Oss production process quality traceability distributed storage method
Patent Information
- Application Number
- CN202610354334.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2026-03-23
- Publication Date
- 2026-09-15
- Estimated Expiration
- 2046-03-23
AI Technical Summary
[0006]本发明的目的在于提供OSS生产过程质量溯源分布式存储方法,解决了现有分布式存储方法中因缺乏碎片级差异化加密、密钥与节点物理绑定以及自动化攻击响应与恢复机制,导致跨节点关联攻击风险高、数据泄露范围大、恢复效率低的技术问题
[0074] This invention configures an anti-attack fragment placement engine in the data batch parsing and fragment adaptation module, introducing a deep Q-network model to deeply integrate multi-dimensional security attributes such as historical failure rate, historical attack index, and real-time reputation value of storage nodes with production data fragment placement decisions. This engine quantifies the initial security cost by constructing a fragment-node security adaptation matrix and defines incremental risk values using a risk co-location matrix. Under the premise of meeting the storage requirements of fragment length adaptation attributes, it disperses production data fragments from the same production data batch across storage nodes in different racks and with different risk levels. This shift from a "resource-oriented" to a "security-oriented" placement strategy physically blocks attackers from piecing together complete quality traceability data by breaching a few storage nodes, fundamentally reducing the success rate of cross-node correlation attacks and achieving proactive data security defense.
Smart Images

Figure CN122263130B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of industrial data storage security technology, specifically to a distributed storage method for traceability of production process quality in an object storage system (OSS). Background Technology
[0002] With the deepening of industrial digital transformation, the reliable storage of production process quality traceability data has become crucial to ensuring product safety and corporate reputation. Distributed storage technology, due to its high scalability and fault tolerance, is widely used in quality traceability systems. However, existing distributed storage solutions still have many shortcomings in data security protection.
[0003] Patent CN109150968B proposes a blockchain distributed storage method based on secret sharing. It protects the encryption key using the Shamir threshold scheme and records the encrypted node location information in the blockchain. While this scheme enhances key security, it suffers from the following drawbacks: Using a unified encryption key for all data means that if one node is compromised, an attacker could use that key to decrypt data from other nodes; it lacks differentiated protection against data fragmentation, making it unable to handle targeted attacks on specific fragments; and it lacks dynamic access control and attack response mechanisms, making it impossible to isolate infected nodes in real time after a threat occurs.
[0004] Patent application CN119720256A discloses a distributed storage method for data security, employing an adaptive encryption algorithm and homomorphic encryption handles to manage keys, and distributing encrypted fragments for storage according to multi-dimensional rules. This scheme achieves differentiated encryption at the fragment level, but it has the following shortcomings: key generation is not bound to physical node identifiers, making it impossible to prevent attackers from using the same key to decrypt data on multiple nodes; it lacks abnormal access detection and dynamic protection adjustment mechanisms, making it unable to cope with real-time changes in attack patterns; and it lacks an automated data recovery process, requiring manual intervention for recovery after integrity is compromised.
[0005] Patent application CN120654250A proposes a data security processing method based on distributed storage, which achieves data protection through dynamic threshold values, grouping isolation, and an intelligent threat perception engine. While this scheme introduces the concept of dynamic adjustment, it still has the following limitations: the dynamic threshold value is calculated based on data sensitivity and node load indices, without considering the binding relationship between node identifiers and keys; grouping isolation is based on table-level primary and foreign key associations, resulting in coarse granularity and failing to achieve fragment-level isolation; the response after threat perception mainly involves raising the threshold value and rotating keys, without addressing automated data recovery and integrity reconfirmation after node isolation. Summary of the Invention
[0006] The purpose of this invention is to provide a distributed storage method for quality traceability in the OSS production process, which solves the technical problems of high risk of cross-node related attacks, large scope of data leakage, and low recovery efficiency caused by the lack of fragment-level differentiated encryption, physical binding of keys and nodes, and automated attack response and recovery mechanisms in existing distributed storage methods.
[0007] This distributed storage solution enables fragmented differential encryption, dynamic access control, and automated recovery. By incorporating key derivation based on node identifiers, dynamic protection adjustments based on access anomalies, node isolation and automatic recovery, and closed-loop integrity verification, it comprehensively enhances the overall security of quality traceability data.
[0008] To solve the above-mentioned technical problems, the technical solution adopted by the present invention is as follows:
[0009] The OSS production process quality traceability distributed storage method includes the following steps:
[0010] Step S101: By parsing the production data batch information in the distributed storage, multiple production data fragments after batch splitting are obtained, and the storage node position corresponding to each production data fragment is determined according to the fragment length adaptation attribute, and a node distribution mapping relationship containing node position labels and storage path pointers is generated.
[0011] Step S102: Based on the node distribution mapping relationship, a differentiated encryption algorithm is used to process each production data fragment. During the encryption process, a unique key is generated by incorporating a node-specific identifier through a key derivation function. The fragment is then encrypted based on the encryption mode selection and initialization vector generation attributes to obtain an encrypted set of production data fragments containing the fragment ciphertext content, encryption algorithm identifier, and key version number.
[0012] Step S103: Obtain access log data from the encrypted production data fragment set, extract access timestamp attributes, determine if the abnormal frequency of access timestamps under the same node location tag is higher than a preset threshold, trigger an alarm mechanism, and obtain a list of potential targeted attack identifiers.
[0013] Step S104: Using the potential targeted attack identifier list, a dynamic monitoring algorithm is used to analyze the real-time access pattern of the encrypted production data fragment set. During monitoring, the attributes are adjusted according to the number of rounds of the node load adjustment algorithm, and the key version number is updated to obtain the updated dynamic protection configuration.
[0014] Step S105: According to the updated dynamic protection configuration, apply adaptive access control rules to each production data fragment. The rules verify the fragment sequence index and integrity check value attributes. If the control rules detect an illegal access attempt, isolate the storage node pointed to by the corresponding node location tag and determine the security status of the isolated production data fragment.
[0015] Step S106: Obtain the security status of the isolated production data fragments; if the status indicates that the integrity verification value attribute does not match, resulting in integrity damage, then start the recovery protocol, copy the original data from the backup node according to the key storage separation attribute, and re-encrypt and encapsulate it in ciphertext format to obtain the repaired production data fragment version.
[0016] Step S107: Through the repaired production data fragment version, integrate the data consistency verification of all nodes, verify the integrity verification value hash value matching degree of each fragment, and check the continuity of the fragment sequence index to obtain the overall production data integrity confirmation result.
[0017] Furthermore, the step S102, which involves generating a unique key by incorporating a node-specific identifier through a key derivation function, specifically includes:
[0018] Obtain the node location label corresponding to the production data fragment as a node-specific identifier;
[0019] A random salt value is generated, and a pseudo-random key is extracted using the HKDF key derivation function with the system master key and the salt value as input.
[0020] Using the pseudo-random key, the node-specific identifier, and the preset context string as input, a unique 256-bit key is generated.
[0021] Specifically, step S103, which involves determining that the abnormal frequency is higher than a preset threshold, includes:
[0022] The access frequency is calculated by counting the number of times each production data fragment under the same node location label using a sliding time window.
[0023] If the access frequency exceeds the preset 0.2 times / minute, it will be judged as abnormal;
[0024] An anomaly detection of source IP addresses in access logs is performed using the Isolation Forest algorithm, and source IPs with anomaly scores higher than 0.7 are included in a potential targeted attack flag list.
[0025] Furthermore, the adjustment of attributes based on the number of rounds of the node load adjustment algorithm described in step S104 specifically includes:
[0026] Monitor the CPU load rate of the target node. If the load rate exceeds 70%, reduce the number of iterations of the dynamic monitoring algorithm from the default 10 rounds to 5 rounds.
[0027] At the same time, the key version number of all production data fragments on the target node will be updated to the next version, and the key derivation of the new version will use a new context string.
[0028] Furthermore, the adaptive access control rule described in step S105 specifically includes:
[0029] An access token is generated for each production data fragment. The token is generated using the HMAC-SHA256 algorithm based on the global token key, fragment sequence index, and timestamp. The access control engine parses the token in the request, verifies the token's validity and HMAC correctness, and queries the Bloom filter to confirm that the token has not been revoked.
[0030] Verify whether the fragment sequence index in the verification request is consistent with the index bound in the token, and whether the integrity verification value carried in the request matches the integrity verification value stored in the metadata;
[0031] If any verification fails, it is determined to be an illegal access attempt, and the corresponding storage node is immediately isolated.
[0032] Furthermore, the initiation of the recovery protocol in step S106 specifically includes:
[0033] Copy the original plaintext data from the backup node;
[0034] Obtain the unique key corresponding to the latest key version of this production data fragment;
[0035] Generate a new initialization vector, re-encrypt it using AES-256-GCM mode, and encapsulate it into new ciphertext;
[0036] Update the storage path pointer and key version number in the metadata, and write the repaired production data fragment version to the new node.
[0037] Furthermore, obtaining the overall production data integrity confirmation result in step S107 specifically includes:
[0038] Calculate the current SHA-256 hash value for each production data fragment and compare it with the baseline hash value stored in the metadata;
[0039] Check that the sequence indices of all fragments are continuous and without missing elements;
[0040] The integrity score is calculated using the following formula:
[0041] ;
[0042] in The number of fragments matching the hash value. This represents the total number of fragments.
[0043] If the integrity score is higher than the preset threshold of 99%, the overall production data integrity is confirmed to be qualified.
[0044] Furthermore, the isolation of the storage node pointed to by the corresponding node location tag in step S105 specifically includes:
[0045] Send an isolation command to the resource scheduler to mark the storage node corresponding to the node location tag as isolated;
[0046] Disconnect all external network connections of the storage node;
[0047] Notify other nodes to stop data synchronization with the storage node;
[0048] The distributed ledger is queried to confirm the existence and integrity of the production data fragments in the backup node replicas.
[0049] In addition, this invention also discloses an OSS production process quality traceability distributed storage system for executing the OSS production process quality traceability distributed storage method described above, including:
[0050] The data batch parsing and fragment adaptation module is used to parse the production data batch information in the distributed storage, obtain multiple production data fragments after the batch is split, determine the storage node location corresponding to each production data fragment according to the fragment length adaptation attribute, and generate a node distribution mapping relationship containing node location labels and storage path pointers.
[0051] The differential encryption and key management module is used to process each production data fragment using a differential encryption algorithm according to the node distribution mapping relationship. During the encryption process, a unique key is generated by incorporating a node-specific identifier through a key derivation function. The fragment is then encrypted based on the encryption mode selection and initialization vector generation attributes to obtain an encrypted set of production data fragments containing the fragment ciphertext content, encryption algorithm identifier, and key version number.
[0052] The abnormal access detection and alarm module is used to obtain access log data from the encrypted production data fragment set, extract access timestamp attributes, determine if the abnormal frequency of access timestamps under the same node location tag is higher than a preset threshold, trigger an alarm mechanism, and obtain a list of potential targeted attack identifiers.
[0053] The dynamic monitoring and protection update module is used to analyze the real-time access patterns of the encrypted production data fragment set using a dynamic monitoring algorithm based on the potential targeted attack identification list. During monitoring, the module adjusts the attributes according to the number of rounds of the node load adjustment algorithm and updates the key version number to obtain the updated dynamic protection configuration.
[0054] The adaptive access control and node isolation module is used to apply adaptive access control rules to each production data fragment according to the updated dynamic protection configuration. The rules verify the fragment sequence index and integrity check value attributes. If the control rules detect an illegal access attempt, the storage node pointed to by the corresponding node location tag is isolated to determine the security status of the isolated production data fragment.
[0055] The data recovery and repackaging module is used to obtain the security status of the isolated production data fragments, determine if the integrity is damaged due to the mismatch of the status indication integrity check value attribute, then start the recovery protocol, copy the original data from the backup node according to the key storage separation attribute, and re-encrypt and repackage the data in ciphertext format to obtain the repaired production data fragment version.
[0056] The data consistency verification and integrity confirmation module is used to integrate the data consistency verification of all nodes through the repaired production data fragment version. In the verification, it verifies the matching degree of the integrity verification value hash value of each fragment and checks the continuity of the fragment sequence index to obtain the overall production data integrity confirmation result.
[0057] Furthermore, the differentiated encryption and key management module is specifically used to generate a unique 256-bit key by using the HKDF key derivation function, taking the node location label as the node-specific identifier, and combining it with the system master key, random salt value and preset context string.
[0058] The abnormal access detection and alarm module is specifically used to count the access frequency using a sliding time window, with a preset threshold of 0.2 times / minute, and to use the isolated forest algorithm to detect anomalies in the source IP, with an anomaly score threshold of 0.7.
[0059] The dynamic monitoring and protection update module is specifically used to monitor the node CPU load rate. When the load rate exceeds 70%, the number of iterations of the dynamic monitoring algorithm is reduced from 10 rounds to 5 rounds, and the key version number is updated.
[0060] The adaptive access control and node isolation module is specifically used to generate access tokens based on the HMAC-SHA256 algorithm, verify the validity of the tokens using a Bloom filter, and isolate storage nodes when illegal access is detected.
[0061] The data recovery and repackaging module is specifically used to copy the original plaintext data from the backup node, re-encrypt it using the unique key of the latest key version, and update the storage path pointer in the metadata;
[0062] The data consistency verification and integrity confirmation module is specifically used to calculate the integrity score. The formula is integrity score = number of matching fragments / total number of fragments × 100%, with a preset threshold of 99%.
[0063] Furthermore, the data batch parsing and fragment adaptation module is further configured with an anti-attack fragment placement engine; the anti-attack fragment placement engine is used to perform the following steps:
[0064] Obtain historical access heatmaps for batches of production data to be stored, as well as historical failure rates, historical attack indices, and real-time reputation values for each storage node in the distributed storage cluster;
[0065] Construct a fragment-node security adaptation matrix, where the matrix elements represent the initial security cost of placing a production data fragment on a storage node. The initial security cost is calculated based on a weighted sum of the predicted access conflict index of the production data fragment on the storage node, the historical failure rate of the storage node, the historical attack index, and the real-time reputation value, as predicted by the historical access heat map.
[0066] The fragment-node security adaptation matrix is used as the environmental state input of the deep Q-network model; the deep Q-network model is pre-trained with the objective of minimizing the long-term cumulative placement cost.
[0067] The deep Q-network model outputs an optimal production data fragment placement strategy based on the current environment state, and generates the node distribution mapping relationship, so that the placement of all production data fragments can not only meet the storage requirements of fragment length adaptation attributes, but also minimize the risk of cross-node association attacks on the overall production data.
[0068] Furthermore, the construction and training process of the deep Q-network model includes:
[0069] Construct a simulated distributed storage environment, define the state space as the set of real-time attributes of all storage nodes and the set of attributes of production data fragments to be placed, and define the action space as all possible combinations of allocating all production data fragments to be placed to all available storage nodes.
[0070] A reward function is set up so that at each training time step, for the action of placing a specific production data fragment on a specific storage node, the reward value is obtained by taking the negative value after a weighted sum of the storage cost penalty and the security cost penalty. The storage cost penalty is determined by the load balancing of each storage node after placement, and the security cost penalty is obtained by accumulating the incremental risk value determined by the number of placed production data fragments belonging to the same production data batch that the attacker can continuously obtain after the storage node is compromised.
[0071] The empirical replay technique is used to iteratively update the network parameters of the deep Q-network model by minimizing the loss function, using historical placement experience tuples as samples, until the model converges.
[0072] The trained and converged deep Q-network model is deployed in the anti-attack fragment placement engine to generate the optimal production data fragment placement strategy in real time.
[0073] Compared with the prior art, the present invention has the following beneficial effects:
[0074] This invention configures an anti-attack fragment placement engine in the data batch parsing and fragment adaptation module, introducing a deep Q-network model to deeply integrate multi-dimensional security attributes such as historical failure rate, historical attack index, and real-time reputation value of storage nodes with production data fragment placement decisions. This engine quantifies the initial security cost by constructing a fragment-node security adaptation matrix and defines incremental risk values using a risk co-location matrix. Under the premise of meeting the storage requirements of fragment length adaptation attributes, it disperses production data fragments from the same production data batch across storage nodes in different racks and with different risk levels. This shift from a "resource-oriented" to a "security-oriented" placement strategy physically blocks attackers from piecing together complete quality traceability data by breaching a few storage nodes, fundamentally reducing the success rate of cross-node correlation attacks and achieving proactive data security defense.
[0075] This invention achieves physical-level binding of unique keys to storage nodes. Using the HKDF key derivation function, the node location tag of the storage node is used as a key input parameter, combined with the system master key, a random salt value, and a pre-set context string, to generate a unique 256-bit key uniquely bound to each production data fragment and its storage node. Even if an attacker compromises a storage node and obtains the key for the production data fragment on that node, they cannot decrypt any production data fragments stored on other storage nodes, thus narrowing the scope of data leakage after a single point of attack from "all data" to "a single production data fragment." This sophisticated encryption mechanism of "one production data fragment, one unique key" fundamentally prevents attackers from using a single key to decrypt data across storage nodes.
[0076] This invention uses a sliding time window to statistically analyze access frequency and combines this with the isolated forest algorithm to perform multi-dimensional anomaly detection on source IP addresses, accurately identifying potential attack behaviors and generating a list of potential targeted attacks. When an attack is detected, the system dynamically adjusts the number of iterations of the monitoring algorithm based on the CPU load rate of the storage nodes. Under high load, it intelligently reduces monitoring overhead to avoid becoming a performance bottleneck, while simultaneously triggering a key version number update. This real-time "detection-adjustment" response mechanism enables the system to maintain a high level of attack blocking capability while ensuring business continuity.
[0077] This invention accurately identifies unauthorized access attempts through multiple verification methods, including access tokens generated by the HMAC-SHA256 algorithm, Bloom filters, production data fragment sequence indexes, and integrity check values. Once unauthorized access is detected, the system immediately sends an isolation command to the resource scheduler, marking the storage node pointed to by the corresponding node location tag as isolated, cutting off all external network connections to that storage node, and notifying other storage nodes to stop data synchronization. This real-time isolation capability at the production data fragment level effectively curbs the lateral spread of attacks, minimizing the impact of security incidents.
[0078] This invention constructs an automated data recovery and integrity closed-loop verification mechanism. When storage node isolation leads to data integrity corruption, the system automatically initiates a recovery protocol, copies the original plaintext data from the backup node, re-encrypts it using the unique key corresponding to the latest key version number, and updates the storage path pointer and key version number in the metadata. After recovery, the system performs a global consistency check on all production data fragments, verifies the SHA-256 hash value matching degree of each production data fragment, checks the continuity of the production data fragment sequence index, and calculates the integrity score. This automated "attack-as-recovery" protection capability and multi-dimensional integrity verification method ensure that quality traceability data maintains logical and physical integrity and trustworthiness even after experiencing security incidents.
[0079] In this invention, the risk co-location matrix in the anti-attack fragment placement engine defines the probability of associated attacks between different storage nodes, and the incremental risk value quantifies the impact of each placement action on overall security. Both serve as core components of the reward function of the deep Q-network model. This quantification mechanism enables the system to continuously optimize the placement strategy of production data fragments in a mathematically measurable manner, providing verifiable and traceable technical assurance for the security of industrial data storage. Attached Figure Description
[0080] To more clearly illustrate the technical solutions of the embodiments of the present invention, the accompanying drawings used in the embodiments will be briefly introduced below. It should be understood that the following drawings only show some embodiments of the present invention and should not be regarded as a limitation of the scope. For those skilled in the art, other related drawings can be obtained from these drawings without creative effort.
[0081] Figure 1 This is a flowchart of the overall solution described in this invention.
[0082] Figure 2 The system module architecture and data flow of this invention are shown in the figure.
[0083] Figure 3 This is a flowchart of the anti-attack fragment placement engine described in this invention. Detailed Implementation
[0084] In the following description, only certain exemplary embodiments are briefly described. As those skilled in the art will recognize, the described embodiments can be modified in various ways without departing from the spirit or scope of the embodiments of the invention. Therefore, the drawings and description are considered to be exemplary in nature and not restrictive.
[0085] The following is in conjunction with the appendix Figures 1-3 The embodiments of the present invention will be described in detail below.
[0086] Example 1: This example discloses an OSS production process quality traceability distributed storage system, including:
[0087] The data batch parsing and fragment adaptation module is used to parse the production data batch information in the distributed storage, obtain multiple production data fragments after the batch is split, determine the storage node location corresponding to each production data fragment according to the fragment length adaptation attribute, and generate a node distribution mapping relationship containing node location labels and storage path pointers.
[0088] The differential encryption and key management module is used to process each production data fragment using a differential encryption algorithm according to the node distribution mapping relationship. During the encryption process, a unique key is generated by incorporating a node-specific identifier through a key derivation function. The fragment is then encrypted based on the encryption mode selection and initialization vector generation attributes to obtain an encrypted set of production data fragments containing the fragment ciphertext content, encryption algorithm identifier, and key version number.
[0089] The abnormal access detection and alarm module is used to obtain access log data from the encrypted production data fragment set, extract access timestamp attributes, determine if the abnormal frequency of access timestamps under the same node location tag is higher than a preset threshold, trigger an alarm mechanism, and obtain a list of potential targeted attack identifiers.
[0090] The dynamic monitoring and protection update module is used to analyze the real-time access patterns of the encrypted production data fragment set using a dynamic monitoring algorithm based on the potential targeted attack identification list. During monitoring, the module adjusts the attributes according to the number of rounds of the node load adjustment algorithm and updates the key version number to obtain the updated dynamic protection configuration.
[0091] The adaptive access control and node isolation module is used to apply adaptive access control rules to each production data fragment according to the updated dynamic protection configuration. The rules verify the fragment sequence index and integrity check value attributes. If the control rules detect an illegal access attempt, the storage node pointed to by the corresponding node location tag is isolated to determine the security status of the isolated production data fragment.
[0092] The data recovery and repackaging module is used to obtain the security status of the isolated production data fragments, determine if the integrity is damaged due to the mismatch of the status indication integrity check value attribute, then start the recovery protocol, copy the original data from the backup node according to the key storage separation attribute, and re-encrypt and repackage the data in ciphertext format to obtain the repaired production data fragment version.
[0093] The data consistency verification and integrity confirmation module is used to integrate the data consistency verification of all nodes through the repaired production data fragment version. In the verification, it verifies the matching degree of the integrity verification value hash value of each fragment and checks the continuity of the fragment sequence index to obtain the overall production data integrity confirmation result.
[0094] Furthermore, the differentiated encryption and key management module is specifically used to generate a unique 256-bit key by using the HKDF key derivation function, taking the node location label as the node-specific identifier, and combining it with the system master key, random salt value and preset context string.
[0095] The abnormal access detection and alarm module is specifically used to count the access frequency using a sliding time window, with a preset threshold of 0.2 times / minute, and to use the isolated forest algorithm to detect anomalies in the source IP, with an anomaly score threshold of 0.7.
[0096] The dynamic monitoring and protection update module is specifically used to monitor the node CPU load rate. When the load rate exceeds 70%, the number of iterations of the dynamic monitoring algorithm is reduced from 10 rounds to 5 rounds, and the key version number is updated.
[0097] The adaptive access control and node isolation module is specifically used to generate access tokens based on the HMAC-SHA256 algorithm, verify the validity of the tokens using a Bloom filter, and isolate storage nodes when illegal access is detected.
[0098] The data recovery and repackaging module is specifically used to copy the original plaintext data from the backup node, re-encrypt it using the unique key of the latest key version, and update the storage path pointer in the metadata;
[0099] The data consistency verification and integrity confirmation module is specifically used to calculate the integrity score, and the formula is: Integrity Score The preset threshold is 99%.
[0100] Example 2: This example discloses a distributed storage method for quality traceability in the OSS production process, specifically including the following steps:
[0101] Step S101: Data batch parsing and fragment adaptation;
[0102] This step splits the original production data batch into multiple data fragments and determines the storage location based on the fragment length and node load.
[0103] For example, a production batch with the number B20240315 contains 12,000 quality inspection records, each 1KB in size, for a total data size of 12MB. The system presets a fragment size threshold of 256KB and uses a fixed-length segmentation algorithm (except for the last fragment, which may be less than 256KB) to divide the batch data into 48 production data fragments. During segmentation, starting from the first record, every 256KB is divided into one fragment, with the last fragment potentially smaller than 256KB. Each fragment contains approximately 250 records (the last fragment may contain slightly fewer). The fragment sequence indexes start from 1 and are sequentially numbered F001, F002, ..., F048. The size of each fragment is recorded in the metadata; the specific size may vary slightly depending on the last fragment, but for simplicity, in this embodiment, each fragment is, for example, 256KB (i.e., 262,144 bytes).
[0104] The cluster consists of 5 storage nodes, identified as N001, N002, N003, N004, and N005. The remaining storage capacities of each node are 1.2GB (1258291.2KB), 1.5GB (1572864KB), 0.8GB (838860.8KB), 1.1GB (1153433.6KB), and 0.9GB (943718.4KB), respectively. The system employs a consistent hashing-based allocation strategy, but introduces a node load factor to balance the load. (Current used capacity / total capacity), the goal is to make the total size of fragments stored on each node as balanced as possible.
[0105] Specifically, for fragments Its length attribute (Unit: KB) is used to calculate the node to which the fragment should belong. The system maintains a load dictionary. Represents a node The total size of currently allocated fragments (initially 0). The allocation algorithm is as follows:
[0106] 1. Process each fragment in the order of its fragment sequence index.
[0107] 2. Regarding fragments The hash value is calculated using the MurmurHash3 algorithm:
[0108] ;
[0109] MurmurHash3_32 is a non-cryptographic hash function that takes a fragment index i (an integer) as input and outputs a 32-bit unsigned integer. .
[0110] 3. Calculate the ideal node index:
[0111] ;
[0112] Where mod is the modulo operation, and target takes values in the range of 0 to 4, corresponding to nodes N001 and N005 respectively (for example, 0 corresponds to N001).
[0113] 4. Check the current load of the target node. Has the node's capacity limit been exceeded? The capacity limit is set to 80% of the total capacity of the node, that is... If the load is not exceeded, the node is assigned to the target; if the load exceeds the target, the node with the lowest load among the remaining nodes is selected as the actual assignment node (load is calculated based on...). calculate).
[0114] 5. Update And record the node position label. Simultaneously, a storage path pointer is generated: path = / data / batch_B20240315 / shard_ .
[0115] In this embodiment, the load on each node after the allocation of 48 fragments is as follows:
[0116] N001: 10 fragments, total size 2560KB (10×256KB);
[0117] N002: 9 fragments, 2304KB;
[0118] N003: 10 fragments, 2560KB;
[0119] N004: 9 fragments, 2304KB;
[0120] N005: 10 fragments, 2560KB total data size, 12288KB total data size, with relatively balanced load across nodes. The system stores the node distribution mapping relationship in a distributed metadata table. The table structure and some record examples are shown in Table 1 below:
[0121] Table 1:
[0122]
[0123] The mapping relationships between fragments F006 to F047 are generated sequentially according to the above algorithm. Due to space limitations, they are not listed here, but those skilled in the art can determine the storage node of any fragment based on the algorithm description.
[0124] Step S102: Differentiated encryption and key management;
[0125] This step encrypts each data fragment using a unique key bound to the node identifier.
[0126] The system is pre-configured with a master key. (256 bits), stored in a dedicated Key Management Service (KMS). For each fragment The encryption process is as follows:
[0127] 1. Obtain the node position label of the fragment. (e.g., N003).
[0128] 2. Generate random salt values (16 bytes).
[0129] 3. Use the key derivation function HKDF (RFC 5869) to extract the key from the master key. Derivation of fragment-specific keys The specific calculation is divided into two steps:
[0130] Extraction stage:
[0131] ;
[0132] HKDF-Extract uses HMAC-SHA256 and requires the input master key. and salinity Output pseudo-random key (256 bits).
[0133] Expansion phase:
[0134] ;
[0135] HKDF-Expand uses HMAC-SHA256 as the pseudo-random function and inputs a pseudo-random key. Information string ( (Indicates concatenation) and output length 256 bits, output fragment-specific key. . The fixed string "fragment-encryption" is used to distinguish different uses.
[0136] 4. Generate random initialization vectors (12 bytes).
[0137] 5. Use AES-256-GCM mode to process fragmented plaintext. Encryption is performed to obtain ciphertext. and certification labels (16 bytes):
[0138] ;
[0139] in To supplement authentication data, this embodiment uses the fragment index. The string representation (such as "F001") is used to bind authentication data and prevent fragments from being replaced.
[0140] 6. Encapsulate the encrypted fragment data in the following format: (12B) (16B) ( B). Therefore, the final total size of the ciphertext = plaintext size + 28 bytes.
[0141] For fragment F001 (node N003), the plaintext size is 256KB (262,144 bytes), so the encrypted size is 262,144 + 28 = 262,172 bytes, an increase of approximately 0.0107%. The system records the encryption algorithm identifier for each fragment as "AES-256-GCM", and the initial key version number is "V1.0". The encrypted set of production data fragments is stored in the specified path of the corresponding node.
[0142] Step S103: Abnormal access detection and alert;
[0143] This step identifies abnormal access patterns based on access logs.
[0144] The system continuously collects access logs for encrypted fragments on each node. Each log entry includes: timestamp (millisecond precision), fragment identifier, node location tag, source IP address, and operation type (read / write). For example, within a time window...
[0145]
[0146] Table 2 below shows a partial example of the access records for fragments F001, F002, and F003 under node N003:
[0147] Table 2:
[0148]
[0149] Calculate the access frequency (times / minute) of each fragment within this window. Preset threshold. times per minute. If a certain fragment frequency If so, it is marked as abnormal. In this example, fragment F001 was accessed 60 times by the same source IP within 1 hour (e.g., the log shows once per minute), which is 1 time / minute, exceeding the threshold.
[0150] The system employs an isolated forest algorithm based on a sliding window to detect anomalous source IPs. Input features include: the number of visits within the window, the variance of the visit interval, and the number of different fragments involved. The trained model outputs anomaly scores for each source IP; IPs with scores higher than 0.7 are added to the potential attack flag list. In this example, IP 192.168.1.10 has an anomaly score of 0.85, therefore it is added to the list, and the associated node label N003 is recorded.
[0151] Step S104: Dynamic monitoring and protection updates;
[0152] This step adjusts the monitoring strategy and key version based on the attack identifier list.
[0153] Upon receiving a list of potential attack identifiers, the system dynamically monitors relevant nodes (such as N003). Assuming the CPU load rate of node N003 is 78% (exceeding the 70% threshold), the system automatically reduces the number of iterations for the real-time access pattern analysis algorithm (such as a time-series-based ARIMA model) targeting this node from the default 10 rounds to 5 rounds to reduce computational resource consumption. Simultaneously, a key version update is triggered: the key version number of all fragments on node N003 is upgraded from "V1.0" to "V1.1". The new version's key derivation process still uses the original master key. However, a new context string "fragment-encryption-v2" is introduced during derivation, specifically as follows:
[0154] ;
[0155] in This ensures that the old and new keys are different. The updated dynamic protection configuration includes: node tag N003, monitoring algorithm round number 5, and key version "V1.1".
[0156] Step S105: Adaptive access control and node isolation;
[0157] This step implements fine-grained access control based on dynamic protection configuration and isolates nodes when unauthorized access is detected.
[0158] The system generates an access token for each fragment. Token generation rules: For fragments... ,
[0159] ;
[0160] in This is the system-wide token key (256 bits). For fragment index (integer). The current timestamp (in milliseconds, rounded to the nearest minute). This indicates concatenation. The token's validity period is set to 5 minutes.
[0161] When an access request is received, the control engine performs the following verification:
[0162] 1. Parse the token, extract the timestamp, and check if it is within its validity period (the difference between the current time and the token's timestamp). minute).
[0163] 2. Use Recalculate the HMAC and compare it with the HMAC in the token to verify the token's authenticity.
[0164] 3. Query the Bloom filter (which maintains an index of revoked tokens). If the token index exists in the filter, then deny access.
[0165] 4. Check the fragment sequence index in the request. Does it match the index bound in the token?
[0166] 5. Read the integrity check value (SHA-256 hash) of the fragment from the metadata and compare it with the check value carried in the request.
[0167] If any of the above steps fail, it is considered an unauthorized access attempt. For example, if an expired token is detected to be used for accessing fragment F001, the system immediately sends an isolation command to the resource scheduler based on the node location tag N003 of fragment F001. The scheduler marks node N003 as "isolated," cuts off all its external network connections, and notifies other nodes to stop synchronizing data with that node. After isolation, the system assesses the fragment's security status: by querying the distributed ledger, it is confirmed that fragment F001 has complete copies on nodes N008 and N012, and the integrity checksum of the copies is consistent with the original; therefore, the security status is "recoverable."
[0168] Step S106: Data recovery and repackaging;
[0169] This step restores fragments whose integrity has been compromised.
[0170] For fragment F001, its copy remains intact after isolation. System startup recovery protocol:
[0171] 1. Copy the original plaintext data from backup node N008. At the same time, obtain the key corresponding to the latest key version of the fragment from the key management service. (Because step S104 has been updated).
[0172] 2. Generate new random numbers (12 bytes), re-encrypt:
[0173] ;
[0174] in Still the fragment index "F001".
[0175] 3. Encapsulate as new encrypted text, in the following format: (12B) (16B) ( B).
[0176] 4. Update the storage path pointer of the fragment in the metadata to the new node (such as N020, a backup node), and record the new key version "V1.1".
[0177] 5. Write the repaired fragment version F001-R1 to the new node and update the global distribution mapping table.
[0178] The recovery process takes approximately 200 milliseconds (including network transmission and encryption), which is far less than the hours-long time required for traditional manual recovery.
[0179] Step S107: Data consistency verification and integrity confirmation;
[0180] This step performs a consistency check on all fragments to ensure the integrity of the traceability data.
[0181] The system performs a full check periodically (e.g., hourly). For all fragments, its current integrity check value (SHA-256) is calculated and compared with the baseline value stored in the metadata. Simultaneously, the system checks whether the sequence indexes of all fragments are continuous and without missing values.
[0182] For example, this verification found that fragment F001 has been recovered, and its new verification value... Compared with the repaired baseline value recorded in the metadata Consistent. For other fragments, such as F023, their current hash value... Compared with the benchmark value Match. The sequence indices of all 48 fragments are consecutive from 1 to 48, with no skips.
[0183] The system calculates the overall integrity score:
[0184] ;
[0185] in:
[0186] The number of fragments that match the integrity check value;
[0187] Total number of fragments (48 in this example).
[0188] In this example, the number of matched fragments is 48, with a score of 100%, which is higher than the preset threshold of 99%. Therefore, the integrity of the overall production data is confirmed to be qualified, and the confirmation result is output.
[0189] Example 3: Based on Example 1, this example further details how to achieve attack-resistant production data fragment placement through deep reinforcement learning.
[0190] In the industrial internet environment, production process quality traceability data has extremely high commercial value and sensitivity. When splitting production data batches into multiple fragments and distributing them across different storage nodes, the common approach is to consider only fragment length, remaining node capacity, or simple hash consistency to achieve balanced utilization of storage resources. However, this placement strategy harbors serious security vulnerabilities: once an attacker gains control of a few storage nodes, they can selectively collect critical production data fragments belonging to the same batch based on publicly known or predictable placement patterns. By piecing these fragments together, they can reconstruct complete quality traceability information, leading to large-scale data breaches. This "puzzle-like" cross-node correlation attack has become a new threat to industrial data security.
[0191] Based on this, this embodiment proposes an anti-attack fragment placement engine based on deep reinforcement learning. This engine is built into the data batch parsing and fragment adaptation module. It dynamically learns the optimal placement strategy through a deep Q-network model to achieve coordinated optimization of security and storage efficiency.
[0192] Specifically as follows:
[0193] Data preparation and input:
[0194] For a batch of production data to be stored (e.g., batch B20240315 in Example 1, containing 48 production data fragments), the anti-attack fragment placement engine first obtains the following input data from various modules of the system:
[0195] Attributes of production data fragments to be placed: Each production data fragment (where subscript) For indexing data fragments, ) length (Unit: KB) and security level (Dimensionless, value range 0~1, higher values indicate more sensitive data). In this embodiment, the security level of all production data fragments is set to 0.9 (high sensitivity level).
[0196] Storage node attributes: For each storage node in the cluster (where subscript) For the index of the storage node, (corresponding to node identifiers N001 to N005 respectively), obtain the following attributes:
[0197] Current load rate The ratio of a node's used storage capacity to its total capacity is dimensionless and is collected in real time from the resource monitoring system.
[0198] Historical failure rate : The ratio of the total duration of hardware or software failures to the total operating time of a node in the past month. It is dimensionless and is calculated from the operation and maintenance database.
[0199] Historical attack index : Normalized value of the number of times a node has been successfully attacked or scanned in the past year, ranging from 0 to 1, calculated from security audit logs.
[0200] Real-time reputation value The score is based on the dynamic evaluation of node behavior, ranging from 0 to 1. It is updated in real time by the node behavior analysis module. The lower the reputation score, the more suspicious the node is.
[0201] Production data fragment historical access pattern: Generate each production data fragment by analyzing historical access logs. At storage nodes The predicted access conflict index The index indicates that... Placed in Subsequently, the probability of being noticed by attackers may increase in the future due to access conflicts (such as hotspot access). In this embodiment, Simplified to be obtained by interpolating historical visit heatmaps, the specific calculation method is as follows: statistically analyze the data from the past week and... The average number of accesses per minute for similar types of production data fragments across each node is calculated and normalized. For example, for node N003, .
[0202] The fragment-node security adaptation matrix is constructed as follows:
[0203] The anti-attack fragment placement engine first constructs a fragment-node security adaptation matrix for all production data fragments in the current batch. The matrix is A matrix, where each element This indicates that production data fragments will be generated. Placed on storage nodes The initial security cost is calculated using the following formula:
[0204] ;
[0205] In the formula:
[0206] Production data fragments Placed on storage nodes The initial safety cost is dimensionless; the larger the value, the higher the inherent risk of the placement choice.
[0207] , , , : Preset weighting coefficients are used to balance the impact of various security factors on the initial security cost.
[0208] In this embodiment, based on historical data calibration, take , , , The sum of all weights does not have to be 1; it only indicates their relative importance.
[0209] Production data fragments At storage nodes The predicted access conflict index is dimensionless and ranges from [0,1].
[0210] Storage node The historical failure rate is dimensionless and ranges from [0,1].
[0211] Storage node The historical attack index is dimensionless and ranges from [0,1].
[0212] Storage node The real-time reputation value is dimensionless and ranges from [0,1].
[0213] Calculation example: For production data fragments and storage nodes ,like , , , ,but
[0214]
[0215] Similarly, the matrix can be calculated. All elements of the matrix. This matrix will be used as part of the environment state of the deep Q-network model in subsequent steps.
[0216] The construction and pre-training of the deep Q-network model are as follows:
[0217] To optimize the placement order and location of production data fragments from a global perspective, this embodiment introduces a deep Q-network model. This model learns a mapping from environmental states to placement actions through reinforcement learning, minimizing the long-term accumulated placement cost.
[0218] The environment is defined as follows:
[0219] state space At any moment ,state It consists of two parts. The first part is the node state vector, which contains the real-time attributes of all 5 nodes, with each node represented by a quadruple. It means that among them The current load rate, Historical failure rate Historical attack index, The first part is the real-time reputation value. The second part is the attribute vector of the production data fragments to be placed, containing the attributes of all production data fragments that have not yet been assigned in the current batch, with each production data fragment represented by a tuple. It means that among them For the length of the fragment, For safety levels. Because the number of production data fragments is variable, the state space is represented by a fixed length, and zeros are used to fill in when there are insufficient remaining production data fragments.
[0220] Action space At every step The agent needs to select a storage node for the first production data fragment to be processed. Therefore, the action space consists of 5 discrete actions, corresponding to nodes N001 to N005 respectively.
[0221] The reward function is designed as follows:
[0222] At every step The intelligent agent performs actions (Fragment the current production data) Placed on a node After that, the environment returns an immediate reward. The core innovation lies in the design of the reward function, which aims to guide the agent to minimize the risk of cross-node correlation attacks while satisfying storage resource constraints. The reward value is obtained by weighted summation of two penalty terms and taking the negative value:
[0223] ;
[0224] In the formula:
[0225] : at time step Execute action The instant reward value obtained afterward is dimensionless.
[0226] , : Weighting coefficient, used to balance storage efficiency and security. In this embodiment, it is taken as... , This indicates that security is slightly more important than storage efficiency.
[0227] Storage cost penalty is determined by the load balancing of all nodes after deployment. Load balancing is expressed as the variance of the load rate of each node. This means, that is:
[0228] ;
[0229] in:
[0230] Storage nodes after placement action The load rate is dimensionless.
[0231] The average load rate of all 5 storage nodes after placement is dimensionless and calculated using the following formula: .
[0232] Safety cost penalty item, defined as the incremental risk value brought about by this placement action. Its calculation depends on a risk co-location matrix. .
[0233] In practical implementation, the risk co-location matrix It is A symmetric matrix, where the elements Indicates if storage node Once breached, attackers can access storage nodes. The probability of obtaining production data fragments belonging to the same production data batch. This probability is set based on prior knowledge such as the physical proximity between nodes, network topology, and management domain. In this embodiment, the following is set:
[0234] Between two nodes within the same rack ;
[0235] Nodes in different racks but within the same data center ;
[0236] Between nodes in different data centers, And agree on the co-location probability of the same node. (Because an attacker can directly obtain the data on the node by breaking it down, without needing to go through a co-location relationship).
[0237] matrix It is generated during system initialization and can be updated periodically according to changes in network topology.
[0238] At any moment Fragment production data Placed on a node Then, incremental risk value Defined as: for all nodes that have already placed production data fragments belonging to the same production data batch. This node With the current node Co-location risk between The cumulative sum. The mathematical expression is:
[0239] ;
[0240] In the formula:
[0241] The incremental risk value introduced by this placement action is dimensionless.
[0242] At any moment Previously, fragments of the current production data had already been allocated. A set of storage nodes for production data fragments from the same batch.
[0243] : Storage nodes in the risk co-location matrix With storage nodes The co-occurrence probability between them is dimensionless.
[0244] The physical meaning of this incremental risk value is: as long as the attacker breaks through the current node... This allows you to obtain, with a certain probability, what has already been stored. By identifying fragments of the same batch of production data across all nodes, reinforcement learning agents can move closer to the goal of "pieced together complete data." These agents need to learn to avoid concentrating large amounts of fragmented production data from the same batch in node combinations with high co-location risk.
[0245] Therefore, the safety cost penalty item is directly taken as... .
[0246] The model training process is as follows:
[0247] The Deep Q-Network model adopts the classic DQN architecture and includes an evaluation network (parameters). ) and a target network (parameters) Both have the same structure, which is a three-layer fully connected neural network (the input layer dimension is equal to the length of the state vector, the hidden layers have 128 and 64 neurons respectively, and the output layer dimension is equal to the action space size of 5).
[0248] The training process is as follows:
[0249] Initialization: Randomly initialize and evaluate network parameters Let the target network parameters Initialize the experience replay pool The capacity is 10,000.
[0250] Hyperparameter settings: Discount factor ; Exploration probability The initial value is 1.0, which eventually decays to 0.01, with the decay rate multiplied by 0.995 after each training epoch; batch size. Target network update frequency Step; the optimizer uses Adam, and the learning rate is... .
[0251] Iteration: For each training episode:
[0252] Reset the environment and generate a random batch of production data (the number of production data fragments is random between 10 and 100, and the attributes are random).
[0253] Get the initial state .
[0254] For each step arrive ( (Total number of production data fragments for this batch)
[0255] With probability Randomly select an action Otherwise choose .
[0256] Execute action Calculate the immediate reward based on the above reward function. And observe the next state. .
[0257] empirical tuples Store in the experience replay pool .
[0258] from A small batch of empirical tuples is randomly sampled, with a quantity of tuples. .
[0259] For each sampled tuple, calculate the target value. :
[0260]
[0261] in:
[0262] This represents the immediate reward value in the sampled tuple.
[0263] The discount factor is set to 0.95.
[0264] For the target network in the next state All possible actions The largest value.
[0265] Calculate the loss function:
[0266] ;
[0267] The summation iterates through all samples in the mini-batch.
[0268] Minimize the loss function using the Adam optimizer. Update and evaluate network parameters .
[0269] Every time Step 1: Update target network parameters .
[0270] The exploration probability decreases after each round. .
[0271] Convergence criterion: Training continues until the loss function stabilizes and the average reward per round no longer increases significantly, typically requiring thousands of rounds. At this point, the model has learned a better placement strategy.
[0272] In practice, the converged deep Q-network model is deployed to the anti-attack fragmentation placement engine. When a new batch of production data (such as B20240315) arrives, the engine executes the following online decision-making process:
[0273] Input state construction: Obtain the real-time attributes of each node. and the attributes of the 48 production data fragments to be placed. splice together to form the current state .
[0274] Fragment-Node Safety Adaptation Matrix for Initialization: Although the model can directly use the original state, to accelerate convergence and introduce prior knowledge, the engine may optionally use the calculated fragment-node safety adaptation matrix for initialization. As additional features, they are concatenated into the state to form an enhanced state. .
[0275] Sequential decision: based on production data fragment index arrive The following steps will be executed sequentially:
[0276] Input the current state into the deep Q-network model to obtain the result for each action. value.
[0277] choose The action with the highest value That is, selecting storage nodes .
[0278] Record this placement and update the node distribution mapping relationship (i.e., record the fragment identifier, node location label, and storage path pointer).
[0279] Update status: Remove placed production data fragments and update based on node load after placement. Then proceed to the decision-making process for the next production data fragment.
[0280] Output: The final node distribution mapping relationship is shown in Table 1. This mapping relationship not only meets the storage requirements of fragment length adaptation, but also inherently minimizes the risk of cross-node association attacks.
[0281] In specific implementation, taking batch B20240315 (48 production data fragments, each 256KB) and 5 storage nodes in Example 1 as an example, we will illustrate the calculation steps of online decision-making.
[0282] Assume the attributes of each node at the current moment are as shown in Table 3 below:
[0283] Table 3:
[0284]
[0285] Predicted Access Conflict Index Simplified to a node-independent constant of 0.01 (all) ).
[0286] Fragment-Node Security Adaptation Matrix In the context of production data fragmentation The initial security cost of each node is calculated as follows (using...). ):
[0287]
[0288]
[0289]
[0290]
[0291]
[0292] It is evident that the initial security cost of node N003 is positive (high risk), while that of other nodes is negative (relatively safe).
[0293] Now we're taking the first step in online decision-making ( ,place The current set of nodes. The value is empty, therefore the incremental risk value is... The deep Q-network model is based on the current state (including node attributes and...) (Matrix) outputs the values of each action Value. Assume the model output is as follows (example):
[0294] ;
[0295] ;
[0296] ;
[0297] ;
[0298] ;
[0299] Therefore, the model selects action N004, and... Placed on N004. Update node load; N004 load becomes... Assuming the total capacity remains the same, it is approximately increased, but this is ignored for simplification.
[0300] Step Two ( ,place ),at this time If the model considers... If placed in N004, the incremental risk value (Because the risk of co-location is not considered for the same node). If placed in N001, then Based on the risk co-location matrix, assuming N001 and N004 are in different racks, The model makes a decision by comprehensively considering storage costs (load balancing) and security costs (incremental risks), tending to choose the option that... Small nodes, thus distributing fragments across different nodes.
[0301] Through multi-step decision-making, the model will learn to distribute fragments of production data from the same batch across different racks and nodes with high reputation and low attack index, avoiding concentration on high-risk nodes (such as N003) or nodes with high co-location risk.
[0302] To verify the technical effectiveness of this embodiment, we conducted a comparative experiment in a simulation environment. The experimental setup is as follows:
[0303] Cluster size: 5 nodes, divided into two racks (Rack A: N001, N002; Rack B: N003, N004, N005).
[0304] Production data batches: Simulate 1000 batches, with 48 production data fragments per batch, each fragment being 256KB.
[0305] Attack Model: Randomly compromise two nodes and count the proportion of batches in which the attacker can obtain complete data (i.e., the fragment coverage of the same batch of production data reaches 100%). This proportion is defined as the data leakage risk index.
[0306] Comparison strategy:
[0307] Strategy 1: Traditional consistent hashing (based solely on fragment index hash modulo).
[0308] Strategy 2: Load balancing only (greedy allocation to the node with the lowest current load).
[0309] Strategy 3: The deep reinforcement learning anti-attack placement strategy in this embodiment.
[0310] The experimental results are shown in Table 4 below:
[0311] Table 4:
[0312]
[0313] This embodiment uses a deep reinforcement learning model to drastically reduce the data leakage risk index from 72%~85% to 11.8%, which means that even if an attacker successfully breaches two nodes, there is only a very low probability (about 1 / 9) that they can piece together complete quality traceability data, improving security by nearly an order of magnitude.
[0314] The co-location rate of critical production data fragments decreased from about 40% to below 5%, proving that the model successfully distributed production data fragments from the same batch to nodes of different racks and risk levels, thus physically blocking the path of "puzzle-like" attacks.
[0315] While model inference introduces some computational overhead (approximately 45ms per batch), this is perfectly acceptable for the write frequency of industrial data storage and can be further optimized through hardware acceleration. There is a slight sacrifice in load balancing, but it remains within acceptable limits; the significant improvement in security far outweighs the minor loss in storage efficiency.
[0316] This embodiment introduces a deep reinforcement learning model to realize a paradigm shift in the placement of production data fragments from "resource-oriented" to "security-oriented". It works in conjunction with other modules of the system described in Embodiments 1 and 2 (such as differentiated encryption, dynamic monitoring, automatic recovery, etc.) to form a defense-in-depth system.
[0317] By physically dispersing production data fragments from the same batch during the data writing phase, the "fragment co-location risk" is quantified as an optimization objective, significantly increasing the cost and difficulty for attackers to steal complete data and fundamentally reducing the success rate of cross-node correlation attacks. The Deep Q-network model can continuously adjust placement strategies based on dynamically changing security attributes such as node real-time reputation values and historical attack indices, enabling the system to learn and evolve its security capabilities and effectively cope with new attack patterns. Through the mathematical definition of the fragment-node security adaptation matrix and incremental risk values, a quantitative assessment and optimization of the security of production data fragment placement strategies has been achieved for the first time, providing measurable technical indicators for industrial data storage security.
[0318] Although preferred embodiments of the invention have been described, those skilled in the art, upon learning the basic inventive concept, can make other changes and modifications to these embodiments. Therefore, the appended claims are intended to be interpreted as including both the preferred embodiments and all changes and modifications falling within the scope of the invention.
[0319] The above description is merely a preferred embodiment of the present invention and is not intended to limit the present invention. It should be noted that any modifications, equivalent substitutions, and improvements made within the spirit and principles of the present invention should be included within the protection scope of the present invention.
Claims
1. An OSS production process quality traceability distributed storage method, characterized in that, Includes the following steps: Step S101: By parsing the production data batch information in the distributed storage, multiple production data fragments after batch splitting are obtained, and the storage node position corresponding to each production data fragment is determined according to the fragment length adaptation attribute, and a node distribution mapping relationship containing node position labels and storage path pointers is generated. Step S102: Based on the node distribution mapping relationship, a differentiated encryption algorithm is used to process each production data fragment. During the encryption process, a unique key is generated by incorporating a node-specific identifier through a key derivation function. The fragment is then encrypted based on the encryption mode selection and initialization vector generation attributes to obtain an encrypted set of production data fragments containing the fragment ciphertext content, encryption algorithm identifier, and key version number. Step S103: Obtain access log data from the encrypted production data fragment set, extract access timestamp attributes, determine if the abnormal frequency of access timestamps under the same node location tag is higher than a preset threshold, trigger an alarm mechanism, and obtain a list of potential targeted attack identifiers. Step S104: Using the potential targeted attack identifier list, a dynamic monitoring algorithm is used to analyze the real-time access pattern of the encrypted production data fragment set. During monitoring, the attributes are adjusted according to the number of rounds of the node load adjustment algorithm, and the key version number is updated to obtain the updated dynamic protection configuration. Step S105: According to the updated dynamic protection configuration, apply adaptive access control rules to each production data fragment, use the rules to verify the fragment sequence index and integrity check value attributes, if the control rules detect an illegal access attempt, then isolate the storage node pointed to by the corresponding node location label, and determine the security status of the isolated production data fragment. Step S106: Obtain the security status of the isolated production data fragments; if the status indicates that the integrity verification value attribute does not match, resulting in integrity damage, then start the recovery protocol, copy the original data from the backup node according to the key storage separation attribute, and re-encrypt and encapsulate it in ciphertext format to obtain the repaired production data fragment version. Step S107: Through the repaired production data fragment version, integrate the data consistency verification of all nodes, verify the integrity verification value hash value matching degree of each fragment, and check the continuity of the fragment sequence index to obtain the overall production data integrity confirmation result.
2. The OSS production process quality traceability distributed storage method according to claim 1, characterized in that, Step S102, which involves generating a unique key by incorporating a node-specific identifier through a key derivation function, specifically includes: Obtain the node location label corresponding to the production data fragment as a node-specific identifier; A random salt value is generated, and a pseudo-random key is extracted using the HKDF key derivation function with the system master key and the salt value as input.
3. The OSS production process quality traceability distributed storage method according to claim 1, characterized in that, Step S103, determining that the abnormal frequency is higher than a preset threshold, specifically includes: The access frequency is calculated by counting the number of times each production data fragment under the same node location label using a sliding time window. If the access frequency exceeds the preset 0.2 times / minute, it will be judged as abnormal; An anomaly detection of source IP addresses in access logs is performed using the Isolation Forest algorithm, and source IPs with anomaly scores higher than 0.7 are included in a potential targeted attack flag list.
4. The OSS production process quality traceability distributed storage method according to claim 1, characterized in that, The adjustment of attributes based on the number of rounds of the node load adjustment algorithm mentioned in step S104 specifically includes: Monitor the CPU load rate of the target node. If the load rate exceeds 70%, reduce the number of iterations of the dynamic monitoring algorithm from the default 10 rounds to 5 rounds. At the same time, the key version number of all production data fragments on the target node will be updated to the next version, and the key derivation of the new version will use a new context string.
5. The OSS production process quality traceability distributed storage method according to claim 1, characterized in that, The adaptive access control rules mentioned in step S105 specifically include: An access token is generated for each production data fragment. The token is generated using the HMAC-SHA256 algorithm based on the global token key, fragment sequence index, and timestamp. The access control engine parses the token in the request, verifies the token's validity and HMAC correctness, and queries the Bloom filter to confirm that the token has not been revoked. Verify whether the fragment sequence index in the verification request is consistent with the index bound in the token, and whether the integrity verification value carried in the request matches the integrity verification value stored in the metadata; If any verification fails, it is determined to be an illegal access attempt, and the corresponding storage node is immediately isolated.
6. The OSS production process quality traceability distributed storage method according to claim 1, characterized in that, The startup recovery protocol mentioned in step S106 specifically includes: Copy the original plaintext data from the backup node; Obtain the unique key corresponding to the latest key version of this production data fragment; Generate a new initialization vector, re-encrypt it using AES-256-GCM mode, and encapsulate it into new ciphertext; Update the storage path pointer and key version number in the metadata, and write the repaired production data fragment version to the new node.
7. The OSS production process quality traceability distributed storage method according to claim 1, characterized in that, The step S107, which involves obtaining the overall production data integrity confirmation result, specifically includes: Calculate the current SHA-256 hash value for each production data fragment and compare it with the baseline hash value stored in the metadata; Check that the sequence indices of all fragments are continuous and without missing elements; The integrity score is calculated using the following formula: ; in The number of fragments matching the hash value. This represents the total number of fragments. If the integrity score is higher than the preset threshold of 99%, the overall production data integrity is confirmed to be qualified.
8. The OSS production process quality traceability distributed storage method according to claim 1, characterized in that, The isolation of the storage node pointed to by the corresponding node location tag in step S105 specifically includes: Send an isolation command to the resource scheduler to mark the storage node corresponding to the node location tag as isolated; Disconnect all external network connections of the storage node; Notify other nodes to stop data synchronization with the storage node; The distributed ledger is queried to confirm the existence and integrity of the production data fragments in the backup node replicas.
9. The OSS production process quality traceability distributed storage method according to claim 1, characterized in that, The following OSS production process quality traceability distributed storage system is used for implementation. The system includes: The data batch parsing and fragment adaptation module is used to parse the production data batch information in the distributed storage, obtain multiple production data fragments after the batch is split, determine the storage node location corresponding to each production data fragment according to the fragment length adaptation attribute, and generate a node distribution mapping relationship containing node location labels and storage path pointers. The differential encryption and key management module is used to process each production data fragment using a differential encryption algorithm according to the node distribution mapping relationship. During the encryption process, a unique key is generated by incorporating a node-specific identifier through a key derivation function. The fragment is then encrypted based on the encryption mode selection and initialization vector generation attributes to obtain an encrypted set of production data fragments containing the fragment ciphertext content, encryption algorithm identifier, and key version number. The abnormal access detection and alarm module is used to obtain access log data from the encrypted production data fragment set, extract access timestamp attributes, determine if the abnormal frequency of access timestamps under the same node location tag is higher than a preset threshold, trigger an alarm mechanism, and obtain a list of potential targeted attack identifiers. The dynamic monitoring and protection update module is used to analyze the real-time access patterns of the encrypted production data fragment set using a dynamic monitoring algorithm based on the potential targeted attack identification list. During monitoring, the module adjusts the attributes according to the number of rounds of the node load adjustment algorithm and updates the key version number to obtain the updated dynamic protection configuration. The adaptive access control and node isolation module is used to apply adaptive access control rules to each production data fragment according to the updated dynamic protection configuration, and use the rules to verify the fragment sequence index and integrity check value attributes. If the control rules detect an illegal access attempt, the storage node pointed to by the corresponding node location tag is isolated to determine the security status of the isolated production data fragment. The data recovery and repackaging module is used to obtain the security status of the isolated production data fragments, determine if the integrity is damaged due to the mismatch of the status indication integrity check value attribute, then start the recovery protocol, copy the original data from the backup node according to the key storage separation attribute, and re-encrypt and repackage the data in ciphertext format to obtain the repaired production data fragment version. The data consistency verification and integrity confirmation module is used to integrate the data consistency verification of all nodes through the repaired production data fragment version. In the verification, it verifies the matching degree of the integrity verification value hash value of each fragment and checks the continuity of the fragment sequence index to obtain the overall production data integrity confirmation result.
10. The OSS production process quality traceability distributed storage method according to claim 9, characterized in that, The differentiated encryption and key management module is specifically used to generate a unique 256-bit key by using the HKDF key derivation function, taking the node position label as the node-specific identifier, and combining the system master key, random salt value and preset context string. The abnormal access detection and alarm module is specifically used to count the access frequency using a sliding time window, with a preset threshold of 0.2 times / minute, and to use the isolated forest algorithm to detect anomalies in the source IP, with an anomaly score threshold of 0.
7. The dynamic monitoring and protection update module is specifically used to monitor the node CPU load rate. When the load rate exceeds 70%, the number of iterations of the dynamic monitoring algorithm is reduced from 10 rounds to 5 rounds, and the key version number is updated. The adaptive access control and node isolation module is specifically used to generate access tokens based on the HMAC-SHA256 algorithm, verify the validity of the tokens using a Bloom filter, and isolate storage nodes when illegal access is detected. The data recovery and repackaging module is specifically used to copy the original plaintext data from the backup node, re-encrypt it using the unique key of the latest key version, and update the storage path pointer in the metadata; The data consistency verification and integrity confirmation module is specifically used to calculate the integrity score, and the formula is as follows: Integrity score = (Number of matching fragments / Total number of fragments) × 100%, with a preset threshold of 99%.
Citation Information
Patent Citations
A blockchain-based distributed storage method based on secret sharing
CN109150968B
Distributed storage method and system for data security
CN119720256A
Data security processing method and system based on distributed storage
CN120654250A
Information security storage method
CN120688075A
Industrial raw material traceability management method, device, equipment and medium
CN121684948A