based on the mapping relationship, suitable candidate storage nodes are selected, and the load rate, network latency and transmission success rate of each candidate storage node are collected to construct the corresponding node dynamic adaptation matrix. The storage adaptation score of each candidate storage node is calculated using the entropy weight method, and the encrypted data packet is dynamically fragmented according to the field sensitivity level. A corresponding sorting list is generated based on the storage adaptation score. Each dynamic shard is then encrypted using the node dynamic adaptation matrix based on the sorting list to complete the corresponding distributed storage.

[0021] The third aspect of the present invention proposes: A computer includes a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor, when executing the computer program, implements the distributed data storage method based on a smart terminal as described above.

[0022] The fourth aspect of the present invention proposes: A readable storage medium having a computer program stored thereon, wherein the program, when executed by a processor, implements the distributed data storage method based on a smart terminal as described above.

[0023] Additional aspects and advantages of the invention will be set forth in part in the description which follows, and in part will be obvious from the description, or may be learned by practice of the invention. Attached Figure Description

[0024] Figure 1 A flowchart illustrating the distributed data storage method based on a smart terminal provided in the first embodiment of the present invention; Figure 2 This is a structural block diagram of a distributed data storage system based on a smart terminal provided in the third embodiment of the present invention.

[0025] The following detailed description, in conjunction with the accompanying drawings, will further illustrate the present invention. Detailed Implementation

[0026] To facilitate understanding of the present invention, a more complete description will be given below with reference to the accompanying drawings. Several embodiments of the invention are illustrated in the drawings. However, the invention can be implemented in many different forms and is not limited to the embodiments described herein. Rather, these embodiments are provided so that this disclosure will be thorough and complete.

[0027] It should be noted that when a component is said to be "fixed to" another component, it can be directly on the other component or there may be an intervening component. When a component is said to be "connected to" another component, it can be directly connected to the other component or there may be an intervening component. The terms "vertical," "horizontal," "left," "right," and similar expressions used in this document are for illustrative purposes only.

[0028] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this invention pertains. The terminology used herein in the description of the invention is for the purpose of describing particular embodiments only and is not intended to be limiting of the invention. The term "and / or" as used herein includes any and all combinations of one or more of the associated listed items.

[0029] Please see Figure 1 The figure shows a distributed data storage method based on a smart terminal provided in the first embodiment of the present invention. The distributed data storage method based on a smart terminal provided in this embodiment can effectively avoid the leakage of distributed data and improve storage efficiency accordingly.

[0030] Specifically, the first embodiment of the present invention provides: A distributed data storage method based on a smart terminal, wherein the method includes: Step S10: Collect the security module status, system integrity, and historical behavior logs of the smart terminal, and output the corresponding credibility score through the improved analytic hierarchy process. It's important to note that the first step in obtaining the trust score involves collecting three core indicators from the smart terminal: security module status (e.g., security chip operating status, encryption module effectiveness), system integrity (e.g., system file integrity verification results, presence of malicious tampering traces), and historical behavior logs (e.g., past data processing compliance, abnormal operation records). An improved analytic hierarchy process (AHP) is used to comprehensively analyze these indicators, ultimately outputting a trust score reflecting the terminal's trustworthiness. This facilitates subsequent processing.

[0031] Step S20: Based on the trust score, the smart terminal is divided into core trusted nodes, ordinary trusted nodes and trusted nodes to be verified. The data content and data attributes of the distributed data are collected to classify sensitive data and non-sensitive data according to the data content and the attributes. It should be noted that the next step is the classification stage. Based on the trust score, the terminals are divided into core trusted nodes (highest level of trust), ordinary trusted nodes (medium level of trust), and unverified trusted nodes (trust level to be confirmed). Simultaneously, distributed data is classified, combining data content (such as whether it contains personal privacy, trade secrets, etc.) and data attributes (such as data importance level, access frequency, etc.) to distinguish between sensitive and non-sensitive data. This facilitates subsequent processing.

[0032] Step S30: Collect the target dataset contained in the sensitive data, and generate a dynamic key matrix corresponding to the target dataset through the core trusted node; It's worth noting that the subsequent step is key generation. For the target dataset within the sensitive data, the core trusted node with the highest security generates a corresponding dynamic key matrix to ensure key security and specificity, facilitating subsequent processing.

[0033] Step S40: Encrypt the sensitive data using the dynamic key matrix to complete the storage of the distributed data.

[0034] It's worth noting that the final step, encrypted storage, utilizes a generated dynamic key matrix to encrypt sensitive data, completing the overall distributed data storage. This framework ensures the security and reliability of distributed storage through a logical chain of "terminal trust assessment - data classification - security encryption - distributed storage," facilitating subsequent processing.

[0035] Second Embodiment Furthermore, the step of outputting the corresponding credibility score through the improved analytic hierarchy process includes: With terminal trustworthiness as the target layer, the security module status, the system integrity, and the historical behavior logs as the criteria layer, data detection indicators adapted to the smart terminal are output. Each of the data detection indicators is weighted and fused using a trusted root verification method to output a corresponding dynamic weight vector. Calculate the initial score corresponding to the dynamic weight vector, perform dynamic verification on the initial score, and output the reliable score.

[0036] It's important to note that the process begins with constructing a hierarchical model. "Terminal trustworthiness" is used as the target layer for evaluation, while the aforementioned security module status, system integrity, and historical behavior logs serve as the criterion layer. This hierarchical division outputs data detection indicators adapted to the smart terminal trustworthiness assessment, making the evaluation indicators more targeted. Next, a trusted root verification mechanism is introduced to weight and fuse the indicators. The trusted root, as the fundamental source of trust for terminal security, ensures the security of weight allocation through its verification results. This mechanism weights each data detection indicator, outputting a dynamic weight vector. Compared to the fixed weights of traditional analytic hierarchy process (AHP), the dynamic weight vector better adapts to changes in terminal status. Finally, a scoring calibration is performed. An initial score corresponding to the dynamic weight vector is first calculated, and then the initial score undergoes dynamic verification to eliminate the limitations of static scoring. The final output is a trust score that accurately reflects the current trustworthiness status of the terminal, facilitating subsequent processing.

[0037] Furthermore, the step of dynamically validating the initial score to output the reliable score includes: The actual operating parameters of the intelligent terminal in the current time window are collected, and a dynamic verification benchmark library is constructed by combining the historical fluctuation threshold of the criterion layer indicators to generate a dynamic verification threshold range that is adapted to the current scenario. The initial score is compared with the dynamic verification threshold range. If it is within the range, it is directly marked as a candidate reliable score. If it is outside the range, it is re-verified by the root of confidence to generate an anomaly correction coefficient. The initial score is then adjusted accordingly and marked as a candidate reliable score. Collect the distributed storage task attributes to be assigned to the smart terminal, calculate the fit score between the candidate trust score and the task attributes, and if the fit score is greater than a preset score threshold, then the corresponding trust score is determined.

[0038] It should be noted that, firstly, a dynamic verification benchmark is constructed by collecting the actual operating parameters of the smart terminal within the current time window (such as CPU utilization, memory usage, and security module response speed). This data is then combined with the historical fluctuation thresholds of each indicator in the criterion layer (i.e., the normal fluctuation range of indicators in past operations) to build a dynamic verification benchmark library. Based on this benchmark library, a dynamic verification threshold range adapted to the current operating scenario is generated, making the verification standard more closely aligned with the terminal's real-time state. Next, an initial score comparison and adjustment is performed. The initial score is compared with the dynamic verification threshold range. If the initial score is within the range, it indicates that it reflects the terminal's current trustworthiness and is directly marked as a candidate trustworthy score. If it is outside the range, it indicates that the initial score has a deviation, and an anomaly correction coefficient needs to be generated through re-verification using the root of trust. This coefficient is then used to adjust the initial score before it is marked as a candidate trustworthy score. Finally, task adaptability verification is performed. The attributes of the distributed storage tasks to be assigned to the smart terminal (such as task data volume, security requirement level, real-time requirements, etc.) are collected, and the adaptability score between the candidate trust score and the task attributes is calculated. If the adaptability score exceeds a preset threshold, it indicates that the candidate score matches the task requirements and is ultimately determined as the trust score. This step ensures the adaptability of the trust score to the actual storage task, facilitating subsequent processing.

[0039] Furthermore, the step of generating a dynamic key matrix corresponding to the target dataset through the core trusted node includes: The feature parameters and state parameters of the target dataset are collected by the trusted node to create a corresponding multidimensional feature vector. The basic key matrix is ​​generated by iterative operation through an improved chaotic mapping algorithm. The core trusted node generates corresponding timestamp factors and access subject permission factors, and the dynamic adjustment coefficients are obtained by weighted Markov chain fusion. The basic key matrix is ​​optimized using the dynamic adjustment coefficients to generate the dynamic key matrix.

[0040] It should be noted that the process begins with generating a basic key matrix. The core trusted node first collects feature parameters (such as data format, data length, and distribution of sensitive fields) and state parameters (such as data generation time and update frequency) of the target dataset. Based on these parameters, a multi-dimensional feature vector is created, and then iterative calculations are performed using an improved chaotic mapping algorithm. The chaotic mapping algorithm is sensitive to initial conditions and exhibits strong randomness; its improvement further enhances key security. The basic key matrix is ​​generated through iterative calculations. Next, dynamic adjustment coefficients are generated. The core trusted node itself generates a timestamp factor (reflecting the time characteristics of key generation to ensure timeliness) and an access subject permission factor (reflecting the accessor's permission level to ensure controllable key usage permissions). A weighted Markov chain is used to fuse these two factors. Markov chains effectively handle state transition problems in random processes. After weighting, dynamic adjustment coefficients are generated based on the importance of the two factors, allowing the coefficients to adapt to changes in time and permissions. Finally, a dynamic key matrix is ​​generated through optimization. The dynamic adjustment coefficients are used to optimize the basic key matrix, eliminating the static limitations of the basic key and generating a dynamic key matrix that combines security and dynamic adaptability for subsequent processing.

[0041] Furthermore, the step of optimizing the basic key matrix using the dynamic adjustment coefficients to generate the dynamic key matrix includes: By analyzing the row and column sparsity, eigenvalue distribution, and weight dimension of the dynamically adjusted coefficients of the basic key matrix through the core trusted node, the basic key matrix is ​​divided into sensitive matrix blocks and ordinary matrix blocks using a matrix partitioning algorithm. Collect the actual operating environment parameters of the core trusted node; Based on the actual operating environment parameters, the sensitive matrix block is iteratively fine-tuned using a PID control algorithm to generate the dynamic key matrix.

[0042] It's important to note that the process begins with matrix partitioning. The core trusted node analyzes key characteristics of the basic key matrix, including row and column sparsity (the distribution of empty or invalid values), eigenvalue distribution (reflecting the matrix's mathematical properties), and the weighting dimensions of the dynamic adjustment coefficients (clarifying the impact of each adjustment factor). Using a matrix partitioning algorithm, the basic key matrix is ​​divided into sensitive matrix blocks (the part critical to encryption security) and ordinary matrix blocks (the part assisting encryption), achieving differentiated optimization. Next, environmental parameters are collected, including the actual operating environment parameters of the core trusted node, such as operating temperature, network stability, and hardware resource usage. These parameters directly affect the stability and security of key generation, providing an environmental basis for optimization. Finally, iterative fine-tuning is performed. Based on the collected actual operating environment parameters, a PID control algorithm is used to iteratively fine-tune the sensitive matrix blocks. The PID control algorithm enables precise adjustment of the controlled object. Through the iterative process, the sensitive matrix blocks are adapted to the operating environment of the core trusted node, ultimately generating a dynamic key matrix. This ensures that the key maintains security while possessing good operational adaptability, facilitating subsequent processing.

[0043] Furthermore, the step of encrypting the sensitive data using the dynamic key matrix to complete the distributed data storage includes: The core trusted node parses the sensitivity level of the fields of the sensitive data and decomposes the dynamic key matrix into a multi-level sub-key matrix that matches the level. A differentiated strategy is used to encrypt the multi-level key matrix field by field to generate encrypted data packets and attach encryption identifiers; Establish a mapping relationship between field sensitivity level and node trust level, and distribute the encrypted data packets based on the mapping relationship.

[0044] It's important to note that the process begins with key-data level matching. Core trusted nodes parse the sensitivity levels of sensitive data fields (e.g., core sensitive fields, general sensitive fields, low-sensitivity fields, etc.). Based on these sensitivity levels, the dynamic key matrix is ​​broken down into multi-level sub-key matrices matching the levels, ensuring that different sensitivity levels correspond to different security levels of keys, achieving fine-grained encryption. Next, differentiated encryption is implemented. For fields with different sensitivity levels, a differentiated encryption strategy matching the sub-key matrix is ​​used for field-by-field encryption. After encryption, an encrypted data packet is generated and an encryption identifier is attached. This identifier identifies the encryption level, key information, and other key content of the data packet, facilitating subsequent storage and decryption. Finally, a mapping is established and distributed storage is implemented. A mapping relationship is constructed between field sensitivity levels and node trust levels (e.g., core sensitive fields correspond to core trusted nodes, general sensitive fields correspond to ordinary trusted nodes). Based on this mapping relationship, encrypted data packets are distributed to nodes of the corresponding trust levels for distributed storage, achieving precise matching between data sensitivity levels and node security levels, improving storage security, and facilitating subsequent processing.

[0045] Furthermore, the step of distributing the encrypted data packets based on the mapping relationship includes: Based on the mapping relationship, suitable candidate storage nodes are selected, and the load rate, network latency and transmission success rate of each candidate storage node are collected to construct the corresponding node dynamic adaptation matrix. The storage adaptation score of each candidate storage node is calculated using the entropy weight method, and the encrypted data packet is dynamically fragmented according to the field sensitivity level. A corresponding sorting list is generated based on the storage adaptation score. Each dynamic shard is then encrypted using the node dynamic adaptation matrix based on the sorting list to complete the corresponding distributed storage.

[0046] It's important to note that the process begins with screening candidate nodes and constructing an adaptation matrix. Based on the mapping between field sensitivity levels and node trust levels, suitable candidate storage nodes are selected. Simultaneously, key operational metrics for each candidate node are collected, including load rate (reflecting the node's current workload), network latency (reflecting data transmission speed), and transmission success rate (reflecting data transmission reliability). Based on these metrics, a dynamic node adaptation matrix is ​​constructed to comprehensively reflect the storage capabilities of the candidate nodes. Next, scores are calculated and data is sharded. The entropy weight method is used to calculate the storage adaptation score for each candidate storage node. This method objectively determines weights based on the dispersion of metrics, ensuring the fairness and accuracy of the scoring. Simultaneously, encrypted data packets are dynamically sharded according to field sensitivity levels, so that different shards correspond to different storage needs. Finally, storage allocation is performed. A sorted list of candidate nodes is generated based on their storage adaptation scores, with higher-scoring nodes having higher storage priority. Based on this sorted list and the dynamic node adaptation matrix, each dynamic shard is encrypted again (double encryption enhances security) and allocated to the corresponding node to complete distributed storage, achieving optimized storage resource configuration and secure data storage for subsequent processing.

[0047] Please see Figure 2 The third embodiment of the present invention provides: A distributed data storage system based on a smart terminal, wherein the system comprises: The data acquisition module is used to collect the security module status, system integrity, and historical behavior logs of smart terminals, and outputs the corresponding reliability score through an improved analytic hierarchy process. The segmentation module is used to segment the smart terminal into core trusted nodes, ordinary trusted nodes and trusted nodes to be verified according to the trust score, and to collect the data content and data attributes of distributed data to segment sensitive data and non-sensitive data according to the data content and the attributes. The generation module is used to collect the target dataset contained in the sensitive data and generate a dynamic key matrix corresponding to the target dataset through the core trusted node; An encryption module is used to encrypt the sensitive data using the dynamic key matrix to complete the storage of the distributed data.

[0048] Furthermore, the acquisition module is specifically used for: With terminal trustworthiness as the target layer, the security module status, the system integrity, and the historical behavior logs as the criteria layer, data detection indicators adapted to the smart terminal are output. Each of the data detection indicators is weighted and fused using a trusted root verification method to output a corresponding dynamic weight vector. Calculate the initial score corresponding to the dynamic weight vector, perform dynamic verification on the initial score, and output the reliable score.

[0049] Furthermore, the acquisition module is specifically used for: The actual operating parameters of the intelligent terminal in the current time window are collected, and a dynamic verification benchmark library is constructed by combining the historical fluctuation threshold of the criterion layer indicators to generate a dynamic verification threshold range that is adapted to the current scenario. The initial score is compared with the dynamic verification threshold range. If it is within the range, it is directly marked as a candidate reliable score. If it is outside the range, it is re-verified by the root of confidence to generate an anomaly correction coefficient. The initial score is then adjusted accordingly and marked as a candidate reliable score. Collect the distributed storage task attributes to be assigned to the smart terminal, calculate the fit score between the candidate trust score and the task attributes, and if the fit score is greater than a preset score threshold, then the corresponding trust score is determined.

[0050] Furthermore, the generation module is specifically used for: The feature parameters and state parameters of the target dataset are collected by the trusted node to create a corresponding multidimensional feature vector. The basic key matrix is ​​generated by iterative operation through an improved chaotic mapping algorithm. The core trusted node generates corresponding timestamp factors and access subject permission factors, and the dynamic adjustment coefficients are obtained by weighted Markov chain fusion. The basic key matrix is ​​optimized using the dynamic adjustment coefficients to generate the dynamic key matrix.

[0051] Furthermore, the generation module is specifically used for: By analyzing the row and column sparsity, eigenvalue distribution, and weight dimension of the dynamically adjusted coefficients of the basic key matrix through the core trusted node, the basic key matrix is ​​divided into sensitive matrix blocks and ordinary matrix blocks using a matrix partitioning algorithm. Collect the actual operating environment parameters of the core trusted node; Based on the actual operating environment parameters, the sensitive matrix block is iteratively fine-tuned using a PID control algorithm to generate the dynamic key matrix.

[0052] Furthermore, the encryption module is specifically used for: The core trusted node parses the sensitivity level of the fields of the sensitive data and decomposes the dynamic key matrix into a multi-level sub-key matrix that matches the level. A differentiated strategy is used to encrypt the multi-level key matrix field by field to generate encrypted data packets and attach encryption identifiers; Establish a mapping relationship between field sensitivity level and node trust level, and distribute the encrypted data packets based on the mapping relationship.

[0053] Furthermore, the encryption module is specifically used for: Based on the mapping relationship, suitable candidate storage nodes are selected, and the load rate, network latency and transmission success rate of each candidate storage node are collected to construct the corresponding node dynamic adaptation matrix. The storage adaptation score of each candidate storage node is calculated using the entropy weight method, and the encrypted data packet is dynamically fragmented according to the field sensitivity level. A corresponding sorting list is generated based on the storage adaptation score. Each dynamic shard is then encrypted using the node dynamic adaptation matrix based on the sorting list to complete the corresponding distributed storage.

[0054] The fourth embodiment of the present invention provides a computer, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the computer program to implement the distributed data storage method based on a smart terminal as described above.

[0055] The fifth embodiment of the present invention provides: a readable storage medium having a computer program stored thereon, wherein the program, when executed by a processor, implements the distributed data storage method based on a smart terminal as described above.

[0056] In summary, the distributed data storage method and system based on smart terminals provided in the above embodiments of the present invention can effectively prevent the leakage of distributed data and improve data storage efficiency accordingly.

[0057] It should be noted that the above modules can be functional modules or program modules, and can be implemented through software or hardware. For modules implemented through hardware, the above modules can reside in the same processor; or the above modules can be located in different processors in any combination.

[0058] The logic and / or steps represented in the flowchart or otherwise described herein, for example, can be considered as a sequenced list of executable instructions for implementing logical functions, and can be embodied in any computer-readable medium for use by, or in conjunction with, an instruction execution system, apparatus, or device (such as a computer-based system, a processor-including system, or other system that can fetch and execute instructions from, an instruction execution system, apparatus, or device). For the purposes of this specification, "computer-readable medium" can be any means that can contain, store, communicate, propagate, or transmit programs for use by, or in conjunction with, an instruction execution system, apparatus, or device.

[0059] More specific examples of computer-readable media (a non-exhaustive list) include: electrical connections (electronic devices) having one or more wires, portable computer disk drives (magnetic devices), random access memory (RAM), read-only memory (ROM), erasable and editable read-only memory (EPROM or flash memory), fiber optic devices, and portable optical disc read-only memory (CDROM). Furthermore, computer-readable media can even be paper or other suitable media on which the program can be printed, because the program can be obtained electronically, for example, by optically scanning the paper or other medium, followed by editing, interpreting, or otherwise processing as necessary, and then stored in computer memory.

[0060] It should be understood that various parts of the present invention can be implemented in hardware, software, firmware, or a combination thereof. In the above embodiments, multiple steps or methods can be implemented in software or firmware stored in memory and executed by a suitable instruction execution system. For example, if implemented in hardware, as in another embodiment, it can be implemented using any one or a combination of the following techniques known in the art: discrete logic circuits having logic gates for implementing logical functions on data signals, application-specific integrated circuits (ASICs) having suitable combinational logic gates, programmable gate arrays (PGAs), field-programmable gate arrays (FPGAs), etc.

[0061] In the description of this specification, references to terms such as "one embodiment," "some embodiments," "example," "specific example," or "some examples," etc., indicate that a specific feature, structure, material, or characteristic described in connection with that embodiment or example is included in at least one embodiment or example of the invention. In this specification, the illustrative expressions of the above terms do not necessarily refer to the same embodiment or example. Furthermore, the specific features, structures, materials, or characteristics described may be combined in any suitable manner in one or more embodiments or examples.

[0062] The embodiments described above are merely illustrative of several implementations of the present invention, and while the descriptions are specific and detailed, they should not be construed as limiting the scope of the present invention. It should be noted that those skilled in the art can make various modifications and improvements without departing from the concept of the present invention, and these modifications and improvements all fall within the scope of protection of the present invention. Therefore, the scope of protection of this patent should be determined by the appended claims.

Claims

1. A distributed data storage method based on a smart terminal, characterized in that, The method includes: Collect the security module status, system integrity, and historical behavior logs of smart terminals, and output the corresponding reliability score through an improved analytic hierarchy process. Based on the trust score, the smart terminal is divided into core trusted nodes, ordinary trusted nodes and trusted nodes to be verified. The data content and data attributes of the distributed data are collected to classify sensitive data and non-sensitive data according to the data content and the attributes. Collect the target dataset contained in the sensitive data, and generate a dynamic key matrix corresponding to the target dataset through the core trusted node; The sensitive data is encrypted using the dynamic key matrix to complete the storage of the distributed data.

2. The distributed data storage method based on a smart terminal according to claim 1, characterized in that, The steps for outputting the corresponding reliability score using the improved analytic hierarchy process include: With terminal trustworthiness as the target layer, the security module status, the system integrity, and the historical behavior logs as the criteria layer, data detection indicators adapted to the smart terminal are output. Each of the data detection indicators is weighted and fused using a trusted root verification method to output a corresponding dynamic weight vector. Calculate the initial score corresponding to the dynamic weight vector, perform dynamic verification on the initial score, and output the reliable score.

3. The distributed data storage method based on a smart terminal according to claim 2, characterized in that, The step of dynamically validating the initial score to output the reliable score includes: The actual operating parameters of the intelligent terminal in the current time window are collected, and a dynamic verification benchmark library is constructed by combining the historical fluctuation threshold of the criterion layer indicators to generate a dynamic verification threshold range that is adapted to the current scenario. The initial score is compared with the dynamic verification threshold range. If it is within the range, it is directly marked as a candidate reliable score. If it is outside the range, it is re-verified by the root of confidence to generate an anomaly correction coefficient. The initial score is then adjusted accordingly and marked as a candidate reliable score. Collect the distributed storage task attributes to be assigned to the smart terminal, calculate the fit score between the candidate trust score and the task attributes, and if the fit score is greater than a preset score threshold, then the corresponding trust score is determined.

4. The distributed data storage method based on a smart terminal according to claim 1, characterized in that, The step of generating a dynamic key matrix corresponding to the target dataset through the core trusted node includes: The feature parameters and state parameters of the target dataset are collected by the trusted node to create a corresponding multidimensional feature vector. The basic key matrix is ​​generated by iterative operation through an improved chaotic mapping algorithm. The core trusted node generates corresponding timestamp factors and access subject permission factors, and the dynamic adjustment coefficients are obtained by weighted Markov chain fusion. The basic key matrix is ​​optimized using the dynamic adjustment coefficients to generate the dynamic key matrix.

5. The distributed data storage method based on a smart terminal according to claim 4, characterized in that, The step of optimizing the basic key matrix using the dynamic adjustment coefficients to generate the dynamic key matrix includes: By analyzing the row and column sparsity, eigenvalue distribution, and weight dimension of the dynamically adjusted coefficients of the basic key matrix through the core trusted node, the basic key matrix is ​​divided into sensitive matrix blocks and ordinary matrix blocks using a matrix partitioning algorithm. Collect the actual operating environment parameters of the core trusted node; Based on the actual operating environment parameters, the sensitive matrix block is iteratively fine-tuned using a PID control algorithm to generate the dynamic key matrix.

6. The distributed data storage method based on a smart terminal according to claim 1, characterized in that, The step of encrypting the sensitive data using the dynamic key matrix to complete the distributed data storage includes: The core trusted node parses the sensitivity level of the fields of the sensitive data and decomposes the dynamic key matrix into a multi-level sub-key matrix that matches the level. A differentiated strategy is used to encrypt the multi-level key matrix field by field to generate encrypted data packets and attach encryption identifiers; Establish a mapping relationship between field sensitivity level and node trust level, and distribute the encrypted data packets based on the mapping relationship.

7. The distributed data storage method based on a smart terminal according to claim 6, characterized in that, The step of distributing the encrypted data packet based on the mapping relationship includes: Based on the mapping relationship, suitable candidate storage nodes are selected, and the load rate, network latency and transmission success rate of each candidate storage node are collected to construct the corresponding node dynamic adaptation matrix. The storage adaptation score of each candidate storage node is calculated using the entropy weight method, and the encrypted data packet is dynamically fragmented according to the field sensitivity level. A corresponding sorting list is generated based on the storage adaptation score. Each dynamic shard is then encrypted using the node dynamic adaptation matrix based on the sorting list to complete the corresponding distributed storage.

8. A distributed data storage system based on a smart terminal, characterized in that, The system includes: The data acquisition module is used to collect the security module status, system integrity, and historical behavior logs of smart terminals, and outputs the corresponding reliability score through an improved analytic hierarchy process. The segmentation module is used to segment the smart terminal into core trusted nodes, ordinary trusted nodes and trusted nodes to be verified according to the trust score, and to collect the data content and data attributes of distributed data to segment sensitive data and non-sensitive data according to the data content and the attributes. The generation module is used to collect the target dataset contained in the sensitive data and generate a dynamic key matrix corresponding to the target dataset through the core trusted node; An encryption module is used to encrypt the sensitive data using the dynamic key matrix to complete the storage of the distributed data.

9. A computer comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the computer program, it implements the distributed data storage method based on a smart terminal as described in any one of claims 1 to 7.

10. A readable storage medium having a computer program stored thereon, characterized in that, When executed by the processor, the program implements the distributed data storage method based on a smart terminal as described in any one of claims 1 to 7.